Security Questionnaire Mapper
Framework

NIST Cybersecurity Framework 2.0: what it anchors in a questionnaire

The framework US customers and many banks map their questionnaires to. Version 2.0 ids (PR.AA-01); version 1.1 ids are named as old numbering.

The requirement lines are our statement of each clause, read against the copy we hold and cited to it. Ticked by default for bank, government agency and other customer customers.

Families anchored here

11 families, 10 clauses cited
FamilyClause
Multi-factor authenticationPR.AA-03
Access provisioning and reviewPR.AA-05
Privileged accessPR.AA-05
Encryption at restPR.DS-01
Encryption in transitPR.DS-02
Logging and monitoringDE.CM-01
Vulnerability and patch managementID.RA-01
Incident response planRS.MA-01
Business continuity planRC.RP-01
Backup and disaster recoveryPR.DS-11
Assessing your own suppliersGV.SC-07

Every NIST CSF clause the register cites, with its text and evidence