Security Questionnaire Mapper
Clause text

NIST Cybersecurity Framework 2.0: the clauses the register cites

The 10 NIST Cybersecurity Framework 2.0 clauses that questions are placed on, each with the evidence an assessor asks for and where answers usually fall short.

The requirement lines are our statement of each clause, read against the copy we hold and cited to it.

10 clauses

the families they anchor
NIST CSF DE.CM-01 Networks and network services are monitored to find potentially adverse events

Networks and network services are monitored to find potentially adverse events.

Evidence an assessor expects: Network flow telemetry coverage map by segment; IDS or NDR sensor inventory with placement diagram; DNS query analytics pipeline configuration; East-west traffic monitoring sample alerts; Egress monitoring policy and exception register
Where answers usually fall short: Encrypted traffic not inspected at chokepoints; Container and service mesh traffic invisible
Source: NIST Cybersecurity Framework 2.0
NIST CSF GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

Evidence an assessor expects: Continuous monitoring evidence for critical suppliers; Periodic reassessment schedule and completion records; Threat intelligence on supplier ecosystem; Performance review minutes with security topics; Findings remediation tracker per supplier
Where answers usually fall short: Continuous monitoring only via marketing dashboards; Reassessments slip beyond cycle
Source: NIST Cybersecurity Framework 2.0
NIST CSF ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded

Vulnerabilities in assets are identified, validated, and recorded.

Evidence an assessor expects: Vulnerability scanning coverage report; Vulnerability triage workflow with severity SLAs; Validated findings with proof and remediation status; Asset coverage exceptions register; Trend analysis on vulnerability backlog
Where answers usually fall short: Coverage gaps for cloud and container workloads; SLAs missed for high severity items
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.AA-03 Users, services, and hardware are authenticated

Users, services, and hardware are authenticated.

Evidence an assessor expects: Multi factor authentication coverage report; Phishing resistant authentication rollout plan; Authentication failure analytics; Workload identity authentication policy; Periodic authentication strength review
Where answers usually fall short: MFA fatigue not addressed; Legacy protocols still enabled
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Evidence an assessor expects: Access policy framework with role definitions; Privileged access management deployment evidence; Periodic access reviews with sign off; Segregation of duties matrix; Just in time access workflow records
Where answers usually fall short: Standing privileges still common; Access reviews rubber stamped
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected

The confidentiality, integrity, and availability of data-at-rest are protected.

Evidence an assessor expects: Data at rest encryption inventory by store type; Key management standards and rotation evidence; Storage configuration baselines with attestation; Sensitive data discovery findings remediated; Audit findings on data at rest protection
Where answers usually fall short: Encryption inventory misses backup media; Key rotation manual and missed
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected

The confidentiality, integrity, and availability of data-in-transit are protected.

Evidence an assessor expects: TLS configuration standards and scan results; VPN and zero trust network access policy; Email transport encryption configuration; API security policy with mutual authentication; Network traffic encryption audit
Where answers usually fall short: Weak ciphers still permitted for legacy clients; Internal traffic unencrypted
Source: NIST Cybersecurity Framework 2.0
NIST CSF PR.DS-11 Backups of data are created, protected, maintained, and tested

Backups of data are created, protected, maintained, and tested.

Evidence an assessor expects: Backup policy with frequency and retention; Backup integrity test reports; Immutable backup configuration evidence; Restoration test records with success criteria; Backup access control and audit logs
Where answers usually fall short: Restoration tests narrow in scope; Immutability not configured on all critical systems
Source: NIST Cybersecurity Framework 2.0
NIST CSF RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process

The recovery portion of the incident response plan is executed once initiated from the incident response process

Evidence an assessor expects: Recovery plan with triggers and decision rights; Execution log of recovery activities; Recovery team roster with on call coverage; Plan invocation tests and outcomes; Post execution review records
Where answers usually fall short: Triggers unclear in the plan; Execution log incomplete during incidents
Source: NIST Cybersecurity Framework 2.0
NIST CSF RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared

The incident response plan is executed in coordination with relevant third parties once an incident is declared

Evidence an assessor expects: Incident response plan with third party invocation; Retainer contract evidence for IR vendor; Joint exercise records with the IR vendor; Coordination procedure with law enforcement; Vendor activation log during real incidents
Where answers usually fall short: Retainer in place but contact path untested; Coordination with law enforcement absent
Source: NIST Cybersecurity Framework 2.0