NIST Cybersecurity Framework
Requirements Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| CSF 2.0 published | Feb 26, 2024 | Major update adding Govern function |
| CSF 1.1 published | Apr 16, 2018 | Update to the original 2014 framework |
Provisions (2)
Incident Response (RS.AN, RS.MI)
"NIST CSF 2.0 defines Incident Analysis (RS.AN) and Incident Mitigation (RS.MI) as categories under the Respond function."
Requirements
| Requirement | Details |
|---|---|
| Analysis | Investigate incidents to determine scope and impact |
| Mitigation | Contain and mitigate effects of detected incidents |
Sources: NIST CSF 2.0
Access Control (PR.AA)
"NIST CSF 2.0 names PR.AA as the Identity Management, Authentication, and Access Control category under the Protect function."
Requirements
| Requirement | Details |
|---|---|
| Identity management | Manage identities and credentials for authorized users |
| Access enforcement | Enforce access permissions based on policies |
Sources: NIST CSF 2.0