All frameworks
csf-2-0version 2.0

NIST Cybersecurity Framework 2.0

Official source

134 controls.

ReferenceFamilyTitle
DEn/aDETECT
DE.AEn/aAdverse Event Analysis
DE.AE-02n/aPotentially adverse events are analyzed to better understand associated activities
DE.AE-03n/aInformation is correlated from multiple sources
DE.AE-04n/aThe estimated impact and scope of adverse events are understood
DE.AE-06n/aInformation on adverse events is provided to authorized staff and tools
DE.AE-07n/aCyber threat intelligence and other contextual information are integrated into the analysis
DE.AE-08n/aIncidents are declared when adverse events meet the defined incident criteria
DE.CMn/aContinuous Monitoring
DE.CM-01n/aNetworks and network services are monitored to find potentially adverse events
DE.CM-02n/aThe physical environment is monitored to find potentially adverse events
DE.CM-03n/aPersonnel activity and technology usage are monitored to find potentially adverse events
DE.CM-06n/aExternal service provider activities and services are monitored to find potentially adverse events
DE.CM-09n/aComputing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
GVn/aGOVERN
GV.OCn/aOrganizational Context
GV.OC-01n/aThe organizational mission is understood and informs cybersecurity risk management
GV.OC-02n/aInternal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
GV.OC-03n/aLegal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
GV.OC-04n/aCritical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
GV.OC-05n/aOutcomes, capabilities, and services that the organization depends on are understood and communicated
GV.OVn/aOversight
GV.OV-01n/aCybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
GV.OV-02n/aThe cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
GV.OV-03n/aOrganizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
GV.POn/aPolicy
GV.PO-01n/aPolicy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
GV.PO-02n/aPolicy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
GV.RMn/aRisk Management Strategy
GV.RM-01n/aRisk management objectives are established and agreed to by organizational stakeholders
GV.RM-02n/aRisk appetite and risk tolerance statements are established, communicated, and maintained
GV.RM-03n/aCybersecurity risk management activities and outcomes are included in enterprise risk management processes
GV.RM-04n/aStrategic direction that describes appropriate risk response options is established and communicated
GV.RM-05n/aLines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
GV.RM-06n/aA standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
GV.RM-07n/aStrategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
GV.RRn/aRoles, Responsibilities, and Authorities
GV.RR-01n/aOrganizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
GV.RR-02n/aRoles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
GV.RR-03n/aAdequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
GV.RR-04n/aCybersecurity is included in human resources practices
GV.SCn/aCybersecurity Supply Chain Risk Management
GV.SC-01n/aA cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
GV.SC-02n/aCybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
GV.SC-03n/aCybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
GV.SC-04n/aSuppliers are known and prioritized by criticality
GV.SC-05n/aRequirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
GV.SC-06n/aPlanning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
GV.SC-07n/aThe risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
GV.SC-08n/aRelevant suppliers and other third parties are included in incident planning, response, and recovery activities

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.