NIST Cybersecurity Framework 2.0: the clauses the register cites
The 10 NIST Cybersecurity Framework 2.0 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.
The requirement lines are our statement of each clause, read against the copy we hold and cited to it.
10 clauses
the families they anchorNIST CSF DE.CM-01 Networks and network services are monitored to find potentially adverse eventsNetworks and network services are monitored to find potentially adverse events.
Where answers usually fall short: Encrypted traffic not inspected at chokepoints; Container and service mesh traffic invisible
Source: NIST Cybersecurity Framework 2.0
NIST CSF GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationshipThe risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
Where answers usually fall short: Continuous monitoring only via marketing dashboards; Reassessments slip beyond cycle
Source: NIST Cybersecurity Framework 2.0
NIST CSF ID.RA-01 Vulnerabilities in assets are identified, validated, and recordedVulnerabilities in assets are identified, validated, and recorded.
Where answers usually fall short: Coverage gaps for cloud and container workloads; SLAs missed for high severity items
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.AA-03 Users, services, and hardware are authenticatedUsers, services, and hardware are authenticated.
Where answers usually fall short: MFA fatigue not addressed; Legacy protocols still enabled
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of dutiesAccess permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Where answers usually fall short: Standing privileges still common; Access reviews rubber stamped
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protectedThe confidentiality, integrity, and availability of data-at-rest are protected.
Where answers usually fall short: Encryption inventory misses backup media; Key rotation manual and missed
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protectedThe confidentiality, integrity, and availability of data-in-transit are protected.
Where answers usually fall short: Weak ciphers still permitted for legacy clients; Internal traffic unencrypted
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.DS-11 Backups of data are created, protected, maintained, and testedBackups of data are created, protected, maintained, and tested.
Where answers usually fall short: Restoration tests narrow in scope; Immutability not configured on all critical systems
Source: NIST Cybersecurity Framework 2.0
NIST CSF RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response processThe recovery portion of the incident response plan is executed once initiated from the incident response process
Where answers usually fall short: Triggers unclear in the plan; Execution log incomplete during incidents
Source: NIST Cybersecurity Framework 2.0
NIST CSF RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declaredThe incident response plan is executed in coordination with relevant third parties once an incident is declared
Where answers usually fall short: Retainer in place but contact path untested; Coordination with law enforcement absent
Source: NIST Cybersecurity Framework 2.0