NIST Cybersecurity Framework
Requirements Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| CSF 2.0 published | Feb 26, 2024 | Major update adding Govern function |
| CSF 1.1 published | Apr 16, 2018 | Original framework |
Provisions (2)
Incident Response (RS.AN, RS.MI)
"NIST CSF 2.0 restructured response activities into **analysis and mitigation** subcategories, emphasizing that incident response is a continuous improvement process."
Requirements
| Requirement | Details |
|---|---|
| Analysis | Investigate incidents to determine scope and impact |
| Mitigation | Contain and mitigate effects of detected incidents |
Sources: NIST CSF 2.0
Access Control (PR.AA)
"CSF 2.0 consolidated identity and access management into a single **PR.AA** subcategory, clarifying that authentication and authorization are inseparable."
Requirements
| Requirement | Details |
|---|---|
| Identity management | Manage identities and credentials for authorized users |
| Access enforcement | Enforce access permissions based on policies |
Sources: NIST CSF 2.0