All frameworks
csf-2-0version 2.0

NIST Cybersecurity Framework 2.0

Official source

134 controls.

ReferenceFamilyTitle
GV.SC-09n/aSupply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
GV.SC-10n/aCybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
IDn/aIDENTIFY
ID.AMn/aAsset Management
ID.AM-01n/aInventories of hardware managed by the organization are maintained
ID.AM-02n/aInventories of software, services, and systems managed by the organization are maintained
ID.AM-03n/aRepresentations of the organization's authorized network communication and internal and external network data flows are maintained
ID.AM-04n/aInventories of services provided by suppliers are maintained
ID.AM-05n/aAssets are prioritized based on classification, criticality, resources, and impact on the mission
ID.AM-07n/aInventories of data and corresponding metadata for designated data types are maintained
ID.AM-08n/aSystems, hardware, software, services, and data are managed throughout their life cycles
ID.IMn/aImprovement
ID.IM-01n/aImprovements are identified from evaluations
ID.IM-02n/aImprovements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
ID.IM-03n/aImprovements are identified from execution of operational processes, procedures, and activities
ID.IM-04n/aIncident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
ID.RAn/aRisk Assessment
ID.RA-01n/aVulnerabilities in assets are identified, validated, and recorded
ID.RA-02n/aCyber threat intelligence is received from information sharing forums and sources
ID.RA-03n/aInternal and external threats to the organization are identified and recorded
ID.RA-04n/aPotential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
ID.RA-05n/aThreats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
ID.RA-06n/aRisk responses are chosen, prioritized, planned, tracked, and communicated
ID.RA-07n/aChanges and exceptions are managed, assessed for risk impact, recorded, and tracked
ID.RA-08n/aProcesses for receiving, analyzing, and responding to vulnerability disclosures are established
ID.RA-09n/aThe authenticity and integrity of hardware and software are assessed prior to acquisition and use
ID.RA-10n/aCritical suppliers are assessed prior to acquisition
PRn/aPROTECT
PR.AAn/aIdentity Management, Authentication, and Access Control
PR.AA-01n/aIdentities and credentials for authorized users, services, and hardware are managed by the organization
PR.AA-02n/aIdentities are proofed and bound to credentials based on the context of interactions
PR.AA-03n/aUsers, services, and hardware are authenticated
PR.AA-04n/aIdentity assertions are protected, conveyed, and verified
PR.AA-05n/aAccess permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
PR.AA-06n/aPhysical access to assets is managed, monitored, and enforced commensurate with risk
PR.ATn/aAwareness and Training
PR.AT-01n/aPersonnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
PR.AT-02n/aIndividuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
PR.DSn/aData Security
PR.DS-01n/aThe confidentiality, integrity, and availability of data-at-rest are protected
PR.DS-02n/aThe confidentiality, integrity, and availability of data-in-transit are protected
PR.DS-10n/aThe confidentiality, integrity, and availability of data-in-use are protected
PR.DS-11n/aBackups of data are created, protected, maintained, and tested
PR.IRn/aTechnology Infrastructure Resilience
PR.IR-01n/aNetworks and environments are protected from unauthorized logical access and usage
PR.IR-02n/aThe organization's technology assets are protected from environmental threats
PR.IR-03n/aMechanisms are implemented to achieve resilience requirements in normal and adverse situations
PR.IR-04n/aAdequate resource capacity to ensure availability is maintained
PR.PSn/aPlatform Security
PR.PS-01n/aConfiguration management practices are established and applied

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.