NIST Cybersecurity Framework

Scope: Federal Organization: National Institute of Standards and Technology active Effective: Feb 26, 2024 Official source

Requirements Covered

Incident Response Access Control

Timeline

MilestoneDateNotes
CSF 2.0 publishedFeb 26, 2024Major update adding Govern function
CSF 1.1 publishedApr 16, 2018Update to the original 2014 framework

Provisions (2)

Incident Response (RS.AN, RS.MI)

Implements: Incident Response active Effective: Feb 26, 2024
"NIST CSF 2.0 defines Incident Analysis (RS.AN) and Incident Mitigation (RS.MI) as categories under the Respond function."

Requirements

RequirementDetails
AnalysisInvestigate incidents to determine scope and impact
MitigationContain and mitigate effects of detected incidents
Sources: NIST CSF 2.0

Access Control (PR.AA)

Implements: Access Control active Effective: Feb 26, 2024
"NIST CSF 2.0 names PR.AA as the Identity Management, Authentication, and Access Control category under the Protect function."

Requirements

RequirementDetails
Identity managementManage identities and credentials for authorized users
Access enforcementEnforce access permissions based on policies
Sources: NIST CSF 2.0