All frameworks
csf-2-0version 2.0

NIST Cybersecurity Framework 2.0

Official source

134 controls.

ReferenceFamilyTitle
PR.PS-02n/aSoftware is maintained, replaced, and removed commensurate with risk
PR.PS-03n/aHardware is maintained, replaced, and removed commensurate with risk
PR.PS-04n/aLog records are generated and made available for continuous monitoring
PR.PS-05n/aInstallation and execution of unauthorized software are prevented
PR.PS-06n/aSecure software development practices are integrated, and their performance is monitored throughout the software development life cycle
RCn/aRECOVER
RC.COn/aIncident Recovery Communication
RC.CO-03n/aRecovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
RC.CO-04n/aPublic updates on incident recovery are shared using approved methods and messaging
RC.RPn/aIncident Recovery Plan Execution
RC.RP-01n/aThe recovery portion of the incident response plan is executed once initiated from the incident response process
RC.RP-02n/aRecovery actions are selected, scoped, prioritized, and performed
RC.RP-03n/aThe integrity of backups and other restoration assets is verified before using them for restoration
RC.RP-04n/aCritical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
RC.RP-05n/aThe integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
RC.RP-06n/aThe end of incident recovery is declared based on criteria, and incident-related documentation is completed
RSn/aRESPOND
RS.ANn/aIncident Analysis
RS.AN-03n/aAnalysis is performed to establish what has taken place during an incident and the root cause of the incident
RS.AN-06n/aActions performed during an investigation are recorded, and the records' integrity and provenance are preserved
RS.AN-07n/aIncident data and metadata are collected, and their integrity and provenance are preserved
RS.AN-08n/aAn incident's magnitude is estimated and validated
RS.COn/aIncident Response Reporting and Communication
RS.CO-02n/aInternal and external stakeholders are notified of incidents
RS.CO-03n/aInformation is shared with designated internal and external stakeholders
RS.MAn/aIncident Management
RS.MA-01n/aThe incident response plan is executed in coordination with relevant third parties once an incident is declared
RS.MA-02n/aIncident reports are triaged and validated
RS.MA-03n/aIncidents are categorized and prioritized
RS.MA-04n/aIncidents are escalated or elevated as needed
RS.MA-05n/aThe criteria for initiating incident recovery are applied
RS.MIn/aIncident Mitigation
RS.MI-01n/aIncidents are contained
RS.MI-02n/aIncidents are eradicated

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.