The NIST Cybersecurity Framework (CSF) 2.0 Core is a taxonomy of high-level cybersecurity
outcomes that any organization can use to understand, assess, prioritize, and communicate its
cybersecurity risks. The Core is organized hierarchically into Functions, Categories,
and Subcategories. Subcategories are supported by non-normative Implementation Examples
(illustrative actions, labelled Ex1, Ex2, …) and Informative References
(mappings to related standards, guidelines, frameworks, and regulations).
This page reproduces the CSF 2.0 Core reference data as published by NIST in the accompanying
spreadsheet (csf2.xlsx). Content is unchanged; informative references that share a source
document have been merged onto a single line, separated by semicolons, to keep the tables readable.
Entries marked [Withdrawn] were carried over from CSF 1.1 and have been incorporated
elsewhere in CSF 2.0.
Framework Core at a glance
CSF 2.0 Functions and their Categories
| Function
|
Category ID
|
Category
|
| GOVERN (GV)
|
GV.OC
|
Organizational Context
|
| GV.RM
|
Risk Management Strategy
|
| GV.RR
|
Roles, Responsibilities, and Authorities
|
| GV.PO
|
Policy
|
| GV.OV
|
Oversight
|
| GV.SC
|
Cybersecurity Supply Chain Risk Management
|
| IDENTIFY (ID)
|
ID.AM
|
Asset Management
|
| ID.RA
|
Risk Assessment
|
| ID.IM
|
Improvement
|
| ID.BE
|
Business Environment (withdrawn)
|
| ID.GV
|
Governance (withdrawn)
|
| ID.RM
|
Risk Management Strategy (withdrawn)
|
| ID.SC
|
Supply Chain Risk Management (withdrawn)
|
| PROTECT (PR)
|
PR.AA
|
Identity Management, Authentication, and Access Control
|
| PR.AT
|
Awareness and Training
|
| PR.DS
|
Data Security
|
| PR.PS
|
Platform Security
|
| PR.IR
|
Technology Infrastructure Resilience
|
| PR.AC
|
Identity Management, Authentication and Access Control (withdrawn)
|
| PR.IP
|
Information Protection Processes and Procedures (withdrawn)
|
| PR.MA
|
Maintenance (withdrawn)
|
| PR.PT
|
Protective Technology (withdrawn)
|
| DETECT (DE)
|
DE.CM
|
Continuous Monitoring
|
| DE.AE
|
Adverse Event Analysis
|
| DE.DP
|
Detection Processes (withdrawn)
|
| RESPOND (RS)
|
RS.MA
|
Incident Management
|
| RS.AN
|
Incident Analysis
|
| RS.CO
|
Incident Response Reporting and Communication
|
| RS.MI
|
Incident Mitigation
|
| RS.RP
|
Response Planning (withdrawn)
|
| RS.IM
|
Improvements (withdrawn)
|
| RECOVER (RC)
|
RC.RP
|
Incident Recovery Plan Execution
|
| RC.CO
|
Incident Recovery Communication
|
| RC.IM
|
Improvements (withdrawn)
|
GOVERN (GV)
Function GV
| Outcome
|
The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored
|
| Informative References
|
- CRI Profile v2.0: GV
- CSF v1.1: ID.GV
- ISO/IEC 27001:2022: Mandatory Clause: 6.1; Mandatory Clause: 8.1; Mandatory Clause: 8.2; Mandatory Clause: 8.3; Annex A Controls: 5.1
- SCF: GOV-01; GOV-05; RSK-01
- SP 800-221A: GV.PO
|
Organizational Context (GV.OC)
Category GV.OC
| Outcome
|
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood
|
| Informative References
|
- CRI Profile v2.0: GV.OC
- CSF v1.1: ID.BE
- ISO/IEC 27001:2022: Mandatory Clause: 4.2(a); Mandatory Clause: 4.4; Mandatory Clause: 6.1; Mandatory Clause: 8.1; Mandatory Clause: 8.2; Mandatory Clause: 8.3; Annex A Controls: 5.20; Annex A Controls: 5.31
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-014; OG-WRL-015
- SCF: CPL-01; TPM-05.4
- SP 800-221A: GV.CT; GV.CT-5
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus; RMF Prepare Step (System Level): TASK P-9 System Stakeholders; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Prepare Step (System Level): TASK P-15 Requirements Definition
|
GV.OC Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| GV.OC-01
|
The organizational mission is understood and informs cybersecurity risk management
|
- Ex1: Share the organization's mission (e.g., through vision and mission statements, marketing, and service strategies) to provide a basis for identifying risks that may impede that mission
|
- BXAIOS: Chapter 2 - Unify the Vision
- CCMv4.0: BCR-01; BCR-07
- CRI Profile v2.0: GV.OC-01; GV.OC-01.01
- CSF v1.1: ID.BE-2; ID.BE-3
- CoP: A3
- IRP: IRP-Sec-1
- ISO/IEC 27001:2022: Mandatory Clause: 4.1; Mandatory Clause: 6.1,; Mandatory Clause: 8.1; Mandatory Clause: 8.2; Mandatory Clause: 8.3; Annex A Controls:
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-010; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM06-2025; LLM09-2025
- PCI DSS: 12.1.1
- SCF: RSK-01.1; TDA-06.2
- SP 800-221A: GV.CT-5; GV.CT-3
- SP 800-53 Rev 5.1.1: PM-11
- SP 800-53 Rev 5.2.0: PM-11
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus
|
| GV.OC-02
|
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered
|
- Ex1: Identify relevant internal stakeholders and their cybersecurity-related expectations (e.g., performance and risk expectations of officers, directors, and advisors; cultural expectations of employees)
- Ex2: Identify relevant external stakeholders and their cybersecurity-related expectations (e.g., privacy expectations of customers, business expectations of partnerships, compliance expectations of regulators, ethics expectations of society)
|
- CCMv4.0: STA-08; STA-13
- CRI Profile v2.0: GV.OC-02; GV.OC-02.01; GV.OC-02.02; GV.OC-02.03
- CSF v1.1: ID.SC-2; ID.GV-2
- CoP: A1; E2; E3
- ISO/IEC 27001:2022: Mandatory Clause: 4.1; Mandatory Clause: 4.2; Mandatory Clause: 4.4; Mandatory Clause: 6.1; Mandatory Clause: 8.1; Mandatory Clause: 8.2; Mandatory Clause: 8.3; Annex A Controls:
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-010; OG-WRL-014
- OWASP Top 10 LLM Applications: LLM02-2025; LLM09-2025
- PCI DSS: 12.8.1; 12.8.5; 12.9.1; 12.9.2; 12.1.4
- SCF: TPM-05; TPM-05.4
- SP 800-171 Rev 3: 03.11.01; 03.17.02; 03.17.03
- SP 800-221A: GV.OV-2; GV.CT-2; GV.CT-3
- SP 800-53 Rev 5.1.1: PM-09; PM-18; PM-30; SR-03; SR-05; SR-06; SR-08
- SP 800-53 Rev 5.2.0: PM-09; PM-18; PM-30; SR-03; SR-05; SR-06; SR-08
- SP-800-37 Rev 2: RMF Prepare Step - Organization and Mission/Business Level - Task P-1: Risk Management Roles; RMF Prepare Step - Organization and Mission/Business Level - Task P-3: Risk Assessment - Organizat; RMF Prepare Step (System Level): TASK P-9 System Stakeholders; RMF Prepare Step (System Level): TASK P-15 Requirements Definition
- SSDF: PO.2.1
|
| GV.OC-03
|
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
|
- Ex1: Determine a process to track and manage legal and regulatory requirements regarding protection of individuals' information (e.g., Health Insurance Portability and Accountability Act, California Consumer Privacy Act, General Data Protection Regulation)
- Ex2: Determine a process to track and manage contractual requirements for cybersecurity management of supplier, customer, and partner information
- Ex3: Align the organization's cybersecurity strategy with legal, regulatory, and contractual requirements
|
- CCMv4.0: CEK-12; CEK-13; CEK-14; CEK-15; CEK-16; CEK-17; CEK-18; CEK-19; CEK-20; CEK-21; DSP-01; DSP-10; DSP-11; DSP-12; DSP-16; DSP-18; GRC-07; HRS-13; STA-05; STA-13
- CRI Profile v2.0: GV.OC-03; GV.OC-03.01; GV.OC-03.02
- CSF v1.1: ID.GV-3
- CoP: A1; D3; E2; E3; E4; E5
- ISO/IEC 27001:2022: Mandatory Clause: 4.2(a); Mandatory Clause: 4.2(b); Annex A Controls: 5.20; Annex A Controls: 5.31
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010
- OWASP Top 10 LLM Applications: LLM02-2025; LLM03-2025; LLM09-2025
- PCI DSS: 12.8.2; 12.8.4; 12.8.5; 12.8.1; 12.9.1; 12.9.2; 3.2.1; 9.4.6; 9.4.7
- SCF: CPL-01; CPL-02; PRI-01; TPM-05; TPM-05.2
- SDOS: SDOS-GV-01; SDOS-GV-03; SDOS-GV-05
- SP 800-171 Rev 3: 03.15.01
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; PM-28; PT
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; PM-28; PT
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (System Level): TASK P-15 Requirements Definition; RMF Prepare Step (System Level): TASK P-17 Requirements Allocation
- SSDF: PO.1.1; PO.1.2
|
| GV.OC-04
|
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
|
- Ex1: Establish criteria for determining the criticality of capabilities and services as viewed by internal and external stakeholders
- Ex2: Determine (e.g., from a business impact analysis) assets and business operations that are vital to achieving mission objectives and the potential impact of a loss (or partial loss) of such operations
- Ex3: Establish and communicate resilience objectives (e.g., recovery time objectives) for delivering critical capabilities and services in various operating states (e.g., under attack, during recovery, normal operation)
|
- CCMv4.0: BCR-01; BCR-02; BCR-03; BCR-11; IVS-02; STA-05
- CRI Profile v2.0: GV.OC-04; GV.OC-04.01; GV.OC-04.02; GV.OC-04.03; GV.OC-04.04
- CSF v1.1: ID.BE-4; ID.BE-5
- CoP: A1
- ISO/IEC 27001:2022: Mandatory Clause: 4.2(a); Mandatory Clause: 4.2(b); Annex A Controls: 5.20; Annex A Controls: 5.31
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-010; OG-WRL-014
- OWASP Top 10 LLM Applications: LLM09-2025; LLM10-2025
- PCI DSS: 12.10.1; 12.5.2; 12.5.1
- SCF: BCD-02; TPM-02
- SP 800-221A: MA.RI-1
- SP 800-53 Rev 5.1.1: PM-08; PM-11; CP-02(08); PM-30(01); RA-09
- SP 800-53 Rev 5.2.0: PM-08; PM-11; CP-02(08); PM-30(01); RA-09
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus; RMF Prepare Step (System Level): TASK P-9 System Stakeholders
|
| GV.OC-05
|
Outcomes, capabilities, and services that the organization depends on are understood and communicated
|
- Ex1: Create an inventory of the organization's dependencies on external resources (e.g., facilities, cloud-based hosting providers) and their relationships to organizational assets and business functions
- Ex2: Identify and document external dependencies that are potential points of failure for the organization's critical capabilities and services, and share that information with appropriate personnel
|
- CCMv4.0: BCR-11; STA-01; STA-04
- CRI Profile v2.0: GV.OC-05; GV.OC-05.01; GV.OC-05.02; GV.OC-05.03; GV.OC-05.04
- CSF v1.1: ID.BE-1; ID.BE-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.3; Control 5.8
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-010; OG-WRL-014
- OWASP Top 10 LLM Applications: LLM03-2025; LLM10-2025
- PCI DSS: 12.8.1; 12.8.4; 12.9.1; 12.9.2; 1.2.3; 1.2.4; 12.5.2; 12.5.1
- SCF: BCD-02; TPM-02
- SP 800-171 Rev 3: 03.11.04; 03.16.03; 03.17.02
- SP 800-221A: GV.CT-5; MA.RI-1
- SP 800-53 Rev 5.1.1: PM-11; PM-30; RA-07; SA-09; SR-05
- SP 800-53 Rev 5.2.0: PM-11; PM-30; RA-07; SA-09; SR-05
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus; RMF Prepare Step (System Level): TASK P-10 Asset Identification
|
Risk Management Strategy (GV.RM)
Category GV.RM
| Outcome
|
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions
|
| Informative References
|
- CRI Profile v2.0: GV.RM
- CSF v1.1: ID.RM
- ISO/IEC 27001:2022: Mandatory Clause: 6.1; Annex A Controls: 5.1
- NICE Framework: DD-WRL-002; DD-WRL-006; IO-WRL-003; IO-WRL-006; OG-WRL-002; OG-WRL-003; OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-009; OG-WRL-010; OG-WRL-011; OG-WRL-012; OG-WRL-013; OG-WRL-014; OG-WRL-015
- SCF: GOV-04; PRM-01; RSK-01; RSK-01.1
- SP 800-221A: GV.BE-3
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
GV.RM Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| GV.RM-01
|
Risk management objectives are established and agreed to by organizational stakeholders
|
- Ex1: Update near-term and long-term cybersecurity risk management objectives as part of annual strategic planning and when major changes occur
- Ex2: Establish measurable objectives for cybersecurity risk management (e.g., manage the quality of user training, ensure adequate risk protection for industrial control systems)
- Ex3: Senior leaders agree about cybersecurity objectives and use them for measuring and managing risk and performance
|
- CCMv4.0: GRC-02; CEK-07
- CRI Profile v2.0: GV.RM-01; GV.RM-01.01; GV.RM-01.02; GV.RM-01.03; GV.RM-01.04; GV.RM-01.05
- CSF v1.1: ID.RM-1
- CoP: A1
- IRP: IRP-Sec-2
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Annex A Controls: 5.1
- NICE Framework: OG-WRL-002; OG-WRL-007; OG-WRL-008; OG-WRL-011; OG-WRL-012; OG-WRL-013; OG-WRL-014; OG-WRL-015
- PCI DSS: 12.1.4; 12.1.2; 12.1.1
- SCF: GOV-01; RSK-01
- SP 800-171 Rev 3: 03.11.04; 03.17.01
- SP 800-221A: GV.RR-2
- SP 800-53 Rev 5.1.1: PM-09; RA-07; SR-02
- SP 800-53 Rev 5.2.0: PM-09; RA-07; SR-02
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
| GV.RM-02
|
Risk appetite and risk tolerance statements are established, communicated, and maintained
|
- Ex1: Determine and communicate risk appetite statements that convey expectations about the appropriate level of risk for the organization
- Ex2: Translate risk appetite statements into specific, measurable, and broadly understandable risk tolerance statements
- Ex3: Refine organizational objectives and risk appetite periodically based on known risk exposure and residual risk
|
- CCMv4.0: GRC-02; BCR-03; IVS-08
- CRI Profile v2.0: GV.RM-02; GV.RM-02.01; GV.RM-02.02; GV.RM-02.03
- CSF v1.1: ID.RM-2; ID.RM-3
- CoP: A3
- Guardian-SDK: GS-CF-01
- IRP: IRP-Sec-5
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.2; Annex A Controls: 5.1
- NICE Framework: DD-WRL-006; IO-WRL-003; OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-010; OG-WRL-011; OG-WRL-013; OG-WRL-014; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM06-2025; LLM09-2025
- SDOS: SDOS-RM-01; SDOS-RM-02; SDOS-RM-03
- SP 800-221A: GV.BE-1; GV.BE-3
- SP 800-53 Rev 5.1.1: PM-09
- SP 800-53 Rev 5.2.0: PM-09
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
| GV.RM-03
|
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
|
- Ex1: Aggregate and manage cybersecurity risks alongside other enterprise risks (e.g., compliance, financial, operational, regulatory, reputational, safety)
- Ex2: Include cybersecurity risk managers in enterprise risk management planning
- Ex3: Establish criteria for escalating cybersecurity risks within enterprise risk management
|
- CCMv4.0: GRC-02; A&A-03
- CRI Profile v2.0: GV.RM-03; GV.RM-03.01; GV.RM-03.02; GV.RM-03.03; GV.RM-03.04
- CSF v1.1: ID.GV-4
- CoP: A2
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.3; Annex A Controls: 5.1
- NICE Framework: DD-WRL-002; OG-WRL-002; OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-011; OG-WRL-015
- PCI DSS: 12.5.3; 10.4.2.1; 11.3.1.1; 11.6.1; 12.10.4.1; 5.2.3.1; 5.3.2.1; 7.2.5.1; 8.6.3; 6.3.1; 6.3.3; 9.5.1.2.1; 12.3.4; 12.3.3; 12.8.3
- SCF: GOV-01; RSK-01
- SP 800-171 Rev 3: 03.11.04; 03.17.01
- SP 800-221A: GV.PO-2; GV.PO-3
- SP 800-53 Rev 5.1.1: PM-03; PM-09; PM-30; RA-07; SR-02
- SP 800-53 Rev 5.2.0: PM-03; PM-09; PM-30; RA-07; SA-24; SR-02
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
| GV.RM-04
|
Strategic direction that describes appropriate risk response options is established and communicated
|
- Ex1: Specify criteria for accepting and avoiding cybersecurity risk for various classifications of data
- Ex2: Determine whether to purchase cybersecurity insurance
- Ex3: Document conditions under which shared responsibility models are acceptable (e.g., outsourcing certain cybersecurity functions, having a third party perform financial transactions on behalf of the organization, using public cloud-based services)
|
- CCMv4.0: GRC-02; BCR-03; STA-01
- CRI Profile v2.0: GV.RM-04; GV.RM-04.01
- CSF v1.1: ID.RM-2
- CoP: B1; B2
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.3; Annex A Controls: 5.1
- NICE Framework: OG-WRL-002; OG-WRL-007; OG-WRL-010; OG-WRL-015
- PCI DSS: 12.10.1; 12.10.2; 12.10.6
- SCF: RSK-01; RSK-01.1; RSK-06.1
- SDOS: SDOS-GV-02; SDOS-RM-01
- SP 800-171 Rev 3: 03.17.01
- SP 800-221A: GV.BE-1
- SP 800-53 Rev 5.1.1: PM-09; PM-28; PM-30; SR-02
- SP 800-53 Rev 5.2.0: PM-09; PM-28; PM-30; SR-02
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
|
| GV.RM-05
|
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
|
- Ex1: Determine how to update senior executives, directors, and management on the organization's cybersecurity posture at agreed-upon intervals
- Ex2: Identify how all departments across the organization - such as management, operations, internal auditors, legal, acquisition, physical security, and HR - will communicate with each other about cybersecurity risks
|
- CCMv4.0: GRC-02; STA-01; STA-08
- CRI Profile v2.0: GV.RM-05; GV.RM-05.01; GV.RM-05.02
- CSF v1.1: ID.SC-1
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.3; Annex A Controls: 5.1; Annex A Controls: 5.19
- NICE Framework: DD-WRL-006; OG-WRL-002; OG-WRL-003; OG-WRL-007; OG-WRL-008; OG-WRL-009; OG-WRL-010; OG-WRL-013; OG-WRL-014; OG-WRL-015
- PCI DSS: 12.8.2; 12.8.5; 12.9.2; 12.9.1; 12.8.4; 12.5.3; 12.10.1; 10.7.1; 10.7.2
- SCF: GOV-04; HRS-03; TPM-05.4
- SP 800-221A: GV.PO-1
- SP 800-53 Rev 5.1.1: PM-09; PM-30
- SP 800-53 Rev 5.2.0: PM-09; PM-30
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-9 System Stakeholders
|
| GV.RM-06
|
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
|
- Ex1: Establish criteria for using a quantitative approach to cybersecurity risk analysis, and specify probability and exposure formulas
- Ex2: Create and use templates (e.g., a risk register) to document cybersecurity risk information (e.g., risk description, exposure, treatment, and ownership)
- Ex3: Establish criteria for risk prioritization at the appropriate levels within the enterprise
- Ex4: Use a consistent list of risk categories to support integrating, aggregating, and comparing cybersecurity risks
|
- CCMv4.0: GRC-02; TVM-08; IVS-08
- CRI Profile v2.0: GV.RM-06; GV.RM-06.01
- CSF v1.1: ID.RM-1
- IRP: IRP-Sec-2
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.2; Annex A Controls: 5.1
- NICE Framework: DD-WRL-006; IO-WRL-003; IO-WRL-006; OG-WRL-002; OG-WRL-007; OG-WRL-010; OG-WRL-012; OG-WRL-013; OG-WRL-014; OG-WRL-015
- PCI DSS: 12.3.1; 12.3.2; 10.4.2.1; 11.3.1.1; 11.6.1; 12.10.4.1; 5.2.3.1; 5.3.2.1; 7.2.5.1; 8.6.3; 6.3.1; 6.3.3; 9.5.1.2.1; 12.3.4; 12.3.3; 12.8.3
- SCF: RSK-01; RSK-01.1; RSK-04
- SDOS: SDOS-AU-01; SDOS-RM-01; SDOS-RM-02
- SP 800-171 Rev 3: 03.11.01
- SP 800-221A: GV.RR-2
- SP 800-53 Rev 5.1.1: PM-09; PM-18; PM-28; PM-30; RA-03
- SP 800-53 Rev 5.2.0: PM-09; PM-18; PM-28; PM-30; RA-03
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
|
| GV.RM-07
|
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
|
- Ex1: Define and communicate guidance and methods for identifying opportunities and including them in risk discussions (e.g., strengths, weaknesses, opportunities, and threats [SWOT] analysis)
- Ex2: Identify stretch goals and document them
- Ex3: Calculate, document, and prioritize positive risks alongside negative risks
|
- CCMv4.0: GRC-02
- CRI Profile v2.0: GV.RM-07; GV.RM-07.01
- ISO/IEC 27001:2022: Mandatory Clause: 6.11; Annex A Controls: None
- NICE Framework: OG-WRL-002; OG-WRL-007; OG-WRL-015
- SCF: RSK-01.1
- SDOS: SDOS-GV-02; SDOS-RM-01
- SP 800-171 Rev 3: 03.11.01
- SP 800-53 Rev 5.1.1: PM-09; PM-18; PM-28; PM-30; RA-03
- SP 800-53 Rev 5.2.0: PM-09; PM-18; PM-28; PM-30; RA-03
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
Roles, Responsibilities, and Authorities (GV.RR)
Category GV.RR
| Outcome
|
Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated
|
| Informative References
|
- CRI Profile v2.0: GV.RR
- CSF v1.1: ID.GV-2
- ISO/IEC 27001:2022: Mandatory Clause: 5.3; Annex A Controls: 5.2; Annex A Controls: 5.4
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-007; OG-WRL-010
- SCF: HRS-03; TPM-05.4
- SP 800-221A: GV.OV-2
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles; RMF Prepare Step (System Level): TASK P-9 System Stakeholders
- SSDF: PO.2.1
|
GV.RR Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| GV.RR-01
|
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving
|
- Ex1: Leaders (e.g., directors) agree on their roles and responsibilities in developing, implementing, and assessing the organization's cybersecurity strategy
- Ex2: Share leaders' expectations regarding a secure and ethical culture, especially when current events present the opportunity to highlight positive or negative examples of cybersecurity risk management
- Ex3: Leaders direct the CISO to maintain a comprehensive cybersecurity risk strategy and review and update it at least annually and after major events
- Ex4: Conduct reviews to ensure adequate authority and coordination among those responsible for managing cybersecurity risk
|
- BXAIOS: Chapter 8 - Activate the Champions
- CCMv4.0: HRS-09; HRS-13
- CIS Controls v8.0: 14.1
- CIS Controls v8.1: 14.1
- CRI Profile v2.0: GV.RR-01; GV.RR-01.01; GV.RR-01.02; GV.RR-01.03; GV.RR-01.04; GV.RR-01.05
- CoP: A2; C1; E3
- ISO/IEC 27001:2022: Mandatory Clause: 7.2; Annex A Controls: 5.4; Control 5.4
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-007; OG-WRL-010
- PCI DSS: 12.1.4; 12.6.1; 6.2.2; 12.10.6; 12.1.3
- SCF: GOV-01; GOV-04; RSK-01
- SP 800-53 Rev 5.1.1: PM-02; PM-19; PM-23; PM-24; PM-29
- SP 800-53 Rev 5.2.0: PM-02; PM-19; PM-23; PM-24; PM-29
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
- SSDF: PO.2.3
|
| GV.RR-02
|
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
|
- Ex1: Document risk management roles and responsibilities in policy
- Ex2: Document who is responsible and accountable for cybersecurity risk management activities and how those teams and individuals are to be consulted and informed
- Ex3: Include cybersecurity responsibilities and performance requirements in personnel descriptions
- Ex4: Document performance goals for personnel with cybersecurity risk management responsibilities, and periodically measure performance to identify areas for improvement
- Ex5: Clearly articulate cybersecurity responsibilities within operations, risk functions, and internal audit functions
|
- CCMv4.0: CEK-02; GRC-06; HRS-02; HRS-03; HRS-06; HRS-08; HRS-09; HRS-13; SEF-08; STA-02; STA-04; UEM-14
- CIS Controls v8.0: 14.9
- CIS Controls v8.1: 14.9
- CRI Profile v2.0: GV.RR-02; GV.RR-02.01; GV.RR-02.02; GV.RR-02.03; GV.RR-02.04; GV.RR-02.05; GV.RR-02.06; GV.RR-02.07
- CSF v1.1: ID.AM-6; ID.GV-2; DE.DP-1
- CoP: B4; E1; E2
- ISO/IEC 27001:2022: Mandatory Clause: 7.2; Annex A Controls: None; Control 5.2; Control 5.3
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-007; OG-WRL-010
- OWASP Top 10 LLM Applications: LLM06-2025
- PCI DSS: 1.1.2; 2.1.2; 3.1.2; 4.1.2; 5.1.2; 6.1.2; 7.1.2; 8.1.2; 9.1.2; 10.1.2; 11.1.2; 12.1.3
- SCF: GOV-04; HRS-02; HRS-03; TPM-05.4
- SDOS: SDOS-AD-01; SDOS-EN-02; SDOS-GV-01
- SP 800-221A: GV.RR-1; GV.RR-2; GV.OV-2
- SP 800-53 Rev 5.1.1: PM-02; PM-13; PM-19; PM-23; PM-24; PM-29
- SP 800-53 Rev 5.2.0: PM-02; PM-13; PM-19; PM-23; PM-24; PM-29
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
- SSDF: PO.2.1
|
| GV.RR-03
|
Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
|
- Ex1: Conduct periodic management reviews to ensure that those given cybersecurity risk management responsibilities have the necessary authority
- Ex2: Identify resource allocation and investment in line with risk tolerance and response
- Ex3: Provide adequate and sufficient people, process, and technical resources to support the cybersecurity strategy
|
- CRI Profile v2.0: GV.RR-03; GV.RR-03.01; GV.RR-03.02; GV.RR-03.03
- CSF v1.1: ID.RM-1
- CoP: B3
- IRP: IRP-Sec-4
- ISO/IEC 27001:2022: Mandatory Clause: 7.1, 7.2; Annex A Controls:; Control 6.6
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-007; OG-WRL-010
- PCI DSS: 12.1.4; 12.10.3
- SCF: PRM-01; PRM-02; PRM-03
- SP 800-221A: GV.RR-2
- SP 800-53 Rev 5.1.1: PM-03
- SP 800-53 Rev 5.2.0: PM-03
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
| GV.RR-04
|
Cybersecurity is included in human resources practices
|
- Ex1: Integrate cybersecurity risk management considerations into human resources processes (e.g., personnel screening, onboarding, change notification, offboarding)
- Ex2: Consider cybersecurity knowledge to be a positive factor in hiring, training, and retention decisions
- Ex3: Conduct background checks prior to onboarding new personnel for sensitive roles, and periodically repeat background checks for personnel with such roles
- Ex4: Define and enforce obligations for personnel to be aware of, adhere to, and uphold security policies as they relate to their roles
|
- CCMv4.0: HRS-01; HRS-05; HRS-06; HRS-07; HRS-08; HRS-10; IAM-07
- CIS Controls v8.0: 6.1; 6.2
- CIS Controls v8.1: 6.1; 6.2
- CRI Profile v2.0: GV.RR-04; GV.RR-04.01; GV.RR-04.02; GV.RR-04.03
- CSF v1.1: PR.IP-11
- CoP: C1
- ISO/IEC 27001:2022: Mandatory Clause: 7.3; Annex A Controls: 6.1; Annex A Controls: 6.2; Annex A Controls: 6.3; Annex A Controls: 6.4; Annex A Controls: 6.5; Annex A Controls: 6.6; Annex A Controls: 6.7; Annex A Controls: 6.8
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-010
- PCI DSS: 12.7.1; 12.6.3; 7.2.2; 8.2.5; 9.3.1.1
- SCF: HRS-01
- SP 800-171 Rev 3: 03.15.01
- SP 800-53 Rev 5.1.1: PM-13; PS-01; PS-07; PS-09
- SP 800-53 Rev 5.2.0: PM-13; PS-01; PS-07; PS-09
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
Policy (GV.PO)
Category GV.PO
| Outcome
|
Organizational cybersecurity policy is established, communicated, and enforced
|
| Informative References
|
- CRI Profile v2.0: GV.PO
- CSF v1.1: ID.GV-1
- ISO/IEC 27001:2022: Mandatory Clause: 5.2; Annex A Controls: 5.3; Annex A Controls: 5.36
- NICE Framework: IO-WRL-003; OG-WRL-002; OG-WRL-007; OG-WRL-010
- SCF: GOV-02; HRS-07
- SP 800-221A: GV.PO-1
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
GV.PO Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| GV.PO-01
|
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
|
- Ex1: Create, disseminate, and maintain an understandable, usable risk management policy with statements of management intent, expectations, and direction
- Ex2: Periodically review policy and supporting processes and procedures to ensure that they align with risk management strategy objectives and priorities, as well as the high-level direction of the cybersecurity policy
- Ex3: Require approval from senior management on policy
- Ex4: Communicate cybersecurity risk management policy and supporting processes and procedures across the organization
- Ex5: Require personnel to acknowledge receipt of policy when first hired, annually, and whenever policy is updated
|
- BXAIOS: Chapter 3 - The Charter (POP Framework)
- CCMv4.0: A&A-01; AIS-01; BCR-01; CCC-01; CEK-01; DCS-01; DCS-02; DCS-03; DCS-04; DSP-01; GRC-01; HRS-01; HRS-02; HRS-03; HRS-04; HRS-09; IAM-01; IAM-02; IPY-01; IVS-01; LOG-01; SEF-01; SEF-02; STA-01; TVM-01; TVM-02; UEM-01; UEM-05
- CRI Profile v2.0: GV.PO-01; GV.PO-01.01; GV.PO-01.02; GV.PO-01.03; GV.PO-01.04; GV.PO-01.05; GV.PO-01.06; GV.PO-01.07; GV.PO-01.08
- CSF v1.1: ID.GV-1
- CoP: C2
- Guardian-SDK: GS-CF-01
- IRP: IRP-Sec-5
- ISO/IEC 27001:2022: Mandatory Clause: 5.2; Annex A Controls: 5.1; Control 5.1; Control 5.37; Control 6.1; Control 6.2; Control 6.4; Control 6.5; Control 6.7; Control 6.8
- NICE Framework: IO-WRL-003; OG-WRL-002; OG-WRL-007; OG-WRL-010
- OWASP Top 10 LLM Applications: LLM02-2025; LLM06-2025
- PCI DSS: 12.1.1; 12.6.1; 12.1.4; 12.1.2; 12.1.3
- SCF: GOV-02; HRS-07
- SDOS: SDOS-GV-01; SDOS-GV-03; SDOS-GV-04; SDOS-GV-05
- SP 800-171 Rev 3: 03.15.01
- SP 800-221A: GV.PO-1
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
| GV.PO-02
|
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
|
- Ex1: Update policy based on periodic reviews of cybersecurity risk management results to ensure that policy and supporting processes and procedures adequately maintain risk at an acceptable level
- Ex2: Provide a timeline for reviewing changes to the organization's risk environment (e.g., changes in risk or in the organization's mission objectives), and communicate recommended policy updates
- Ex3: Update policy to reflect changes in legal and regulatory requirements
- Ex4: Update policy to reflect changes in technology (e.g., adoption of artificial intelligence) and changes to the business (e.g., acquisition of a new business, new contract requirements)
|
- CCMv4.0: A&A-01; AIS-01; BCR-01; CCC-01; CEK-01; DCS-01; DCS-02; DCS-03; DCS-04; DSP-01; GRC-01; GRC-03; HRS-01; HRS-02; HRS-03; HRS-04; IAM-01; IAM-02; IPY-01; IVS-01; LOG-01; SEF-01; SEF-02; STA-01; TVM-01; TVM-02; UEM-01; UEM-05
- CRI Profile v2.0: GV.PO-02; GV.PO-02.01
- CSF v1.1: ID.GV-1
- CoP: C2; E1
- ISO/IEC 27001:2022: Mandatory Clause: 5.2; Annex A Controls: 5.1; Control 5.31; Control 5.32; Control 5.34
- NICE Framework: IO-WRL-003; OG-WRL-002; OG-WRL-007; OG-WRL-010
- PCI DSS: 12.1.2; 1.1.1; 2.1.1; 3.1.1; 4.1.1; 5.1.1; 6.1.1; 7.1.1; 8.1.1; 9.1.1; 10.1.1; 11.1.1
- SCF: GOV-03; HRS-07
- SDOS: SDOS-AU-01; SDOS-GV-01; SDOS-GV-04; SDOS-GV-05
- SP 800-171 Rev 3: 03.15.01
- SP 800-221A: GV.PO-1
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
Oversight (GV.OV)
Category GV.OV
| Outcome
|
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy
|
| Informative References
|
- CRI Profile v2.0: GV.OV
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Mandatory Clause: 8.2; Mandatory Clause: 8.3; Mandatory Clause: 9.1; Mandatory Clause: 10.2; Annex A Controls: 5.1; Annex A Controls: 5.19
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-007; OG-WRL-016
- SCF: GOV-05; GOV-03
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Select Step: TASK S-5 Continuous Monitoring Strategy— System; RMF Authorize Step: TASK R-3 Risk Response; RMF Monitor Step: TASK M-2 Ongoing Assessments; RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
GV.OV Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| GV.OV-01
|
Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
|
- Ex1: Measure how well the risk management strategy and risk results have helped leaders make decisions and achieve organizational objectives
- Ex2: Examine whether cybersecurity risk strategies that impede operations or innovation should be adjusted
|
- CRI Profile v2.0: GV.OV-01; GV.OV-01.01; GV.OV-01.02; GV.OV-01.03
- CoP: E1
- ISO/IEC 27001:2022: Mandatory Clause: 9.1; Annex A Controls: 5.1; Annex A Controls: 5.19; Control 5.5; Control 5.6; Control 5.24
- NICE Framework: OG-WRL-002; OG-WRL-007; OG-WRL-016
- PCI DSS: 12.3.1; 12.10.6; 12.10.2; 12.4.2; 12.4.2.1; 10.7.1; 10.7.2
- SCF: GOV-05; GOV-03
- SDOS: SDOS-AU-01; SDOS-RS-01
- SP 800-171 Rev 3: 03.11.01; 03.11.04; 03.15.01
- SP 800-221A: GV.AD-3
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; PM-09; PM-18; PM-30; PM-31; RA-07; SR-06
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; PM-09; PM-18; PM-30; PM-31; RA-07; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Select Step: TASK S-5 Continuous Monitoring Strategy— System; RMF Authorize Step: TASK R-3 Risk Response; RMF Monitor Step: TASK M-2 Ongoing Assessments; RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
| GV.OV-02
|
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
|
- Ex1: Review audit findings to confirm whether the existing cybersecurity strategy has ensured compliance with internal and external requirements
- Ex2: Review the performance oversight of those in cybersecurity-related roles to determine whether policy changes are necessary
- Ex3: Review strategy in light of cybersecurity incidents
|
- CRI Profile v2.0: GV.OV-02; GV.OV-02.01; GV.OV-02.02
- CoP: E1
- Guardian-SDK: GS-PO-02
- ISO/IEC 27001:2022: Mandatory Clause: 9.1; Annex A Controls: 5.1; Annex A Controls: 5.19; Control 5.27; Control 5.35; Control 5.36
- NICE Framework: OG-WRL-002; OG-WRL-007
- PCI DSS: 12.10.6; 12.10.2; 12.4.2; 12.4.2.1; 12.5.3; 12.8.4; 10.7.1; 10.7.2; 11.4.4; 12.3.4; 12.5.2
- SCF: GOV-03; RSK-01
- SDOS: SDOS-AU-01; SDOS-RS-01
- SP 800-171 Rev 3: 03.11.01; 03.11.04
- SP 800-221A: GV.AD-2; GV.AD-3; MA.RM-8
- SP 800-53 Rev 5.1.1: PM-09; PM-19; PM-30; PM-31; RA-07; SR-06
- SP 800-53 Rev 5.2.0: PM-09; PM-19; PM-30; PM-31; RA-07; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
| GV.OV-03
|
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
|
- Ex1: Review key performance indicators (KPIs) to ensure that organization-wide policies and procedures achieve objectives
- Ex2: Review key risk indicators (KRIs) to identify risks the organization faces, including likelihood and potential impact
- Ex3: Collect and communicate metrics on cybersecurity risk management with senior leadership
|
- CCMv4.0: AIS-03
- CRI Profile v2.0: GV.OV-03; GV.OV-03.01; GV.OV-03.02
- CoP: E1
- ISO/IEC 27001:2022: Mandatory Clause: 9.1; Annex A Controls: 5.1; Annex A Controls: 5.19; Annex A Controls: 5.20; Control 8.30; Control 8.32; Control 8.34
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-007
- PCI DSS: 12.4.2; 10.7.2; 7.2.5.1; 11.3.1; 11.3.2; 11.4.4; 12.3.1; 12.3.4
- SCF: GOV-05; RSK-01
- SDOS: SDOS-AU-01; SDOS-AU-02; SDOS-RS-01
- SP 800-171 Rev 3: 03.11.01; 03.11.04
- SP 800-221A: GV.OV-2; MA.RM-2
- SP 800-53 Rev 5.1.1: PM-04; PM-06; RA-07; SR-06
- SP 800-53 Rev 5.2.0: PM-04; PM-06; RA-07; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Authorize Step: TASK R-3 Risk Response; RMF Monitor Step: TASK M-2 Ongoing Assessments; RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
Cybersecurity Supply Chain Risk Management (GV.SC)
Category GV.SC
| Outcome
|
Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders
|
| Informative References
|
- CRI Profile v2.0: GV.SC
- CSF v1.1: ID.SC
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Annex A Controls: 5.1; Annex A Controls: 5.19; Annex A Controls: 5.20
- NICE Framework: DD-WRL-001; IO-WRL-003; IO-WRL-005; OG-WRL-002; OG-WRL-003; OG-WRL-006; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016; PD-WRL-003
- SCF: GOV-01; GOV-05; RSK-01; RSK-09; RSK-09.1; TPM-03
- SP 800-221A: GV.OV-4
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
GV.SC Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| GV.SC-01
|
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
|
- Ex1: Establish a strategy that expresses the objectives of the cybersecurity supply chain risk management program
- Ex2: Develop the cybersecurity supply chain risk management program, including a plan (with milestones), policies, and procedures that guide implementation and improvement of the program, and share the policies and procedures with the organizational stakeholders
- Ex3: Develop and implement program processes based on the strategy, objectives, policies, and procedures that are agreed upon and performed by the organizational stakeholders
- Ex4: Establish a cross-organizational mechanism that ensures alignment between functions that contribute to cybersecurity supply chain risk management, such as cybersecurity, IT, operations, legal, human resources, and engineering
|
- CCMv4.0: STA-01; STA-06; STA-08
- CIS Controls v8.0: 15.2
- CIS Controls v8.1: 15.2
- CRI Profile v2.0: GV.SC-01; GV.SC-01.01; GV.SC-01.02
- CSF v1.1: ID.SC-1
- CoP: A4
- IRP: IRP-Sec-1
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Annex A Controls: 5.1; Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.21; Annex A Controls: 5.22; Control 5.19; Control 5.21
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025; LLM04-2025
- PCI DSS: 12.8.1; 12.8.3; 12.8.4; 12.8.5; 12.9.1; 12.9.2; 12.1.4; 1.2.3; 1.2.4; 6.3.1; 6.3.2; 6.4.3; 11.6.1
- SCF: GOV-01; GOV-02; RSK-01; RSK-09
- SP 800-171 Rev 3: 03.17.01; 03.17.03
- SP 800-221A: GV.PO-1
- SP 800-53 Rev 5.1.1: PM-30; SR-02; SR-03
- SP 800-53 Rev 5.2.0: PM-30; SR-02; SR-03
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-9 System Stakeholders
|
| GV.SC-02
|
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
|
- Ex1: Identify one or more specific roles or positions that will be responsible and accountable for planning, resourcing, and executing cybersecurity supply chain risk management activities
- Ex2: Document cybersecurity supply chain risk management roles and responsibilities in policy
- Ex3: Create responsibility matrixes to document who will be responsible and accountable for cybersecurity supply chain risk management activities and how those teams and individuals will be consulted and informed
- Ex4: Include cybersecurity supply chain risk management responsibilities and performance requirements in personnel descriptions to ensure clarity and improve accountability
- Ex5: Document performance goals for personnel with cybersecurity risk management-specific responsibilities, and periodically measure them to demonstrate and improve performance
- Ex6: Develop roles and responsibilities for suppliers, customers, and business partners to address shared responsibilities for applicable cybersecurity risks, and integrate them into organizational policies and applicable third-party agreements
- Ex7: Internally communicate cybersecurity supply chain risk management roles and responsibilities for third parties
- Ex8: Establish rules and protocols for information sharing and reporting processes between the organization and its suppliers
|
- CCMv4.0: HRS-09; HRS-10; HRS-13; IAM-11; STA-01; STA-02; STA-03; STA-04; STA-05; STA-06; STA-12; UEM-14
- CIS Controls v8.0: 15.4
- CIS Controls v8.1: 15.4
- CRI Profile v2.0: GV.SC-02; GV.SC-02.01
- CSF v1.1: ID.AM-6
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 5.3; Annex A Controls: 5.2; Annex A Controls: 5.4
- NICE Framework: OG-WRL-002; OG-WRL-003; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.8.3; 12.8.4; 12.1.4; 12.10.1
- SCF: TPM-05; TPM-05.2; TPM-05.4
- SP 800-171 Rev 3: 03.17.02; 03.17.03
- SP 800-221A: GV.RR-1; GV.RR-2
- SP 800-53 Rev 5.1.1: SR-02; SR-03; SR-05
- SP 800-53 Rev 5.2.0: SR-02; SR-03; SR-05
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles
- SSDF: PO.2.1
|
| GV.SC-03
|
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
|
- Ex1: Identify areas of alignment and overlap with cybersecurity and enterprise risk management
- Ex2: Establish integrated control sets for cybersecurity risk management and cybersecurity supply chain risk management
- Ex3: Integrate cybersecurity supply chain risk management into improvement processes
- Ex4: Escalate material cybersecurity risks in supply chains to senior management, and address them at the enterprise risk management level
|
- CCMv4.0: STA-01; STA-06; STA-08; STA-11; STA-12; UEM-14
- CRI Profile v2.0: GV.SC-03; GV.SC-03.01
- CSF v1.1: ID.SC-2
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Annex A Controls: 5.1; Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.21
- NICE Framework: OG-WRL-002; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 6.4.3; 6.2.3; 12.8.3; 12.3.4; 11.6.1; 6.3.2; 6.3.1
- SCF: GOV-01; GOV-02; RSK-01; RSK-09
- SP 800-171 Rev 3: 03.11.01; 03.11.04; 03.15.01; 03.17.01; 03.17.03
- SP 800-221A: GV.CT-2; GV.CT-3
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; PM-09; PM-18; PM-30; PM-31; SR-02; SR-03; RA-03; RA-07
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; PM-09; PM-18; PM-30; PM-31; SR-02; SR-03; RA-03; RA-07
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
- SSDF: PW.4.1
|
| GV.SC-04
|
Suppliers are known and prioritized by criticality
|
- Ex1: Develop criteria for supplier criticality based on, for example, the sensitivity of data processed or possessed by suppliers, the degree of access to the organization's systems, and the importance of the products or services to the organization's mission
- Ex2: Keep a record of all suppliers, and prioritize suppliers based on the criticality criteria
|
- CCMv4.0: STA-07
- CIS Controls v8.0: 15.1; 15.3
- CIS Controls v8.1: 15.1; 15.3
- CRI Profile v2.0: GV.SC-04; GV.SC-04.01
- CSF v1.1: ID.SC-2
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Mandatory Clause: 6.1.3; Annex A Controls: 5.19; Annex A Controls: 5.22
- NICE Framework: IO-WRL-003; OG-WRL-002; OG-WRL-009; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.8.1; 12.8.3; 12.8.4; 12.8.5; 12.8.2; 12.5.2; 1.2.4; 6.3.2
- SCF: AST-01; TPM-01; TPM-02
- SDOS: SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.11.01; 03.16.03
- SP 800-221A: GV.CT-2; GV.CT-3
- SP 800-53 Rev 5.1.1: RA-09; SA-09; SR-06
- SP 800-53 Rev 5.2.0: RA-09; SA-09; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-10 Asset Identification; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
|
| GV.SC-05
|
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties
|
- Ex1: Establish security requirements for suppliers, products, and services commensurate with their criticality level and potential impact if compromised
- Ex2: Include all cybersecurity and supply chain requirements that third parties must follow and how compliance with the requirements may be verified in default contractual language
- Ex3: Define the rules and protocols for information sharing between the organization and its suppliers and sub-tier suppliers in agreements
- Ex4: Manage risk by including security requirements in agreements based on their criticality and potential impact if compromised
- Ex5: Define security requirements in service-level agreements (SLAs) for monitoring suppliers for acceptable security performance throughout the supplier relationship lifecycle
- Ex6: Contractually require suppliers to disclose cybersecurity features, functions, and vulnerabilities of their products and services for the life of the product or the term of service
- Ex7: Contractually require suppliers to provide and maintain a current component inventory (e.g., software or hardware bill of materials) for critical products
- Ex8: Contractually require suppliers to vet their employees and guard against insider threats
- Ex9: Contractually require suppliers to provide evidence of performing acceptable security practices through, for example, self-attestation, conformance to known standards, certifications, or inspections
- Ex10: Specify in contracts and other agreements the rights and responsibilities of the organization, its suppliers, and their supply chains, with respect to potential cybersecurity risks
|
- CCMv4.0: CCC-05; CEK-08; DSP-13; DSP-14; IPY-04; STA-02; STA-03; STA-04; STA-08; STA-09; STA-12; STA-13; UEM-14
- CIS Controls v8.0: 15.4
- CIS Controls v8.1: 15.4
- CRI Profile v2.0: EX.CN; EX.CN-01; EX.CN-02; EX.CN-01.01; EX.CN-01.02; EX.CN-01.03; EX.CN-02.01; EX.CN-02.02; EX.CN-02.03; EX.CN-02.04
- CSF v1.1: ID.SC-3
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 4.2 (a); Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.31; Control 5.20
- NICE Framework: IO-WRL-003; OG-WRL-002; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025; LLM04-2025
- PCI DSS: 12.8.2; 12.9.1; 12.9.2; 12.8.5; 12.8.3; 12.8.1
- SCF: CPL-01; RSK-01; RSK-09; TPM-05; TPM-05.2
- SDOS: SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.11.01; 03.16.03; 03.17.02; 03.17.03
- SP 800-53 Rev 5.1.1: SA-04; SA-09; SR-03; SR-05; SR-06; SR-10
- SP 800-53 Rev 5.2.0: SA-04; SA-09; SR-03; SR-05; SR-06; SR-10
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
- SSDF: PO.1.3
|
| GV.SC-06
|
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
|
- Ex1: Perform thorough due diligence on prospective suppliers that is consistent with procurement planning and commensurate with the level of risk, criticality, and complexity of each supplier relationship
- Ex2: Assess the suitability of the technology and cybersecurity capabilities and the risk management practices of prospective suppliers
- Ex3: Conduct supplier risk assessments against business and applicable cybersecurity requirements
- Ex4: Assess the authenticity, integrity, and security of critical products prior to acquisition and use
|
- CCMv4.0: STA-01; STA-08; STA-11
- CIS Controls v8.0: 15.5
- CIS Controls v8.1: 15.5
- CRI Profile v2.0: EX.DD; EX.DD-01; EX.DD-02; EX.DD-01.01; EX.DD-01.02; EX.DD-01.03; EX.DD-02.01; EX.DD-02.02; EX.DD-02.03; EX.DD-02.04
- CSF v1.1: ID.SC-1
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 4.2 (a); Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.31
- NICE Framework: OG-WRL-002; OG-WRL-006; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025; LLM04-2025
- PCI DSS: 12.8.3; 12.8.1; 12.8.5; 12.8.2; 12.5.2; 1.2.4; 1.2.3
- SCF: TPM-01; TPM-02; TPM-03; TPM-03.2; TPM-03.3; TPM-04; TPM-04.1; TPM-04.3; TPM-04.4; TPM-05; TPM-05.2; TPM-05.4; TPM-05.7
- SP 800-171 Rev 3: 03.11.01; 03.16.03; 03.17.02
- SP 800-221A: GV.PO-1
- SP 800-53 Rev 5.1.1: SA-04; SA-09; SR-05; SR-06
- SP 800-53 Rev 5.2.0: SA-04; SA-09; SR-05; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
|
| GV.SC-07
|
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
|
- Ex1: Adjust assessment formats and frequencies based on the third party's reputation and the criticality of the products or services they provide
- Ex2: Evaluate third parties' evidence of compliance with contractual cybersecurity requirements, such as self-attestations, warranties, certifications, and other artifacts
- Ex3: Monitor critical suppliers to ensure that they are fulfilling their security obligations throughout the supplier relationship lifecycle using a variety of methods and techniques, such as inspections, audits, tests, or other forms of evaluation
- Ex4: Monitor critical suppliers, services, and products for changes to their risk profiles, and reevaluate supplier criticality and risk impact accordingly
- Ex5: Plan for unexpected supplier and supply chain-related interruptions to ensure business continuity
|
- CCMv4.0: STA-01; STA-08; STA-10; STA-11; STA-12; STA-13; STA-14; UEM-14
- CIS Controls v8.0: 15.6
- CIS Controls v8.1: 15.6
- CRI Profile v2.0: EX.MM; EX.MM-01; EX.MM-02; EX.MM-01.01; EX.MM-01.02; EX.MM-01.03; EX.MM-01.04; EX.MM-01.05; EX.MM-01.06; EX.MM-02.01; EX.MM-02.02; EX.MM-02.03
- CSF v1.1: ID.SC-2; ID.SC-4
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Mandatory Clause: 6.1.3; Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.31; Control 5.22
- NICE Framework: OG-WRL-002; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025; LLM04-2025
- PCI DSS: 12.8.4; 12.9.2; 12.9.1; 12.8.5; 12.8.2; 12.8.3; 12.8.1; 12.5.2; 1.2.4; 6.3.2; 6.3.1; 6.4.3; 11.6.1
- SCF: TPM-01; TPM-02; TPM-03; TPM-03.2; TPM-03.3; TPM-04; TPM-04.1; TPM-08
- SDOS: SDOS-AU-02; SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.11.01; 03.16.03; 03.17.03
- SP 800-221A: GV.CT-2; GV.CT-3; MA.RM-2; MA.RM-3
- SP 800-53 Rev 5.1.1: RA-09; SA-04; SA-09; SR-03; SR-06
- SP 800-53 Rev 5.2.0: RA-09; SA-04; SA-09; SR-03; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Select Step: TASK S-5 Continuous Monitoring Strategy— System; RMF Assess Step: TASK A-3 Control Assessments; RMF Assess Step: TASK A-5 Remediation Actions; RMF Assess Step: TASK A-6 Plan of Action and Milestones; RMF Authorize Step: TASK R-2 Risk Analysis and Determination; RMF Authorize Step: TASK R-3 Risk Response; RMF Monitor Step: TASK M-1 System and Environment Changes; RMF Monitor Step: TASK M-2 Ongoing Assessments; RMF Monitor Step: TASK M-3 Ongoing Risk Response
- SSDF: PW.4.1; PW.4.4
|
| GV.SC-08
|
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
|
- Ex1: Define and use rules and protocols for reporting incident response and recovery activities and the status between the organization and its suppliers
- Ex2: Identify and document the roles and responsibilities of the organization and its suppliers for incident response
- Ex3: Include critical suppliers in incident response exercises and simulations
- Ex4: Define and coordinate crisis communication methods and protocols between the organization and its critical suppliers
- Ex5: Conduct collaborative lessons learned sessions with critical suppliers
|
- CCMv4.0: BCR-06; BCR-07; DSP-18; SEF-03; SEF-04; SEF-07; UEM-14
- CIS Controls v8.0: 15.4
- CIS Controls v8.1: 15.4
- CRI Profile v2.0: GV.SC-08; GV.SC-08.01
- CSF v1.1: ID.SC-5
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: IO-WRL-005; OG-WRL-002; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.10.5; 12.10.1; 12.8.5; 12.8.1; 1.2.4; 1.2.3; 12.10.2; 12.10.6; 12.8.2; 12.9.1
- SCF: BCD-01; BCD-01.2; IRO-01; IRO-02; IRO-02.5; TPM-01; TPM-02; TPM-10; TPM-11
- SDOS: SDOS-AU-02; SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.06.01; 03.06.02; 03.06.05; 03.15.01; 03.16.03; 03.17.01; 03.17.03
- SP 800-221A: GV.CT-3
- SP 800-53 Rev 5.1.1: SA-04; SA-09; SR-02; SR-03; SR-08; CP-01; IR-01
- SP 800-53 Rev 5.2.0: SA-04; SA-09; SR-02; SR-03; SR-08; CP-01; IR-01
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-9 System Stakeholders; RMF Monitor Step: TASK M-1 System and Environment Changes; RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
| GV.SC-09
|
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle
|
- Ex1: Policies and procedures require provenance records for all acquired technology products and services
- Ex2: Periodically provide risk reporting to leaders about how acquired components are proven to be untampered and authentic
- Ex3: Communicate regularly among cybersecurity risk managers and operations personnel about the need to acquire software patches, updates, and upgrades only from authenticated and trustworthy software providers
- Ex4: Review policies to ensure that they require approved supplier personnel to perform maintenance on supplier products
- Ex5: Policies and procedure require checking upgrades to critical hardware for unauthorized changes
|
- CCMv4.0: STA-11; STA-12
- CIS Controls v8.0: 15.6
- CIS Controls v8.1: 15.6
- CRI Profile v2.0: GV.SC-09; GV.SC-09.01
- CSF v1.1: ID.SC-1
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.21; Annex A Controls: 5.22
- NICE Framework: DD-WRL-001; OG-WRL-002; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 6.4.3; 9.5.1.1; 9.5.1.2; 9.5.1.2.1; 6.3.1; 6.3.3; 11.6.1; 6.2.3; 12.3.4; 12.8.4; 6.3.2; 12.8.1; 12.8.5
- SCF: GOV-01; GOV-05; PRM-07; RSK-01; RSK-09; RSK-09.1; SEA-07.1; TDA-01.1
- SDOS: SDOS-AU-02; SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.11.01; 03.11.04; 03.16.03; 03.17.01; 03.17.02; 03.17.03
- SP 800-221A: GV.PO-1
- SP 800-53 Rev 5.1.1: PM-09; PM-19; PM-28; PM-30; PM-31; RA-03; RA-07; SA-04; SA-09; SR-02; SR-03; SR-05; SR-06
- SP 800-53 Rev 5.2.0: PM-09; PM-19; PM-28; PM-30; PM-31; RA-03; RA-07; SA-04; SA-09; SR-02; SR-03; SR-05; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O
|
| GV.SC-10
|
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
|
- Ex1: Establish processes for terminating critical relationships under both normal and adverse circumstances
- Ex2: Define and implement plans for component end-of-life maintenance support and obsolescence
- Ex3: Verify that supplier access to organization resources is deactivated promptly when it is no longer needed
- Ex4: Verify that assets containing the organization's data are returned or properly disposed of in a timely, controlled, and safe manner
- Ex5: Develop and execute a plan for terminating or transitioning supplier relationships that takes supply chain security risk and resiliency into account
- Ex6: Mitigate risks to data and systems created by supplier termination
- Ex7: Manage data leakage risks associated with supplier termination
|
- CCMv4.0: DSP-02; DSP-16; HRS-05; IAM-07; IPY-04; SEF-04
- CIS Controls v8.0: 15.7
- CIS Controls v8.1: 15.7
- CRI Profile v2.0: EX.TR; EX.TR-01; EX.TR-02; EX.TR-01.01; EX.TR-01.02; EX.TR-01.03; EX.TR-02.01
- CSF v1.1: ID.SC-1
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Mandatory Clause: 6.1.3; Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.21; Annex A Controls: 5.22
- NICE Framework: OG-WRL-002; OG-WRL-009; OG-WRL-012; OG-WRL-015; OG-WRL-016
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.8.2; 12.8.5; 12.8.3; 8.2.5; 9.3.1.1; 12.3.4; 6.4.3; 12.10.1; 12.5.2; 1.2.4; 1.2.3; 3.2.1; 9.4.7; 9.4.6
- SCF: RSK-09; TPM-01; TPM-05.2
- SP 800-171 Rev 3: 03.11.01; 03.11.02; 03.11.04; 03.14.08; 03.16.03; 03.17.01; 03.17.02; 03.17.03
- SP 800-221A: GV.PO-1
- SP 800-53 Rev 5.1.1: PM-31; RA-03; RA-05; RA-07; SA-04; SA-09; SR-02; SR-03; SR-05; SR-06
- SP 800-53 Rev 5.2.0: PM-31; RA-03; RA-05; RA-07; SA-04; SA-09; SR-02; SR-03; SR-05; SR-06
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-15 Requirements Definition; RMF Monitor Step: TASK M-7 System Disposal
|
IDENTIFY (ID)
Function ID
| Outcome
|
The organization's current cybersecurity risks are understood
|
| Informative References
|
- CRI Profile v2.0: ID
- CSF v1.1: ID
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Mandatory Clause: 8.2; Mandatory Clause: 8.3; Mandatory Clause: 10.2; Annex A Controls: None
- SCF: RSK-01; RSK-01.1; RSK-04; RSK-09
|
Asset Management (ID.AM)
Category ID.AM
| Outcome
|
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy
|
| Informative References
|
- CRI Profile v2.0: ID.AM
- CSF v1.1: ID.AM
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.9; Annex A Controls: 5.12; Annex A Controls: 5.13
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-003; DD-WRL-004; DD-WRL-005; DD-WRL-009; IO-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-004; IO-WRL-005; OG-WRL-011; OG-WRL-015
- SCF: AST-01; AST-02; AST-03; AST-03.1; HRS-01; HRS-03; HRS-05; HRS-05.1; PES-01; RSK-02; TPM-01; TPM-05.4
- SP 800-221A: MA.RI-1
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification
|
ID.AM Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| ID.AM-01
|
Inventories of hardware managed by the organization are maintained
|
- Ex1: Maintain inventories for all types of hardware, including IT, IoT, OT, and mobile devices
- Ex2: Constantly monitor networks to detect new hardware and automatically update inventories
|
- CCMv4.0: CCC-04; DCS-06; DSP-19; UEM-04
- CIS Controls v8.0: 1.1
- CIS Controls v8.1: 1.1
- CRI Profile v2.0: ID.AM-01; ID.AM-01.01
- CSF v1.1: ID.AM-1
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.9; Control 5.9
- NICE Framework: DD-WRL-002; DD-WRL-009; IO-WRL-002; IO-WRL-003; IO-WRL-004; IO-WRL-005; OG-WRL-015
- PCI DSS: 12.5.1; 9.5.1.1; 1.2.3; 9.5.1.2
- SCF: AST-02
- SP 800-221A: MA.RI-1
- SP 800-53 Rev 5.1.1: CM-08; PM-05
- SP 800-53 Rev 5.2.0: CM-08; PM-05
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification
|
| ID.AM-02
|
Inventories of software, services, and systems managed by the organization are maintained
|
- Ex1: Maintain inventories for all types of software and services, including commercial-off-the-shelf, open-source, custom applications, API services, and cloud-based applications and services
- Ex2: Constantly monitor all platforms, including containers and virtual machines, for software and service inventory changes
- Ex3: Maintain an inventory of the organization's systems
|
- BXAIOS: Chapter 5 - Blueprint the Ecosystem
- CCMv4.0: CCC-04; DCS-06; DSP-19; UEM-02; UEM-04
- CIS Controls v8.0: 2.1
- CIS Controls v8.1: 2.1
- CRI Profile v2.0: ID.AM-02; ID.AM-02.01
- CSF v1.1: ID.AM-2
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.9
- NICE Framework: DD-WRL-002; DD-WRL-005; DD-WRL-009; IO-WRL-002; IO-WRL-003; IO-WRL-004; IO-WRL-005; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM03-2025; LLM10-2025
- PCI DSS: 6.3.2; 12.5.1; 12.8.1; 6.4.3
- SCF: AST-02
- SDOS: SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.04.10; 03.16.03
- SP 800-221A: MA.RI-1
- SP 800-53 Rev 5.1.1: AC-20; CM-08; PM-05; SA-05; SA-09
- SP 800-53 Rev 5.2.0: AC-20; CM-08; PM-05; SA-05; SA-09
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification
|
| ID.AM-03
|
Representations of the organization's authorized network communication and internal and external network data flows are maintained
|
- Ex1: Maintain baselines of communication and data flows within the organization's wired and wireless networks
- Ex2: Maintain baselines of communication and data flows between the organization and third parties
- Ex3: Maintain baselines of communication and data flows for the organization's infrastructure-as-a-service (IaaS) usage
- Ex4: Maintain documentation of expected network ports, protocols, and services that are typically used among authorized systems
|
- CCMv4.0: DSP-05; DSP-10; IPY-01; IVS-03; IVS-09; LOG-05
- CIS Controls v8.0: 3.8
- CIS Controls v8.1: 3.8
- CRI Profile v2.0: ID.AM-03; ID.AM-03.01
- CSF v1.1: ID.AM-3; DE.AE-1
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.14; Annex A Controls: 8.20; Annex A Controls: 8.21; Annex A Controls: 8.22
- NICE Framework: DD-WRL-002; DD-WRL-009; IO-WRL-002; IO-WRL-003; IO-WRL-004; IO-WRL-005; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM05-2025
- PCI DSS: 1.2.3; 1.2.4; 12.5.2
- SCF: AST-04; DCH-19
- SDOS: SDOS-AU-01; SDOS-EN-04; SDOS-GV-04
- SP 800-171 Rev 3: 03.12.05; 03.15.02
- SP 800-53 Rev 5.1.1: AC-04; CA-03; CA-09; PL-02; PL-08; PM-07
- SP 800-53 Rev 5.2.0: AC-04; CA-03; CA-09; PL-02; PL-08; PM-07
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-11 Authorization Boundary; RMF Prepare Step (System Level): TASK P-13 Information Life Cycle; RMF Prepare Step (System Level): TASK P-16 Enterprise Architecture
|
| ID.AM-04
|
Inventories of services provided by suppliers are maintained
|
- Ex1: Inventory all external services used by the organization, including third-party infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS), and software-as-a-service (SaaS) offerings; APIs; and other externally hosted application services
- Ex2: Update the inventory when a new external service is going to be utilized to ensure adequate cybersecurity risk management monitoring of the organization's use of that service
|
- CCMv4.0: CCC-04; DCS-06; STA-07; UEM-02; UEM-04
- CIS Controls v8.0: 15.1
- CIS Controls v8.1: 15.1
- CRI Profile v2.0: ID.AM-04; ID.AM-04.01
- CSF v1.1: ID.AM-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.22
- NICE Framework: DD-WRL-002; IO-WRL-002; IO-WRL-003; IO-WRL-004; IO-WRL-005; OG-WRL-011; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.8.1; 12.8.5; 12.8.3; 12.8.4
- SDOS: SDOS-AU-02; SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.16.03; 03.17.01
- SP 800-53 Rev 5.1.1: AC-20; SA-09; SR-02
- SP 800-53 Rev 5.2.0: AC-20; SA-09; SR-02
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification
|
| ID.AM-05
|
Assets are prioritized based on classification, criticality, resources, and impact on the mission
|
- Ex1: Define criteria for prioritizing each class of assets
- Ex2: Apply the prioritization criteria to assets
- Ex3: Track the asset priorities and update them periodically or when significant changes to the organization occur
|
- CCMv4.0: CEK-04; DCS-05; DSP-04
- CIS Controls v8.0: 3.7
- CIS Controls v8.1: 3.7
- CRI Profile v2.0: ID.AM-05; ID.AM-05.01; ID.AM-05.02
- CSF v1.1: ID.AM-5
- CoP: A1
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.9; Annex A Controls: 5.12; Annex A Controls: 5.13
- NICE Framework: DD-WRL-001; DD-WRL-002; IO-WRL-002; IO-WRL-003; IO-WRL-004; IO-WRL-005; OG-WRL-011; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM02-2025; LLM04-2025
- PCI DSS: 12.3.1; 6.3.1; 9.5.1.2.1; 10.4.2.1; 11.6.1
- SCF: AST-04.1; BCD-02; TPM-02
- SP 800-221A: MA.RI-1
- SP 800-53 Rev 5.1.1: RA-03; RA-09; RA-02
- SP 800-53 Rev 5.2.0: RA-03; RA-09; RA-02
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-6 Impact-Level Prioritization (Opt; RMF Prepare Step (System Level): TASK P-8 Mission or Business Focus; RMF Prepare Step (System Level): TASK P-10 Asset Identification; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
|
| ID.AM-06
|
[Withdrawn: Incorporated into GV.RR-02, GV.SC-02]
|
| ID.AM-07
|
Inventories of data and corresponding metadata for designated data types are maintained
|
- Ex1: Maintain a list of the designated data types of interest (e.g., personally identifiable information, protected health information, financial account numbers, organization intellectual property, operational technology data)
- Ex2: Continuously discover and analyze ad hoc data to identify new instances of designated data types
- Ex3: Assign data classifications to designated data types through tags or labels
- Ex4: Track the provenance, data owner, and geolocation of each instance of designated data types
|
- CCMv4.0: DSP-01; DSP-03; DSP-04; DSP-06; DSP-10; DSP-19; UEM-02
- CIS Controls v8.0: 3.2
- CIS Controls v8.1: 3.2
- CRI Profile v2.0: ID.AM-07; ID.AM-07.01
- Guardian-SDK: GS-TT-05
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.9
- NICE Framework: DD-WRL-002; IO-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-005; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM02-2025; LLM04-2025; LLM08-2025
- PCI DSS: 12.5.2; 3.2.1; 3.4.1; 3.4.2; 12.10.7
- SCF: DCH-06; PRI-05; PRI-05.5
- SP 800-171 Rev 3: 03.14.08
- SP 800-221A: MA.RI-1
- SP 800-53 Rev 5.1.1: CM-12; CM-13; SI-12
- SP 800-53 Rev 5.2.0: CM-12; CM-13; SI-12
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-12 Information Types; RMF Prepare Step (System Level): TASK P-13 Information Life Cycle
|
| ID.AM-08
|
Systems, hardware, software, services, and data are managed throughout their life cycles
|
- Ex1: Integrate cybersecurity considerations throughout the life cycles of systems, hardware, software, and services
- Ex2: Integrate cybersecurity considerations into product life cycles
- Ex3: Identify unofficial uses of technology to meet mission objectives (i.e., shadow IT)
- Ex4: Periodically identify redundant systems, hardware, software, and services that unnecessarily increase the organization's attack surface
- Ex5: Properly configure and secure systems, hardware, software, and services prior to their deployment in production
- Ex6: Update inventories when systems, hardware, software, and services are moved or transferred within the organization
- Ex7: Securely destroy stored data based on the organization's data retention policy using the prescribed destruction method, and keep and manage a record of the destructions
- Ex8: Securely sanitize data storage when hardware is being retired, decommissioned, reassigned, or sent for repairs or replacement
- Ex9: Offer methods for destroying paper, storage media, and other physical forms of data storage
|
- CCMv4.0: AIS-02; AIS-04; AIS-05; AIS-06; AIS-07; CCC-04; CEK-14; CEK-21; DCS-01; DCS-02; DSP-02; DSP-07; DSP-16; DSP-19; HRS-05; IVS-01; LOG-02; LOG-06; UEM-03; UEM-05; UEM-09; UEM-10; UEM-11; UEM-13
- CIS Controls v8.0: 1.1; 3.5
- CIS Controls v8.1: 1.1; 3.5
- CRI Profile v2.0: ID.AM-08; ID.AM-08.01; ID.AM-08.02; ID.AM-08.03; ID.AM-08.04; ID.AM-08.05; ID.AM-08.06
- CSF v1.1: PR.DS-3; PR.IP-2; PR.MA-1; PR.MA-2; PR.IP-6; PR.DS
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.8; Annex A Controls: 5.9; Annex A Controls: 5.12; Annex A Controls: 5.13; Annex A Controls: 5.19; Annex A Controls: 5.22; Annex A Controls: 7.10; Annex A Controls: 7.13; Annex A Controls: 7.14; Control 5.11
- NICE Framework: DD-WRL-002; DD-WRL-003; DD-WRL-004; IO-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-004; IO-WRL-005; OG-WRL-015
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 6.2.2; 6.2.1; 6.2.3; 6.2.3.1; 6.2.4; 6.3.1; 6.3.3; 12.3.4; 11.6.1
- SCF: AST-01; DCH-01; DCH-01.1; PRM-07; SEA-07; SEA-07.1
- SDOS: SDOS-GV-01; SDOS-IA-02
- SP 800-171 Rev 3: 03.14.08; 03.15.02; 03.16.01; 03.16.02; 03.17.02
- SP 800-221A: MA.RI-1
- SP 800-53 Rev 5.1.1: CM-09; CM-13; MA-02; MA-06; PL-02; PM-22; PM-23; SA-03; SA-04; SA-08; SA-22; SI-12; SI-18; SR-05; SR-12
- SP 800-53 Rev 5.2.0: CM-09; CM-13; MA-02; MA-06; PL-02; PM-22; PM-23; SA-03; SA-04; SA-08; SA-22; SI-12; SI-18; SR-05; SR-12
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification; RMF Prepare Step (System Level): TASK P-12 Information Types; RMF Prepare Step (System Level): TASK P-13 Information Life Cycle; RMF Monitor Step: TASK M-7 System Disposal
- SSDF: PW.4.1; PW.4.4
|
Risk Assessment (ID.RA)
Category ID.RA
| Outcome
|
The cybersecurity risk to the organization, assets, and individuals is understood by the organization
|
| Informative References
|
- CRI Profile v2.0: ID.RA
- CSF v1.1: ID.RA
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Mandatory Clause: 6.1.3; Annex A Controls: None
- NICE Framework: DD-WRL-005; DD-WRL-008; IO-WRL-006; OG-WRL-009; OG-WRL-010; OG-WRL-011; OG-WRL-012; OG-WRL-013; OG-WRL-014; OG-WRL-015; OG-WRL-016; PD-WRL-006; PD-WRL-007
- SCF: GOV-01; GOV-02; RSK-01; RSK-09
- SP 800-221A: GV.BE-4
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Categorize Step: TASK C-2 Security Categorization; RMF Categorize Step: TASK C-3 Security Categorization Review and Approval; RMF Authorize Step: TASK R-2 Risk Analysis and Determination; RMF Authorize Step: TASK R-4 Authorization Decision; RMF Authorize Step: TASK R-5 Authorization Reporting
|
ID.RA Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| ID.RA-01
|
Vulnerabilities in assets are identified, validated, and recorded
|
- Ex1: Use vulnerability management technologies to identify unpatched and misconfigured software
- Ex2: Assess network and system architectures for design and implementation weaknesses that affect cybersecurity
- Ex3: Review, analyze, or test organization-developed software to identify design, coding, and default configuration vulnerabilities
- Ex4: Assess facilities that house critical computing assets for physical vulnerabilities and resilience issues
- Ex5: Monitor sources of cyber threat intelligence for information on new vulnerabilities in products and services
- Ex6: Review processes and procedures for weaknesses that could be exploited to affect cybersecurity
|
- AI-SOC: AI-SOC-21; AI-SOC-15
- CCMv4.0: AIS-05; AIS-07; TVM-01; TVM-03; TVM-05; TVM-06; TVM-07; TVM-08; TVM-09; TVM-10
- CIS Controls v8.0: 7.1
- CIS Controls v8.1: 7.1
- CRI Profile v2.0: ID.RA-01; ID.RA-01.01; ID.RA-01.02; ID.RA-01.03
- CSF v1.1: ID.RA-1; PR.IP-12; DE.CM-8
- CoP: A5
- Guardian-SDK: GS-TT-01; GS-TT-02; GS-TT-03; GS-TT-04; GS-TT-14; GS-TT-15; GS-TT-16
- IRP: IRP-Sec-2
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.8
- NICE Framework: DD-WRL-005; IO-WRL-006; OG-WRL-012; OG-WRL-013; OG-WRL-014; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM01-2025; LLM05-2025; LLM07-2025; LLM08-2025
- PCI DSS: 11.3.1; 11.3.2; 6.3.1; 11.4.4; 6.3.2
- SCF: IAO-01; IAO-02; IAO-05; RSK-04; TDA-09; VPM-01; VPM-06
- SDOS: SDOS-AU-02; SDOS-IN-01
- SP 800-171 Rev 3: 03.11.01; 03.11.02; 03.12.01; 03.12.03; 03.14.03; 03.14.06
- SP 800-221A: MA.RI-3
- SP 800-53 Rev 5.1.1: CA-02; CA-07; CA-08; RA-03; RA-05; SA-11(02); SA-15(07); SA-15(08); SI-04; SI-05
- SP 800-53 Rev 5.2.0: CA-02; CA-07; CA-08; RA-03; RA-05; SA-11(02); SA-15(07); SA-15(08); SI-04; SI-05
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Assess Step: TASK A-3 Control Assessments; RMF Monitor Step: TASK M-1 System and Environment Changes; RMF Monitor Step: TASK M-2 Ongoing Assessments
- SSDF: PO.5.2
|
| ID.RA-02
|
Cyber threat intelligence is received from information sharing forums and sources
|
- Ex1: Configure cybersecurity tools and technologies with detection or response capabilities to securely ingest cyber threat intelligence feeds
- Ex2: Receive and review advisories from reputable third parties on current threat actors and their tactics, techniques, and procedures (TTPs)
- Ex3: Monitor sources of cyber threat intelligence for information on the types of vulnerabilities that emerging technologies may have
|
- AI-SOC: AI-SOC-05; AI-SOC-13
- CCMv4.0: GRC-08; TVM-04
- CRI Profile v2.0: ID.RA-02; ID.RA-02.01; ID.RA-02.02
- CSF v1.1: ID.RA-2
- CoP: A5
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.7; Annex A Controls: 5.22; Annex A Controls: 8.16; Control 5.7
- NICE Framework: IO-WRL-006; OG-WRL-013; OG-WRL-014; PD-WRL-006; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM01-2025; LLM03-2025; LLM04-2025
- SCF: GOV-07; THR-03
- SDOS: SDOS-DE-01
- SP 800-171 Rev 3: 03.11.01
- SP 800-221A: GV.BE-4
- SP 800-53 Rev 5.1.1: SI-05; PM-15; PM-16
- SP 800-53 Rev 5.2.0: SI-05; PM-15; PM-16
- SP 800-81r3: 1.2; 2.1.1; 2.3.3
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
|
| ID.RA-03
|
Internal and external threats to the organization are identified and recorded
|
- Ex1: Use cyber threat intelligence to maintain awareness of the types of threat actors likely to target the organization and the TTPs they are likely to use
- Ex2: Perform threat hunting to look for signs of threat actors within the environment
- Ex3: Implement processes for identifying internal threat actors
|
- AI-SOC: AI-SOC-05; AI-SOC-13
- CCMv4.0: A&A-05; TVM-05
- CRI Profile v2.0: ID.RA-03; ID.RA-03.01; ID.RA-03.02; ID.RA-03.03; ID.RA-03.04
- CSF v1.1: ID.RA-3
- CoP: A5
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Mandatory Clause: 6.1.3; Annex A Controls: 5.7; Annex A Controls: 5.22; Annex A Controls: 8.16
- NICE Framework: IO-WRL-006; OG-WRL-013; OG-WRL-014; PD-WRL-006; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM01-2025; LLM04-2025; LLM06-2025; LLM10-2025
- PCI DSS: 12.3.1
- SCF: THR-01; THR-03; THR-04; THR-05; THR-07
- SDOS: SDOS-AD-01; SDOS-AU-02
- SP 800-171 Rev 3: 03.11.01; 03.14.03
- SP 800-221A: MA.RI-2
- SP 800-53 Rev 5.1.1: PM-12; PM-16; RA-03; SI-05
- SP 800-53 Rev 5.2.0: PM-12; PM-16; RA-03; SI-05
- SP 800-81r3: 2.1.3
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Assess Step: TASK A-3 Control Assessments; RMF Monitor Step: TASK M-1 System and Environment Changes; RMF Monitor Step: TASK M-2 Ongoing Assessments
|
| ID.RA-04
|
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
|
- Ex1: Business leaders and cybersecurity risk management practitioners work together to estimate the likelihood and impact of risk scenarios and record them in risk registers
- Ex2: Enumerate the potential business impacts of unauthorized access to the organization's communications, systems, and data processed in or by those systems
- Ex3: Account for the potential impacts of cascading failures for systems of systems
|
- AI-SOC: AI-SOC-21; AI-SOC-17
- CCMv4.0: A&A-05; BCR-02; CEK-06; CEK-07; CEK-20; TVM-09
- CRI Profile v2.0: ID.RA-04; ID.RA-04.01
- CSF v1.1: ID.RA-4
- CoP: A5
- Guardian-SDK: GS-TT-06; GS-TT-07
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Mandatory Clause: 6.1.3; Annex A Controls: None
- NICE Framework: IO-WRL-006; OG-WRL-013; OG-WRL-014; PD-WRL-006; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM09-2025
- PCI DSS: 12.3.1
- SDOS: SDOS-RM-01; SDOS-RM-02
- SP 800-171 Rev 3: 03.11.01
- SP 800-221A: MA.RI-4
- SP 800-53 Rev 5.1.1: PM-09; PM-11; RA-02; RA-03; RA-08; RA-09
- SP 800-53 Rev 5.2.0: PM-09; PM-11; RA-02; RA-03; RA-08; RA-09
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
|
| ID.RA-05
|
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
|
- Ex1: Develop threat models to better understand risks to the data and identify appropriate risk responses
- Ex2: Prioritize cybersecurity resource allocations and investments based on estimated likelihoods and impacts
|
- CCMv4.0: A&A-05; BCR-02; CEK-07; CEK-20; TVM-01; TVM-08
- CRI Profile v2.0: ID.RA-05; ID.RA-05.01; ID.RA-05.02; ID.RA-05.03; ID.RA-05.04
- CSF v1.1: ID.RA-5
- CoP: A5
- Guardian-SDK: GS-TT-09
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Mandatory Clause: 6.1.2; Mandatory Clause: 6.1.3; Annex A Controls: 5.7
- NICE Framework: DD-WRL-008; IO-WRL-006; OG-WRL-013; OG-WRL-014; PD-WRL-006; PD-WRL-007
- PCI DSS: 12.3.1; 6.3.1; 6.3.3; 11.3.1.1
- SCF: RSK-01.1; RSK-02.1; RSK-04; RSK-06.1
- SDOS: SDOS-RM-01; SDOS-RM-03
- SP 800-171 Rev 3: 03.11.01; 03.11.04
- SP 800-221A: MA.RA-2
- SP 800-53 Rev 5.1.1: PM-16; RA-02; RA-03; RA-07
- SP 800-53 Rev 5.2.0: PM-16; RA-02; RA-03; RA-07
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Authorize Step: TASK R-2 Risk Analysis and Determination; RMF Authorize Step: TASK R-3 Risk Response
- SSDF: PW.1.1
|
| ID.RA-06
|
Risk responses are chosen, prioritized, planned, tracked, and communicated
|
- Ex1: Apply the vulnerability management plan's criteria for deciding whether to accept, transfer, mitigate, or avoid risk
- Ex2: Apply the vulnerability management plan's criteria for selecting compensating controls to mitigate risk
- Ex3: Track the progress of risk response implementation (e.g., plan of action and milestones [POA&M], risk register, risk detail report)
- Ex4: Use risk assessment findings to inform risk response decisions and actions
- Ex5: Communicate planned risk responses to affected stakeholders in priority order
|
- CCMv4.0: A&A-05; A&A-06; AIS-07; CEK-07; TVM-01; TVM-03; TVM-08; TVM-09; TVM-10
- CRI Profile v2.0: ID.RA-06; ID.RA-06.01; ID.RA-06.02; ID.RA-06.03; ID.RA-06.04; ID.RA-06.05; ID.RA-06.06
- CSF v1.1: ID.RA-6; RS.MI-3
- CoP: A5
- ISO/IEC 27001:2022: Mandatory Clause: 6.13; Annex A Controls: 5.7
- NICE Framework: IO-WRL-006; OG-WRL-010; OG-WRL-011; OG-WRL-013; OG-WRL-014; PD-WRL-006; PD-WRL-007
- PCI DSS: 6.3.3; 11.3.1; 11.3.2; 12.10.1
- SCF: RSK-01.1; RSK-02.1; RSK-06.1
- SDOS: SDOS-GV-02; SDOS-RM-01
- SP 800-171 Rev 3: 03.11.04
- SP 800-221A: MA.RP
- SP 800-53 Rev 5.1.1: PM-09; PM-18; PM-30; RA-07
- SP 800-53 Rev 5.2.0: PM-09; PM-18; PM-30; RA-07
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Assess Step: TASK A-5 Remediation Actions; RMF Assess Step: TASK A-6 Plan of Action and Milestones; RMF Authorize Step: TASK R-3 Risk Response; RMF Monitor Step: TASK M-3 Ongoing Risk Response; RMF Monitor Step: TASK M-6 Ongoing Authorization
- SSDF: PO.5.2
|
| ID.RA-07
|
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
|
- Ex1: Implement and follow procedures for the formal documentation, review, testing, and approval of proposed changes and requested exceptions
- Ex2: Document the possible risks of making or not making each proposed change, and provide guidance on rolling back changes
- Ex3: Document the risks related to each requested exception and the plan for responding to those risks
- Ex4: Periodically review risks that were accepted based upon planned future actions or milestones
|
- AI-SOC: AI-SOC-21; AI-SOC-05
- CCMv4.0: A&A-05; AIS-06; CCC-02; CCC-03; CCC-06; CCC-08; CCC-09; CEK-05; CEK-06; GRC-04; UEM-07
- CRI Profile v2.0: ID.RA-07; ID.RA-07.01; ID.RA-07.02; ID.RA-07.03; ID.RA-07.04; ID.RA-07.05
- CSF v1.1: PR.IP-3
- CoP: A5
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.3; Annex A Controls: 8.32
- NICE Framework: IO-WRL-006; OG-WRL-010; OG-WRL-011; OG-WRL-013; OG-WRL-014; PD-WRL-006; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM03-2025; LLM04-2025
- PCI DSS: 12.3.1; 12.3.2; 10.4.2.1; 9.5.1.2.1; 8.6.3
- SCF: CHG-01; CHG-02; CHG-02.1; CHG-02.2; CHG-03; CHG-04
- SDOS: SDOS-AU-01; SDOS-GV-01; SDOS-GV-04; SDOS-IN-01
- SP 800-171 Rev 3: 03.04.03; 03.04.04
- SP 800-221A: MA.RI-3
- SP 800-53 Rev 5.1.1: CA-07; CM-03; CM-04
- SP 800-53 Rev 5.2.0: CA-07; CM-03; CM-04
- SP-800-37 Rev 2: RMF Select Step: TASK S-4 Documentation of Planned Control Implementations; RMF Implement Step: TASK I-2 Update Control Implementation Information; RMF Assess Step: TASK A-6 Plan of Action and Milestones
- SSDF: PO.5.2
|
| ID.RA-08
|
Processes for receiving, analyzing, and responding to vulnerability disclosures are established
|
- Ex1: Conduct vulnerability information sharing between the organization and its suppliers following the rules and protocols defined in contracts
- Ex2: Assign responsibilities and verify the execution of procedures for processing, analyzing the impact of, and responding to cybersecurity threat, vulnerability, or incident disclosures by suppliers, customers, partners, and government cybersecurity organizations
|
- AI-SOC: AI-SOC-21; AI-SOC-05
- CCMv4.0: AIS-07; TVM-03; TVM-09
- CIS Controls v8.0: 7.2
- CIS Controls v8.1: 7.2
- CRI Profile v2.0: ID.RA-08; ID.RA-08.01; ID.RA-08.02
- CSF v1.1: RS.AN-5
- CoP: A5
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.2; Annex A Controls: None
- NICE Framework: IO-WRL-006; OG-WRL-013; OG-WRL-014; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM01-2025; LLM05-2025
- SCF: THR-01; THR-03; VPM-01; VPM-02
- SDOS: SDOS-GV-01
- SP 800-171 Rev 3: 03.11.02
- SP 800-221A: MA.RI-3
- SP 800-53 Rev 5.1.1: RA-05
- SP 800-53 Rev 5.2.0: RA-05
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (System Level): TASK P-15 Requirements Definition; RMF Authorize Step: TASK R-3 Risk Response; RMF Monitor Step: TASK M-2 Ongoing Assessments; RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
| ID.RA-09
|
The authenticity and integrity of hardware and software are assessed prior to acquisition and use
|
- Ex1: Assess the authenticity and cybersecurity of critical technology products and services prior to acquisition and use
|
- AI-SOC: AI-SOC-21; AI-SOC-05
- CCMv4.0: TVM-09
- CRI Profile v2.0: EX.DD-04; EX.DD-04.01; EX.DD-04.02
- CSF v1.1: PR.DS-8
- CoP: A5
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.22
- NICE Framework: IO-WRL-006; OG-WRL-014; OG-WRL-015; PD-WRL-006; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM03-2025; LLM04-2025
- PCI DSS: 6.4.3; 9.5.1.1
- SCF: AST-15; TDA-01; TDA-14; TDA-14.1; TDA-14.2
- SDOS: SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.11.01; 03.17.02
- SP 800-221A: MA.RI-3
- SP 800-53 Rev 5.1.1: SA-04; SA-05; SA-10; SA-11; SA-15; SA-17; SI-07; SR-05; SR-06; SR-10; SR-11
- SP 800-53 Rev 5.2.0: SA-04; SA-05; SA-10; SA-11; SA-15; SA-17; SI-07; SR-05; SR-06; SR-10; SR-11
- SP-800-37 Rev 2: RMF Prepare Step (System Level): TASK P-10 Asset Identification; RMF Assess Step: TASK A-3 Control Assessments
- SSDF: PO.5.2
|
| ID.RA-10
|
Critical suppliers are assessed prior to acquisition
|
- Ex1: Conduct supplier risk assessments against business and applicable cybersecurity requirements, including the supply chain
|
- AI-SOC: AI-SOC-21; AI-SOC-05
- CCMv4.0: STA-08
- CRI Profile v2.0: EX.DD-03; EX.DD-03.01; EX.DD-03.02; EX.DD-03.03
- CSF v1.1: ID.SC-2; ID.SC-4
- CoP: A4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.19; Annex A Controls: 5.20; Annex A Controls: 5.22
- NICE Framework: IO-WRL-006; OG-WRL-009; OG-WRL-013; OG-WRL-014; OG-WRL-015; OG-WRL-016; PD-WRL-006; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.8.3; 12.8.1; 12.8.2
- SCF: TPM-02; TPM-04.1
- SDOS: SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.11.01
- SP 800-221A: GV.CT-2; GV.CT-3; MA.RM-2; MA.RM-3
- SP 800-53 Rev 5.1.1: SR-06
- SP 800-53 Rev 5.2.0: SR-06
- SP 800-81r3: 2.1.2
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (System Level): TASK P-10 Asset Identification; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System
|
Improvement (ID.IM)
Category ID.IM
| Outcome
|
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
|
| Informative References
|
- CRI Profile v2.0: ID.IM
- CSF v1.1: RS.IM; RC.IM; PR.IP-7; DE.DP-5
- ISO/IEC 27001:2022: Mandatory Clause: 10.1; Mandatory Clause: 10.2; Annex A Controls: None
- NICE Framework: DD-WRL-003; DD-WRL-004; DD-WRL-006; DD-WRL-007; DD-WRL-008; IO-WRL-005; IO-WRL-006; OG-WRL-009; OG-WRL-010; OG-WRL-016; PD-WRL-003
- SCF: OPS-01; OPS-01.1; RSK-01; RSK-09
- SP 800-221A: MA.IM-1
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy
|
ID.IM Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| ID.IM-01
|
Improvements are identified from evaluations
|
- Ex1: Perform self-assessments of critical services that take current threats and TTPs into consideration
- Ex2: Invest in third-party assessments or independent audits of the effectiveness of the organization's cybersecurity program to identify areas that need improvement
- Ex3: Constantly evaluate compliance with selected cybersecurity requirements through automated means
|
- CCMv4.0: A&A-02; A&A-03; A&A-04; A&A-05; CEK-09; SEF-04; SEF-05; STA-06; STA-11; STA-13
- CRI Profile v2.0: ID.IM-01; ID.IM-01.01; ID.IM-01.02; ID.IM-01.03; ID.IM-01.04; ID.IM-01.05
- Guardian-SDK: GS-PO-02
- ISO/IEC 27001:2022: Mandatory Clause: 9.2; Mandatory Clause: 10.1; Mandatory Clause: 10.2; Annex A Controls: 5.35
- NICE Framework: DD-WRL-004; DD-WRL-006; DD-WRL-007; DD-WRL-008; OG-WRL-016; PD-WRL-003
- PCI DSS: 12.4.2; 12.4.2.1; 12.3.1; 12.3.4
- SCF: CPL-03; CPL-03.2; IAO-02; IAO-05; TDA-09; TDA-09.1; TPM-04.1; TPM-08
- SDOS: SDOS-AU-01; SDOS-RS-01
- SP 800-171 Rev 3: 03.06.01; 03.06.05; 03.11.01; 03.11.02; 03.11.04; 03.12.01; 03.12.02; 03.12.03; 03.14.01; 03.14.06; 03.15.01; 03.15.02; 03.16.01; 03.17.02
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; CA-02; CA-05; CA-07; CA-08; CP-02; IR-04; IR-08; PL-02; RA-03; RA-05; RA-07; SA-08; SA-11; SA-17(06); SI-02; SI-04; SR-05
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; CA-02; CA-05; CA-07; CA-08; CP-02; IR-04; IR-08; PL-02; RA-03; RA-05; RA-07; SA-08; SA-11; SA-17(06); SI-02; SI-04; SR-05
- SP 800-81r3: 1.2; 3.8.5
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Assess Step: TASK A-3 Control Assessments; RMF Assess Step: TASK A-4 Assessment Reports; RMF Assess Step: TASK A-5 Remediation Actions; RMF Assess Step: TASK A-6 Plan of Action and Milestones; RMF Monitor Step: TASK M-2 Ongoing Assessments
|
| ID.IM-02
|
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
|
- Ex1: Identify improvements for future incident response activities based on findings from incident response assessments (e.g., tabletop exercises and simulations, tests, internal reviews, independent audits)
- Ex2: Identify improvements for future business continuity, disaster recovery, and incident response activities based on exercises performed in coordination with critical service providers and product suppliers
- Ex3: Involve internal stakeholders (e.g., senior executives, legal department, HR) in security tests and exercises as appropriate
- Ex4: Perform penetration testing to identify opportunities to improve the security posture of selected high-risk systems as approved by leadership
- Ex5: Exercise contingency plans for responding to and recovering from the discovery that products or services did not originate with the contracted supplier or partner or were altered before receipt
- Ex6: Collect and analyze performance metrics using security tools and services to inform improvements to the cybersecurity program
|
- CCMv4.0: BCR-06; BCR-07; BCR-10; SEF-01; SEF-03; SEF-04; SEF-05; STA-14; TVM-06; UEM-14
- CIS Controls v8.0: 17.7
- CIS Controls v8.1: 17.7
- CRI Profile v2.0: ID.IM-02; ID.IM-02.01; ID.IM-02.02; ID.IM-02.03; ID.IM-02.04; ID.IM-02.05; ID.IM-02.06; ID.IM-02.07; ID.IM-02.08; ID.IM-02.09
- CSF v1.1: ID.SC-5; PR.IP-10; DE.DP-3
- CoP: D2
- ISO/IEC 27001:2022: Mandatory Clause: 9.2; Mandatory Clause: 9.3; Mandatory Clause: 10.1; Mandatory Clause: 10.2; Annex A Controls: 5.19; Annex A Controls: 5.35
- NICE Framework: DD-WRL-004; DD-WRL-006; DD-WRL-007; OG-WRL-009; OG-WRL-016; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM01-2025; LLM05-2025
- PCI DSS: 12.10.2; 12.10.6; 11.4.4; 12.8.4
- SCF: BCD-05; CPL-03; CPL-03.2; IAO-02; IAO-05; IRO-13; TDA-09; TDA-09.1; TPM-04.1; TPM-08
- SDOS: SDOS-AU-01; SDOS-RS-01
- SP 800-171 Rev 3: 03.06.01; 03.06.03; 03.06.05; 03.11.01; 03.11.02; 03.11.04; 03.12.01; 03.12.02; 03.12.03; 03.14.01; 03.14.06; 03.15.01; 03.15.02; 03.16.01; 03.17.02
- SP 800-221A: GV.CT-3
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; CA-02; CA-05; CA-07; CA-08; CP-02; CP-04; IR-03; IR-04; IR-08; PL-02; PM-04; PM-31; RA-03; RA-05; RA-07; SA-08; SA-11; SI-02; SI-04; SR-05
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; CA-02; CA-05; CA-07; CA-08; CP-02; CP-04; IR-03; IR-04; IR-08; PL-02; PM-04; PM-31; RA-03; RA-05; RA-07; SA-08; SA-11; SI-02; SI-04; SR-05
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Assess Step: TASK A-3 Control Assessments; RMF Assess Step: TASK A-4 Assessment Reports; RMF Assess Step: TASK A-5 Remediation Actions; RMF Assess Step: TASK A-6 Plan of Action and Milestones; RMF Monitor Step: TASK M-2 Ongoing Assessments
|
| ID.IM-03
|
Improvements are identified from execution of operational processes, procedures, and activities
|
- Ex1: Conduct collaborative lessons learned sessions with suppliers
- Ex2: Annually review cybersecurity policies, processes, and procedures to take lessons learned into account
- Ex3: Use metrics to assess operational cybersecurity performance over time
|
- CCMv4.0: A&A-01; AIS-01; AIS-03; BCR-01; CCC-01; CEK-01; DCS-01; DCS-02; DCS-03; DCS-04; DSP-01; GRC-01; HRS-01; HRS-02; HRS-03; HRS-04; IAM-01; IAM-02; IPY-01; IVS-01; LOG-01; SEF-01; SEF-02; SEF-04; STA-01; TVM-01; TVM-02; UEM-01
- CRI Profile v2.0: ID.IM-03; ID.IM-03.01; ID.IM-03.02
- CSF v1.1: PR.IP-7; PR.IP-8; DE.DP-5; RS.IM-1; RS.IM-2; RC.IM-1; RC.IM-2
- ISO/IEC 27001:2022: Mandatory Clause: 9.1; Annex A Controls: 5.27
- NICE Framework: DD-WRL-003; DD-WRL-004; DD-WRL-006; DD-WRL-007; IO-WRL-005; IO-WRL-006; OG-WRL-016; PD-WRL-003
- PCI DSS: 10.7.1; 10.7.2; 11.3.1; 11.3.2; 6.3.3
- SCF: GOV-05; BCD-05; IRO-13
- SDOS: SDOS-AU-01; SDOS-AU-02; SDOS-RS-01
- SP 800-171 Rev 3: 03.06.01; 03.06.05; 03.11.01; 03.11.02; 03.11.04; 03.12.01; 03.12.02; 03.12.03; 03.14.01; 03.14.06; 03.15.01; 03.15.02; 03.16.01; 03.17.02
- SP 800-221A: GV.AD-1; MA.RM-6; MA.IM-1
- SP 800-53 Rev 5.1.1: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; CA-02; CA-05; CA-07; CA-08; CP-02; IR-04; IR-08; PL-02; PM-04; PM-31; RA-03; RA-05; RA-07; SA-04; SA-08; SA-11; SI-02; SI-04; SR-05
- SP 800-53 Rev 5.2.0: AC-01; AT-01; AU-01; CA-01; CM-01; CP-01; IA-01; IR-01; MA-01; MP-01; PE-01; PL-01; PM-01; PS-01; PT-01; RA-01; SA-01; SC-01; SI-01; SR-01; CA-02; CA-05; CA-07; CA-08; CP-02; IR-04; IR-08; PL-02; PM-04; PM-31; RA-03; RA-05; RA-07; SA-04; SA-08; SA-11; SI-02; SI-04; SR-05
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-3 Risk Assessment—Organization; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-7 Continuous Monitoring Strategy—O; RMF Prepare Step (System Level): TASK P-14 Risk Assessment—System; RMF Assess Step: TASK A-3 Control Assessments; RMF Assess Step: TASK A-4 Assessment Reports; RMF Assess Step: TASK A-5 Remediation Actions; RMF Assess Step: TASK A-6 Plan of Action and Milestones; RMF Monitor Step: TASK M-2 Ongoing Assessments
|
| ID.IM-04
|
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
|
- Ex1: Establish contingency plans (e.g., incident response, business continuity, disaster recovery) for responding to and recovering from adverse events that can interfere with operations, expose confidential information, or otherwise endanger the organization's mission and viability
- Ex2: Include contact and communication information, processes for handling common scenarios, and criteria for prioritization, escalation, and elevation in all contingency plans
- Ex3: Create a vulnerability management plan to identify and assess all types of vulnerabilities and to prioritize, test, and implement risk responses
- Ex4: Communicate cybersecurity plans (including updates) to those responsible for carrying them out and to affected parties
- Ex5: Review and update all cybersecurity plans annually or when a need for significant improvements is identified
|
- CCMv4.0: BCR-01; BCR-04; BCR-05; BCR-09; CEK-20; SEF-01; SEF-02; SEF-03; SEF-04; SEF-05
- CRI Profile v2.0: ID.IM-04; ID.IM-04.01; ID.IM-04.02; ID.IM-04.03; ID.IM-04.04; ID.IM-04.05; ID.IM-04.06; ID.IM-04.07; ID.IM-04.08
- CSF v1.1: PR.IP-9; RS.IM-1; RC.IM-1; PR.IP-10
- ISO/IEC 27001:2022: Mandatory Clause: 9.1; Annex A Controls: 5.24; Annex A Controls: 5.26; Annex A Controls: 5.27
- NICE Framework: DD-WRL-004; DD-WRL-006; DD-WRL-007; OG-WRL-010; OG-WRL-016; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM04-2025
- PCI DSS: 12.10.1; 12.10.2; 12.10.6; 12.10.3
- SCF: BCD-01; BCD-06; IRO-04; IRO-04.2
- SP 800-171 Rev 3: 03.06.05; 03.15.02; 03.17.01
- SP 800-221A: MA.RR-4; MA.IM-1
- SP 800-53 Rev 5.1.1: CP-02; IR-08; PL-02; SR-02
- SP 800-53 Rev 5.2.0: CP-02; IR-08; PL-02; SR-02
|
Business Environment (ID.BE)
[Withdrawn: Incorporated into GV.OC]
ID.BE Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| ID.BE-01
|
[Withdrawn: Incorporated into GV.OC-05]
|
| ID.BE-02
|
[Withdrawn: Incorporated into GV.OC-01]
|
| ID.BE-03
|
[Withdrawn: Incorporated into GV.OC-01]
|
| ID.BE-04
|
[Withdrawn: Incorporated into GV.OC-04, GV.OC-05]
|
| ID.BE-05
|
[Withdrawn: Incorporated into GV.OC-04]
|
Governance (ID.GV)
[Withdrawn: Incorporated into GV]
ID.GV Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| ID.GV-01
|
[Withdrawn: Incorporated into GV.PO, GV.PO-01, GV.PO-02]
|
| ID.GV-02
|
[Withdrawn: Incorporated into GV.OC-02, GV.RR, GV.RR-02]
|
| ID.GV-03
|
[Withdrawn: Moved to GV.OC-03]
|
| ID.GV-04
|
[Withdrawn: Moved to GV.RM-04]
|
Risk Management Strategy (ID.RM)
[Withdrawn: Incorporated into GV.RM]
ID.RM Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| ID.RM-01
|
[Withdrawn: Incorporated into GV.RM-01, GV.RM-06, GV.RR-03]
|
| ID.RM-02
|
[Withdrawn: Incorporated into GV.RM-02, GV.RM-04]
|
| ID.RM-03
|
[Withdrawn: Moved into GV.RM-02]
|
Supply Chain Risk Management (ID.SC)
[Withdrawn: Incorporated into GV.SC]
ID.SC Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| ID.SC-01
|
[Withdrawn: Incorporated into GV.RM-05, GV.SC-01, GV.SC-06, GV.SC-09, GV.SC-10]
|
| ID.SC-02
|
[Withdrawn: Incorporated into GV.OC-02, GV.SC-03, GV.SC-04, GV.SC-07, ID.RA-10]
|
| ID.SC-03
|
[Withdrawn: Moved to GV.SC-05]
|
| ID.SC-04
|
[Withdrawn: Incorporated into GV.SC-07, ID.RA-10]
|
| ID.SC-05
|
[Withdrawn: Incorporated into GV.SC-08, ID.IM-02]
|
PROTECT (PR)
Function PR
| Outcome
|
Safeguards to manage the organization's cybersecurity risks are used
|
| Informative References
|
- CRI Profile v2.0: PR
- CSF v1.1: PR
- ISO/IEC 27001:2022: Mandatory Clause: 8.3; Annex A Controls: All applicable controls
- SCF: GOV-01; CPL-01; RSK-01; RSK-09
|
Identity Management, Authentication, and Access Control (PR.AA)
Category PR.AA
| Outcome
|
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access
|
| Informative References
|
- CRI Profile v2.0: PR.AA
- CSF v1.1: PR.AC
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.15; Annex A Controls: 5.18; Annex A Controls: 8.2; Annex A Controls: 8.3
- NICE Framework: DD-WRL-001; DD-WRL-004; IO-WRL-002; IO-WRL-003; IO-WRL-005; OG-WRL-002; OG-WRL-013; OG-WRL-014; PD-WRL-004
- SCF: IAC-01; IAC-01.2; PES-01; PES-02; PES-03
|
PR.AA Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.AA-01
|
Identities and credentials for authorized users, services, and hardware are managed by the organization
|
- Ex1: Initiate requests for new access or additional access for employees, contractors, and others, and track, review, and fulfill the requests, with permission from system or data owners when needed
- Ex2: Issue, manage, and revoke cryptographic certificates and identity tokens, cryptographic keys (i.e., key management), and other credentials
- Ex3: Select a unique identifier for each device from immutable hardware characteristics or an identifier securely provisioned to the device
- Ex4: Physically label authorized hardware with an identifier for inventory and servicing purposes
|
- CCMv4.0: CEK-01; CEK-10; CEK-11; CEK-12; CEK-13; CEK-14; CEK-15; CEK-16; CEK-17; CEK-18; CEK-19; CEK-20; CEK-21; DCS-08; IAM-01; IAM-03; IAM-06; IAM-07; IAM-09; IAM-13; IAM-14; IAM-15; IAM-16; UEM-14
- CIS Controls v8.0: 5.1; 6.7
- CIS Controls v8.1: 5.1; 5.6; 6.7
- CRI Profile v2.0: PR.AA-01; PR.AA-01.01; PR.AA-01.02
- CSF v1.1: PR.AC-1
- IRP: IRP-Sec-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.15; Annex A Controls: 5.18; Annex A Controls: 8.2; Annex A Controls: 8.5; Control 5.16
- NICE Framework: DD-WRL-001; IO-WRL-003; IO-WRL-005; OG-WRL-013; OG-WRL-014; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM02-2025; LLM06-2025
- PCI DSS: 8.2.1; 8.6.2; 8.6.3; 3.6.1; 3.6.1.1; 3.6.1.2; 3.6.1.3; 3.6.1.4; 9.5.1.1; 12.5.1
- SCF: IAC-02; IAC-03; IAC-04; IAC-05
- SDOS: SDOS-IA-01; SDOS-IA-02
- SP 800-171 Rev 3: 03.01.01; 03.05.01; 03.05.02; 03.05.03; 03.05.04; 03.05.05; 03.05.07; 03.05.11; 03.05.12; 03.15.01
- SP 800-53 Rev 5.1.1: AC-01; AC-02; AC-14; IA-01; IA-02; IA-03; IA-04; IA-05; IA-06; IA-07; IA-08; IA-09; IA-10; IA-11
- SP 800-53 Rev 5.2.0: AC-01; AC-02; AC-14; IA-01; IA-02; IA-03; IA-04; IA-05; IA-06; IA-07; IA-08; IA-09; IA-10; IA-11
|
| PR.AA-02
|
Identities are proofed and bound to credentials based on the context of interactions
|
- Ex1: Verify a person's claimed identity at enrollment time using government-issued identity credentials (e.g., passport, visa, driver's license)
- Ex2: Issue a different credential for each person (i.e., no credential sharing)
|
- CCMv4.0: IAM-01; IAM-03; IAM-13; IAM-14; IAM-16; UEM-14
- CRI Profile v2.0: PR.AA-02; PR.AA-02.01
- CSF v1.1: PR.AC-6
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.2; Annex A Controls: 8.3; Annex A Controls: 8.5
- NICE Framework: DD-WRL-001; IO-WRL-003; IO-WRL-005; OG-WRL-013; OG-WRL-014; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM06-2025
- PCI DSS: 12.7.1; 8.2.1; 8.3.5; 8.2.2
- SCF: IAC-28
- SDOS: SDOS-IA-01; SDOS-IA-02
- SP 800-53 Rev 5.1.1: IA-12
- SP 800-53 Rev 5.2.0: IA-12
|
| PR.AA-03
|
Users, services, and hardware are authenticated
|
- Ex1: Require multifactor authentication
- Ex2: Enforce policies for the minimum strength of passwords, PINs, and similar authenticators
- Ex3: Periodically reauthenticate users, services, and hardware based on risk (e.g., in zero trust architectures)
- Ex4: Ensure that authorized personnel can access accounts essential for protecting safety under emergency conditions
|
- CCMv4.0: DCS-08; IAM-01; IAM-02; IAM-14; IAM-16; IVS-03; UEM-05; UEM-06; UEM-14
- CRI Profile v2.0: PR.AA-03; PR.AA-03.01; PR.AA-03.02; PR.AA-03.03
- CSF v1.1: PR.AC-3; PR.AC-7
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.15; Annex A Controls: 5.16; Annex A Controls: 5.17; Annex A Controls: 5.18; Annex A Controls: 8.5; Control 5.17; Control 8.5
- NICE Framework: DD-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-005; OG-WRL-013; OG-WRL-014; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM06-2025; LLM10-2025
- PCI DSS: 8.3.1; 8.3.6; 8.3.7; 8.3.8; 8.3.9; 8.2.8; 9.2.4; 2.2.2; 2.3.1; 3.5.1.3; 8.3.10; 8.3.10.1
- SCF: IAC-01.2; IAC-02; IAC-03; IAC-04; IAC-05
- SDOS: SDOS-AD-01; SDOS-IA-01
- SP 800-171 Rev 3: 03.01.11; 03.05.01; 03.05.02; 03.05.03; 03.05.04; 03.05.07; 03.05.12
- SP 800-53 Rev 5.1.1: AC-07; AC-12; IA-02; IA-03; IA-05; IA-07; IA-08; IA-09; IA-10; IA-11
- SP 800-53 Rev 5.2.0: AC-07; AC-12; IA-02; IA-03; IA-05; IA-07; IA-08; IA-09; IA-10; IA-11
- SP 800-81r3: 3.1; 3.3.2; 3.4.2
- SSDF: PO.5.2
|
| PR.AA-04
|
Identity assertions are protected, conveyed, and verified
|
- Ex1: Protect identity assertions that are used to convey authentication and user information through single sign-on systems
- Ex2: Protect identity assertions that are used to convey authentication and user information between federated systems
- Ex3: Implement standards-based approaches for identity assertions in all contexts, and follow all guidance for the generation (e.g., data models, metadata), protection (e.g., digital signing, encryption), and verification (e.g., signature validation) of identity assertions
|
- CCMv4.0: IAM-01; IAM-03; IAM-16
- CRI Profile v2.0: PR.AA-04; PR.AA-04.01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.16
- NICE Framework: DD-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-005; OG-WRL-013; OG-WRL-014; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM06-2025
- PCI DSS: 12.3.3; 3.6.1; 3.6.1.1; 3.6.1.2; 3.6.1.3; 3.6.1.4; 4.2.1
- SCF: IAC-01.2; IAC-02.2
- SDOS: SDOS-AU-01; SDOS-IA-01
- SP 800-53 Rev 5.1.1: IA-13
- SP 800-53 Rev 5.2.0: IA-13
|
| PR.AA-05
|
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
|
- Ex1: Review logical and physical access privileges periodically and whenever someone changes roles or leaves the organization, and promptly rescind privileges that are no longer needed
- Ex2: Take attributes of the requester and the requested resource into account for authorization decisions (e.g., geolocation, day/time, requester endpoint's cyber health)
- Ex3: Restrict access and privileges to the minimum necessary (e.g., zero trust architecture)
- Ex4: Periodically review the privileges associated with critical business functions to confirm proper separation of duties
|
- BXAIOS: Chapter 6 - Install the Router
- CCMv4.0: CCC-04; CEK-10; CEK-11; CEK-12; CEK-13; CEK-14; CEK-15; CEK-16; CEK-17; CEK-18; CEK-19; CEK-20; CEK-21; IAM-01; IAM-03; IAM-04; IAM-05; IAM-06; IAM-07; IAM-08; IAM-09; IAM-10; IAM-11; IAM-12; IAM-16; IVS-03; IVS-06; LOG-02; LOG-04; LOG-09; UEM-05; UEM-14
- CIS Controls v8.0: 3.3; 6.8
- CIS Controls v8.1: 3.3; 5.1; 6.8
- CRI Profile v2.0: PR.AA-05; PR.AA-05.01; PR.AA-05.02; PR.AA-05.03; PR.AA-05.04
- CSF v1.1: PR.AC-1; PR.AC-3; PR.AC-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.1; Annex A Controls: 5.3; Annex A Controls: 5.14; Annex A Controls: 5.15; Annex A Controls: 5.16; Annex A Controls: 5.17; Annex A Controls: 5.18; Annex A Controls: 8.2; Annex A Controls: 8.3; Annex A Controls: 8.5; Annex A Controls: 8.18; Control 5.15; Control 5.18; Control 8.2; Control 8.3; Control 8.4; Control 8.18
- NICE Framework: DD-WRL-001; DD-WRL-004; IO-WRL-003; IO-WRL-005; OG-WRL-002; OG-WRL-013; OG-WRL-014; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM06-2025; LLM07-2025; LLM08-2025; LLM10-2025
- PCI DSS: 7.2.2; 7.2.4; 7.2.5.1; 8.2.6; 12.1.3; 8.1.1; 7.1.1; 7.2.1
- SCF: HRS-02; HRS-11; IAC-01; IAC-01.2; IAC-02; IAC-03; IAC-04; IAC-05; IAC-08; IAC-21
- SDOS: SDOS-AD-01; SDOS-EN-02; SDOS-GV-01; SDOS-GV-05
- SP 800-171 Rev 3: 03.01.01; 03.01.02; 03.01.04; 03.01.05; 03.01.06; 03.01.07; 03.01.12; 03.01.16; 03.01.18; 03.13.08; 03.15.01
- SP 800-53 Rev 5.1.1: AC-01; AC-02; AC-03; AC-05; AC-06; AC-10; AC-16; AC-17; AC-18; AC-19; AC-24; IA-13
- SP 800-53 Rev 5.2.0: AC-01; AC-02; AC-03; AC-05; AC-06; AC-10; AC-16; AC-17; AC-18; AC-19; AC-24; IA-13
- SP 800-81r3: 3.1.1
- SSDF: PO.5.2; PS.1.1
|
| PR.AA-06
|
Physical access to assets is managed, monitored, and enforced commensurate with risk
|
- Ex1: Use security guards, security cameras, locked entrances, alarm systems, and other physical controls to monitor facilities and restrict access
- Ex2: Employ additional physical security controls for areas that contain high-risk assets
- Ex3: Escort guests, vendors, and other third parties within areas that contain business-critical assets
|
- CCMv4.0: DCS-03; DCS-07; DCS-09; DCS-10; DCS-12; DCS-14; HRS-04; LOG-12; UEM-05; UEM-06; UEM-14
- CRI Profile v2.0: PR.AA-06; PR.AA-06.01; PR.AA-06.02
- CSF v1.1: PR.AC-2; PR.PT-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 7.1; Annex A Controls: 7.2; Annex A Controls: 7.3; Annex A Controls: 7.4; Annex A Controls: 7.12; Control 7.1; Control 7.2; Control 7.3; Control 7.4
- NICE Framework: DD-WRL-001; IO-WRL-005; OG-WRL-013; OG-WRL-014
- PCI DSS: 9.3.1.1; 9.2.4; 9.2.3; 9.5.1.2
- SCF: PES-01; PES-02; PES-02.1; PES-03
- SP 800-171 Rev 3: 03.10.01; 03.10.02; 03.10.07; 03.10.08
- SP 800-53 Rev 5.1.1: PE-02; PE-03; PE-04; PE-05; PE-06; PE-08; PE-18; PE-19; PE-20
- SP 800-53 Rev 5.2.0: PE-02; PE-03; PE-04; PE-05; PE-06; PE-08; PE-18; PE-19; PE-20
- SSDF: PO.5.2
|
Awareness and Training (PR.AT)
Category PR.AT
| Outcome
|
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
|
| Informative References
|
- CRI Profile v2.0: PR.AT
- CSF v1.1: PR.AT
- ISO/IEC 27001:2022: Mandatory Clause: 7.3; Annex A Controls: 6.3
- NICE Framework: IO-WRL-007; OG-WRL-002; OG-WRL-003; OG-WRL-004; OG-WRL-005
- SCF: SAT-01; SAT-02; SAT-03
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-1 Risk Management Roles; RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Select Step; RMF Implement Step
- SSDF: PO.2.2
|
PR.AT Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.AT-01
|
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
|
- Ex1: Provide basic cybersecurity awareness and training to employees, contractors, partners, suppliers, and all other users of the organization's non-public resources
- Ex2: Train personnel to recognize social engineering attempts and other common attacks, report attacks and suspicious activity, comply with acceptable use policies, and perform basic cyber hygiene tasks (e.g., patching software, choosing passwords, protecting credentials)
- Ex3: Explain the consequences of cybersecurity policy violations, both to individual users and the organization as a whole
- Ex4: Periodically assess or test users on their understanding of basic cybersecurity practices
- Ex5: Require annual refreshers to reinforce existing practices and introduce new practices
|
- AI-SOC: AI-SOC-29
- CCMv4.0: DCS-11; HRS-09; HRS-11; HRS-12; HRS-13; SEF-02; SEF-03; UEM-14
- CIS Controls v8.0: 14.1
- CIS Controls v8.1: 14.1
- CRI Profile v2.0: PR.AT-01; PR.AT-01.01; PR.AT-01.02; PR.AT-01.03; PR.AT-01.04
- CSF v1.1: PR.AT-1; PR.AT-3; RS.CO-1
- CoP: C3; C4
- ISO/IEC 27001:2022: Mandatory Clause: 7.3; Annex A Controls: 6.3; Control 6.3
- NICE Framework: IO-WRL-007; OG-WRL-002; OG-WRL-003; OG-WRL-004; OG-WRL-005
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM09-2025
- PCI DSS: 12.6.1; 12.6.3
- SCF: SAT-02; SAT-03; SAT-03.6
- SP 800-171 Rev 3: 03.02.02
- SP 800-221A: GV.CT-3; GV.RR-2
- SP 800-53 Rev 5.1.1: AT-02; AT-03
- SP 800-53 Rev 5.2.0: AT-02; AT-03
- SP 800-81r3: 4.2.1.2
- SSDF: PO.2.2
|
| PR.AT-02
|
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
|
- Ex1: Identify the specialized roles within the organization that require additional cybersecurity training, such as physical and cybersecurity personnel, finance personnel, senior leadership, and anyone with access to business-critical data
- Ex2: Provide role-based cybersecurity awareness and training to all those in specialized roles, including contractors, partners, suppliers, and other third parties
- Ex3: Periodically assess or test users on their understanding of cybersecurity practices for their specialized roles
- Ex4: Require annual refreshers to reinforce existing practices and introduce new practices
|
- AI-SOC: AI-SOC-29
- CCMv4.0: DCS-11; HRS-09; HRS-12; HRS-13; SEF-03; UEM-14
- CIS Controls v8.0: 14.9
- CIS Controls v8.1: 14.9
- CRI Profile v2.0: PR.AT-02; PR.AT-02.01; PR.AT-02.02; PR.AT-02.03; PR.AT-02.04; PR.AT-02.05; PR.AT-02.06; PR.AT-02.07; PR.AT-02.08
- CSF v1.1: PR.AT-2; PR.AT-3; PR.AT-4; PR.AT-5
- CoP: C3; C4
- ISO/IEC 27001:2022: Mandatory Clause: 7.3; Annex A Controls: 5.2; Annex A Controls: 6.3
- NICE Framework: IO-WRL-007; OG-WRL-002; OG-WRL-003; OG-WRL-004; OG-WRL-005
- OWASP Top 10 LLM Applications: LLM01-2025; LLM04-2025; LLM05-2025
- PCI DSS: 6.2.2; 12.10.4; 12.10.4.1
- SCF: SAT-03; SAT-03.6
- SP 800-171 Rev 3: 03.02.02
- SP 800-221A: GV.CT-3; GV.CT-4; GV.RR-2
- SP 800-53 Rev 5.1.1: AT-03
- SP 800-53 Rev 5.2.0: AT-03
- SP 800-81r3: 4.2.1.2; 5.2
- SSDF: PO.2.2
|
| PR.AT-03
|
[Withdrawn: Incorporated into PR.AT-01, PR.AT-02]
|
| PR.AT-04
|
[Withdrawn: Incorporated into PR.AT-02]
|
| PR.AT-05
|
[Withdrawn: Incorporated into PR.AT-02]
|
Data Security (PR.DS)
Category PR.DS
| Outcome
|
Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
|
| Informative References
|
- CRI Profile v2.0: PR.DS
- CSF v1.1: PR.DS
- ISO/IEC 27001:2022: Mandatory Clause: 6.1.1; Annex A Controls: 5.1; Annex A Controls: 5.33
- NICE Framework: DD-WRL-003; DD-WRL-004; DD-WRL-007; IO-WRL-002; IO-WRL-004; IO-WRL-005; IO-WRL-006; PD-WRL-001
- SCF: DCH-01; DCH-01.1; DCH-03
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Select Step; RMF Implement Step; RMF Monitor Step
|
PR.DS Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.DS-01
|
The confidentiality, integrity, and availability of data-at-rest are protected
|
- Ex1: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of stored data in files, databases, virtual machine disk images, container images, and other resources
- Ex2: Use full disk encryption to protect data stored on user endpoints
- Ex3: Confirm the integrity of software by validating signatures
- Ex4: Restrict the use of removable media to prevent data exfiltration
- Ex5: Physically secure removable media containing unencrypted sensitive information, such as within locked offices or file cabinets
|
- BXAIOS: Chapter 4 - The Receipts (Evidence Packets)
- CCMv4.0: BCR-08; CEK-03; CEK-04; CEK-18; CEK-19; DCS-04; DSP-17; HRS-04; LOG-02; LOG-09; UEM-05; UEM-08
- CIS Controls v8.0: 3.11
- CIS Controls v8.1: 3.11
- CRI Profile v2.0: PR.DS-01; PR.DS-01.01; PR.DS-01.02; PR.DS-01.03
- CSF v1.1: PR.DS-1; PR.DS-5; PR.DS-6; PR.PT-2
- Guardian-SDK: GS-TT-05
- ISO/IEC 27001:2022: Mandatory Clause: 4.2(b); Mandatory Clause: 5.2; Annex A Controls: 5.1; Annex A Controls: 5.3; Annex A Controls: 5.10; Annex A Controls: 5.13; Annex A Controls: 5.14; Annex A Controls: 5.15; Annex A Controls: 6.1; Annex A Controls: 6.2; Annex A Controls: 6.5; Annex A Controls: 7.7; Annex A Controls: 7.10; Annex A Controls: 8.2; Annex A Controls: 8.3; Annex A Controls: 8.4; Annex A Controls: 8.7; Annex A Controls: 8.8; Annex A Controls: 8.17; Annex A Controls: 8.19; Annex A Controls: 8.22; Annex A Controls: 8.26; Control 5.10; Control 5.12; Control 5.13; Control 5.33; Control 7.9; Control 7.10; Control 8.10; Control 8.11; Control 8.12; Control 8.13; Control 8.33
- NICE Framework: DD-WRL-003; DD-WRL-004; DD-WRL-007; IO-WRL-002; IO-WRL-005; IO-WRL-006; PD-WRL-001
- OWASP Top 10 LLM Applications: LLM02-2025; LLM04-2025; LLM07-2025; LLM08-2025
- PCI DSS: 3.5.1; 3.6.1; 3.6.1.1; 3.6.1.2; 3.6.1.3; 3.6.1.4; 3.5.1.3; 3.3.1; 9.4.7; 9.4.6
- SCF: DCH-01; CRY-01; CRY-01.1; CRY-05
- SDOS: SDOS-IN-01; SDOS-IN-02
- SP 800-171 Rev 3: 03.08.09; 03.12.05; 03.13.01; 03.13.04; 03.13.06; 03.13.08; 03.13.10; 03.13.11; 03.14.02; 03.14.06
- SP 800-53 Rev 5.1.1: CA-03; CP-09; MP-08; SC-04; SC-07; SC-12; SC-13; SC-28; SC-32; SC-39; SC-43; SI-03; SI-04; SI-07
- SP 800-53 Rev 5.2.0: CA-03; CP-09; MP-08; SC-04; SC-07; SC-12; SC-13; SC-28; SC-32; SC-39; SC-43; SI-03; SI-04; SI-07
- SP 800-81r3: 3.8.2; 3.8.6
- SSDF: PS.1.1; PS.2.1; PS.3.1
|
| PR.DS-02
|
The confidentiality, integrity, and availability of data-in-transit are protected
|
- Ex1: Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of network communications
- Ex2: Automatically encrypt or block outbound emails and other communications that contain sensitive data, depending on the data classification
- Ex3: Block access to personal email, file sharing, file storage services, and other personal communications applications and services from organizational systems and networks
- Ex4: Prevent reuse of sensitive data from production environments (e.g., customer records) in development, testing, and other non-production environments
|
- CCMv4.0: CEK-03; CEK-04; CEK-19; DCS-02; DSP-10; DSP-17; HRS-04; IPY-03; IVS-03; IVS-07; LOG-02; LOG-09; UEM-05; UEM-11
- CIS Controls v8.0: 3.10
- CIS Controls v8.1: 3.10
- CRI Profile v2.0: PR.DS-02; PR.DS-02.01
- CSF v1.1: PR.DS-2; PR.DS-5
- Guardian-SDK: GS-CF-03
- IRP: IRP-Sec-3
- ISO/IEC 27001:2022: Mandatory Clause: 4.2(b); Mandatory Clause: 5.2; Annex A Controls: 5.3; Annex A Controls: 5.10; Annex A Controls: 5.13; Annex A Controls: 5.14; Annex A Controls: 5.15; Annex A Controls: 6.1; Annex A Controls: 6.2; Annex A Controls: 6.5; Annex A Controls: 8.2; Annex A Controls: 8.3; Annex A Controls: 8.4; Annex A Controls: 8.17; Annex A Controls: 8.20; Annex A Controls: 8.22; Annex A Controls: 8.26; Control 5.14; Control 8.24
- NICE Framework: DD-WRL-003; DD-WRL-004; DD-WRL-007; IO-WRL-002; IO-WRL-004; IO-WRL-005; IO-WRL-006; PD-WRL-001
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM04-2025
- PCI DSS: 4.2.1; 12.3.3; 2.3.1
- SCF: DCH-01; CRY-01; CRY-03; CRY-04
- SDOS: SDOS-EN-01; SDOS-EN-04
- SP 800-171 Rev 3: 03.12.05; 03.13.01; 03.13.04; 03.13.06; 03.13.08; 03.13.10; 03.13.11; 03.14.02; 03.14.06
- SP 800-53 Rev 5.1.1: AU-16; CA-03; SC-04; SC-07; SC-08; SC-11; SC-12; SC-13; SC-16; SC-40; SC-43; SI-03; SI-04; SI-07
- SP 800-53 Rev 5.2.0: AU-16; CA-03; SC-04; SC-07; SC-08; SC-11; SC-12; SC-13; SC-16; SC-40; SC-43; SI-03; SI-04; SI-07
- SP 800-81r3: 2.2.2; 3.5; 3.8.1; 4.2.1.3; 4.2.5
|
| PR.DS-03
|
[Withdrawn: Incorporated into ID.AM-08, PR.PS-03]
|
| PR.DS-04
|
[Withdrawn: Moved to PR.IR-04]
|
| PR.DS-05
|
[Withdrawn: Incorporated into PR.DS-01, PR.DS-02, PR.DS-10]
|
| PR.DS-06
|
[Withdrawn: Incorporated into PR.DS-01, DE.CM-09]
|
| PR.DS-07
|
[Withdrawn: Incorporated into PR.IR-01]
|
| PR.DS-08
|
[Withdrawn: Incorporated into ID.RA-09, DE.CM-09]
|
| PR.DS-10
|
The confidentiality, integrity, and availability of data-in-use are protected
|
- Ex1: Remove data that must remain confidential (e.g., from processors and memory) as soon as it is no longer needed
- Ex2: Protect data in use from access by other users and processes of the same platform
|
- CCMv4.0: DSP-17; HRS-04; UEM-11
- CRI Profile v2.0: PR.DS-10; PR.DS-10.01
- CSF v1.1: PR.DS-5
- ISO/IEC 27001:2022: Mandatory Clause: 4.2(b); Mandatory Clause: 5.2; Annex A Controls: 5.3; Annex A Controls: 5.10; Annex A Controls: 5.13; Annex A Controls: 5.14; Annex A Controls: 5.15; Annex A Controls: 6.1; Annex A Controls: 6.2; Annex A Controls: 6.5; Annex A Controls: 8.2; Annex A Controls: 8.3; Annex A Controls: 8.4; Annex A Controls: 8.17; Annex A Controls: 8.22; Annex A Controls: 8.26; Control 5.23
- NICE Framework: DD-WRL-003; DD-WRL-004; DD-WRL-007; IO-WRL-002; IO-WRL-005; IO-WRL-006; PD-WRL-001
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM07-2025; LLM08-2025
- PCI DSS: 3.2.1; 7.2.2; 8.2.8; 3.4.1
- SCF: DCH-01; CRY-01; CFG-02; IAC-21
- SDOS: SDOS-EN-01; SDOS-EN-04; SDOS-GV-05
- SP 800-171 Rev 3: 03.01.01; 03.01.02; 03.01.03; 03.03.08; 03.08.09; 03.12.05; 03.13.01; 03.13.04; 03.13.06; 03.13.11; 03.14.02; 03.14.06; 03.16.01
- SP 800-53 Rev 5.1.1: AC-02; AC-03; AC-04; AU-09; AU-13; CA-03; CP-09; SA-08; SC-04; SC-07; SC-11; SC-13; SC-24; SC-32; SC-39; SC-40; SC-43; SI-03; SI-04; SI-07; SI-10; SI-16
- SP 800-53 Rev 5.2.0: AC-02; AC-03; AC-04; AU-09; AU-13; CA-03; CP-09; SA-08; SC-04; SC-07; SC-11; SC-13; SC-24; SC-32; SC-39; SC-40; SC-43; SI-03; SI-04; SI-07; SI-10; SI-16
- SP 800-81r3: 3.5
|
| PR.DS-11
|
Backups of data are created, protected, maintained, and tested
|
- Ex1: Continuously back up critical data in near-real-time, and back up other data frequently at agreed-upon schedules
- Ex2: Test backups and restores for all types of data sources at least annually
- Ex3: Securely store some backups offline and offsite so that an incident or disaster will not damage them
- Ex4: Enforce geographic separation and geolocation restrictions for data backup storage
|
- CCMv4.0: BCR-08; CEK-18; DSP-16; DSP-19; LOG-02; LOG-09
- CIS Controls v8.0: 11.2; 11.3; 11.5
- CIS Controls v8.1: 11.2; 11.3; 11.5
- CRI Profile v2.0: PR.DS-11; PR.DS-11.01
- CSF v1.1: PR.IP-4
- IRP: IRP-Sec-6
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.13
- NICE Framework: DD-WRL-007; IO-WRL-002; IO-WRL-005; IO-WRL-006; PD-WRL-001
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1; 9.4.7; 9.3.1.1; 9.4.1.1; 9.4.1.2
- SCF: BCD-11; BCD-11.1; BCD-11.5; BCD-11.6
- SDOS: SDOS-IN-01; SDOS-IN-02
- SP 800-171 Rev 3: 03.08.09
- SP 800-53 Rev 5.1.1: CP-06; CP-09
- SP 800-53 Rev 5.2.0: CP-06; CP-09
- SSDF: PS.3.1
|
Category PR.PS
| Outcome
|
The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability
|
| Informative References
|
- CRI Profile v2.0: PR.PS
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Annex A Controls: 8.5; Annex A Controls: 8.8; Annex A Controls: 8.9; Annex A Controls: 8.14
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-003; DD-WRL-005; DD-WRL-006; DD-WRL-008; IO-WRL-003; IO-WRL-005; IO-WRL-007; OG-WRL-001; OG-WRL-013; OG-WRL-016; PD-WRL-004; PD-WRL-007
- SCF: CFG-01; CFG-02; CFG-02.1; CFG-02.5; MNT-01; MNT-02
- SP-800-37 Rev 2: RMF Select Step; RMF Implement Step; RMF Monitor Step
|
PR.PS Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.PS-01
|
Configuration management practices are established and applied
|
- Ex1: Establish, test, deploy, and maintain hardened baselines that enforce the organization's cybersecurity policies and provide only essential capabilities (i.e., principle of least functionality)
- Ex2: Review all default configuration settings that may potentially impact cybersecurity when installing or upgrading software
- Ex3: Monitor implemented software for deviations from approved baselines
|
- AI-SOC: AI-SOC-08; AI-SOC-22
- CCMv4.0: AIS-02; AIS-04; AIS-05; AIS-06; CCC-01; CCC-02; CCC-06; CCC-07; IVS-04; IVS-06; UEM-05; UEM-06; UEM-07; UEM-09; UEM-10; UEM-11; UEM-12; UEM-13
- CIS Controls v8.0: 4.1; 4.2
- CIS Controls v8.1: 4.1; 4.2
- CRI Profile v2.0: PR.PS-01; PR.PS-01.01; PR.PS-01.02; PR.PS-01.03; PR.PS-01.04; PR.PS-01.05; PR.PS-01.06; PR.PS-01.07; PR.PS-01.08; PR.PS-01.09
- CSF v1.1: PR.IP-1; PR.IP-3; PR.PT-2; PR.PT-3
- Guardian-SDK: GS-CF-01
- ISO/IEC 27001:2022: Mandatory Clause: 9.3; Annex A Controls: 8.9; Control 8.8; Control 8.9
- NICE Framework: DD-WRL-001; DD-WRL-002; IO-WRL-005; OG-WRL-013; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM06-2025; LLM07-2025; LLM10-2025
- PCI DSS: 2.2.1; 2.2.2
- SCF: CFG-01
- SDOS: SDOS-GV-01; SDOS-GV-04; SDOS-IN-01
- SP 800-171 Rev 3: 03.04.01; 03.04.02; 03.04.03; 03.04.04; 03.04.05; 03.04.06; 03.04.08; 03.04.10; 03.04.12; 03.15.01
- SP 800-53 Rev 5.1.1: CM-01; CM-02; CM-03; CM-04; CM-05; CM-06; CM-07; CM-08; CM-09; CM-10; CM-11
- SP 800-53 Rev 5.2.0: CM-01; CM-02; CM-03; CM-04; CM-05; CM-06; CM-07; CM-08; CM-09; CM-10; CM-11
- SP 800-81r3: 2.2.3; 2.3.1; 2.3.3; 3.5.1; 3.6.1; 3.6.2; 3.7.1; 3.8.3; 4.2.1.3; 4.2.2
- SSDF: PO.5.2; PS.1.1
|
| PR.PS-02
|
Software is maintained, replaced, and removed commensurate with risk
|
- Ex1: Perform routine and emergency patching within the timeframes specified in the vulnerability management plan
- Ex2: Update container images, and deploy new container instances to replace rather than update existing instances
- Ex3: Replace end-of-life software and service versions with supported, maintained versions
- Ex4: Uninstall and remove unauthorized software and services that pose undue risks
- Ex5: Uninstall and remove any unnecessary software components (e.g., operating system utilities) that attackers might misuse
- Ex6: Define and implement plans for software and service end-of-life maintenance support and obsolescence
|
- AI-SOC: AI-SOC-08; AI-SOC-22
- CCMv4.0: AIS-04; AIS-05; AIS-07; CCC-04; CCC-09; DSP-02; TVM-03; TVM-04; TVM-05; TVM-08; UEM-02; UEM-03; UEM-07
- CIS Controls v8.0: 2.2; 2.3
- CIS Controls v8.1: 2.2; 2.3
- CRI Profile v2.0: PR.PS-02; PR.PS-02.01; PR.PS-02.02; PR.PS-02.03
- CSF v1.1: PR.IP-12; PR.MA-2
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.9; Control 8.7
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-005; DD-WRL-006; IO-WRL-005; IO-WRL-007; OG-WRL-013; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 6.3.3; 6.3.1; 6.3.2; 12.3.4
- SCF: MNT-01; MNT-02; MNT-03; MNT-03.1; PRM-07; SEA-07.1; TDA-17; VPM-01; VPM-01.1; VPM-02; VPM-05
- SDOS: SDOS-IA-02; SDOS-IN-03
- SP 800-171 Rev 3: 03.14.01
- SP 800-53 Rev 5.1.1: CM-11; MA-03(06); SA-10(01); SI-02; SI-07
- SP 800-53 Rev 5.2.0: CM-11; MA-03(06); SA-10(01); SI-02; SI-07
- SP 800-81r3: 2.2.3; 3.8.2; 4.2.6
- SSDF: PO.5.2
|
| PR.PS-03
|
Hardware is maintained, replaced, and removed commensurate with risk
|
- Ex1: Replace hardware when it lacks needed security capabilities or when it cannot support software with needed security capabilities
- Ex2: Define and implement plans for hardware end-of-life maintenance support and obsolescence
- Ex3: Perform hardware disposal in a secure, responsible, and auditable manner
|
- CCMv4.0: CCC-04; DCS-01; DSP-02; TVM-03; TVM-08
- CIS Controls v8.0: 1.2
- CIS Controls v8.1: 1.2
- CRI Profile v2.0: PR.PS-03; PR.PS-03.01
- CSF v1.1: PR.MA-1; PR.DS-3
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.9; Control 8.1
- NICE Framework: DD-WRL-001; DD-WRL-002; IO-WRL-005; IO-WRL-007; OG-WRL-013; PD-WRL-004
- PCI DSS: 12.3.4; 9.4.7; 9.5.1.1
- SCF: MNT-01; MNT-02; MNT-03; MNT-03.1; PRM-07; SEA-07.1; TDA-17
- SP 800-53 Rev 5.1.1: CM-07(09); SA-10(03); SC-03(01); SC-39(01); SC-49; SC-51
- SP 800-53 Rev 5.2.0: CM-07(09); SA-10(03); SC-03(01); SC-39(01); SC-49; SC-51
- SSDF: PO.5.2
|
| PR.PS-04
|
Log records are generated and made available for continuous monitoring
|
- Ex1: Configure all operating systems, applications, and services (including cloud-based services) to generate log records
- Ex2: Configure log generators to securely share their logs with the organization's logging infrastructure systems and services
- Ex3: Configure log generators to record the data needed by zero-trust architectures
|
- AI-SOC: AI-SOC-02; AI-SOC-22
- CCMv4.0: IAM-16; LOG-01; LOG-02; LOG-03; LOG-04; LOG-05; LOG-07; LOG-08; LOG-10; LOG-11; LOG-12; LOG-13
- CIS Controls v8.0: 8.2
- CIS Controls v8.1: 8.2
- CRI Profile v2.0: PR.PS-04; PR.PS-04.01; PR.PS-04.02; PR.PS-04.03
- CSF v1.1: PR.PT-1
- Guardian-SDK: GS-CF-02
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.15; Annex A Controls: 8.17
- NICE Framework: DD-WRL-001; DD-WRL-002; IO-WRL-003; IO-WRL-005; OG-WRL-013; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM06-2025; LLM10-2025
- PCI DSS: 10.2.1; 10.3.1; 10.3.2; 10.3.3; 10.3.4; 10.4.2.1; 10.6.1; 10.6.3
- SCF: MON-01; MON-01.4; MON-03
- SDOS: SDOS-AU-01; SDOS-AU-02; SDOS-AU-03; SDOS-EN-04
- SP 800-171 Rev 3: 03.03.02; 03.03.03; 03.03.05; 03.03.06
- SP 800-53 Rev 5.1.1: AU-02; AU-03; AU-06; AU-07; AU-11; AU-12
- SP 800-53 Rev 5.2.0: AU-02; AU-03; AU-06; AU-07; AU-11; AU-12; SA-15(13)
- SP 800-81r3: 2.1.2; 2.1.3
- SSDF: PO.3.3
|
| PR.PS-05
|
Installation and execution of unauthorized software are prevented
|
- Ex1: When risk warrants it, restrict software execution to permitted products only or deny the execution of prohibited and unauthorized software
- Ex2: Verify the source of new software and the software's integrity before installing it
- Ex3: Configure platforms to use only approved DNS services that block access to known malicious domains
- Ex4: Configure platforms to allow the installation of organization-approved software only
|
- AI-SOC: AI-SOC-03; AI-SOC-20
- CCMv4.0: CCC-04; UEM-02; UEM-09
- CIS Controls v8.0: 2.5
- CIS Controls v8.1: 2.5
- CRI Profile v2.0: PR.PS-05; PR.PS-05.01; PR.PS-05.02; PR.PS-05.03
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.19; Control 8.19
- NICE Framework: DD-WRL-001; DD-WRL-002; IO-WRL-005; IO-WRL-007; OG-WRL-001; OG-WRL-013; PD-WRL-004; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 2.2.1; 5.3.2; 6.4.3
- SCF: CFG-01; CFG-02; CFG-03; CFG-03.2; CFG-05; END-03
- SDOS: SDOS-AD-01; SDOS-GV-01; SDOS-GV-05; SDOS-IN-03
- SP 800-53 Rev 5.1.1: CM-07(02); CM-07(04); CM-07(05); SC-34
- SP 800-53 Rev 5.2.0: CM-07(02); CM-07(04); CM-07(05); SC-34
|
| PR.PS-06
|
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle
|
- Ex1: Protect all components of organization-developed software from tampering and unauthorized access
- Ex2: Secure all software produced by the organization, with minimal vulnerabilities in their releases
- Ex3: Maintain the software used in production environments, and securely dispose of software once it is no longer needed
|
- AI-SOC: AI-SOC-08; AI-SOC-22
- CCMv4.0: AIS-04; AIS-06; AIS-07; DSP-07; IVS-06
- CIS Controls v8.0: 16.1
- CIS Controls v8.1: 16.1
- CRI Profile v2.0: PR.PS-06; PR.PS-06.01; PR.PS-06.02; PR.PS-06.03; PR.PS-06.04; PR.PS-06.05; PR.PS-06.06; PR.PS-06.07; PR.PS-06.08; PR.PS-06.09; PR.PS-06.10
- CSF v1.1: PR.IP-2
- IRP: IRP-Sec-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.25; Annex A Controls: 8.28; Control 8.25; Control 8.26; Control 8.28; Control 8.29; Control 8.31
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-003; DD-WRL-005; DD-WRL-008; IO-WRL-005; OG-WRL-016; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM05-2025; LLM06-2025
- PCI DSS: 6.2.3; 6.2.2; 6.3.2; 11.4.4
- SCF: TDA-01; TDA-01.1; TDA-06; TDA-06.1; TDA-06.2; TDA-09
- SP 800-171 Rev 3: 03.16.01
- SP 800-53 Rev 5.1.1: SA-03; SA-08; SA-10; SA-11; SA-15; SA-17
- SP 800-53 Rev 5.2.0: SA-03; SA-08; SA-10; SA-11; SA-15; SA-15(13); SA-17; SA-24
|
Technology Infrastructure Resilience (PR.IR)
Category PR.IR
| Outcome
|
Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience
|
| Informative References
|
- CRI Profile v2.0: PR.IR
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 6.6; Annex A Controls: 8.27
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-004; DD-WRL-006; DD-WRL-009; IO-WRL-004; OG-WRL-001; OG-WRL-002; OG-WRL-014
- SCF: GOV-01; RSK-01; SEA-01; SEA-01.1; SEA-02
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Prepare Step (System Level): TASK P-15 Requirements Definition; RMF Prepare Step (System Level): TASK P-16 Enterprise Architecture; RMF Prepare Step (System Level): TASK P-17 Requirements Allocation; RMF Select Step; RMF Implement Step
|
PR.IR Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.IR-01
|
Networks and environments are protected from unauthorized logical access and usage
|
- Ex1: Logically segment organization networks and cloud-based platforms according to trust boundaries and platform types (e.g., IT, IoT, OT, mobile, guests), and permit required communications only between segments
- Ex2: Logically segment organization networks from external networks, and permit only necessary communications to enter the organization's networks from the external networks
- Ex3: Implement zero trust architectures to restrict network access to each resource to the minimum necessary
- Ex4: Check the cyber health of endpoints before allowing them to access and use production resources
|
- AI-SOC: AI-SOC-07; AI-SOC-24
- CCMv4.0: AIS-04; AIS-06; DCS-12; DSP-10; DSP-15; IVS-03; IVS-05; IVS-06; IVS-09; UEM-05; UEM-14
- CIS Controls v8.0: 3.12; 12.2
- CIS Controls v8.1: 3.12; 12.2
- CRI Profile v2.0: PR.IR-01; PR.IR-01.01; PR.IR-01.02; PR.IR-01.03; PR.IR-01.04; PR.IR-01.05; PR.IR-01.06; PR.IR-01.07; PR.IR-01.08
- CSF v1.1: PR.AC-3; PR.AC-5; PR.DS-7; PR.PT-4
- Guardian-SDK: GS-PF-01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.20; Annex A Controls: 8.21; Annex A Controls: 8.22; Control 8.20; Control 8.21; Control 8.22; Control 8.23
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-004; DD-WRL-006; DD-WRL-009; IO-WRL-004; OG-WRL-001; OG-WRL-014
- OWASP Top 10 LLM Applications: LLM01-2025; LLM06-2025; LLM10-2025
- PCI DSS: 1.2.3; 1.2.4; 10.2.1; 5.2.1; 5.2.2; 5.2.3; 5.2.3.1; 11.2.1
- SCF: NET-01; SEA-01; SEA-02
- SDOS: SDOS-AD-01; SDOS-EN-02
- SP 800-171 Rev 3: 03.01.02; 03.01.03; 03.13.01; 03.13.04; 03.13.06
- SP 800-53 Rev 5.1.1: AC-03; AC-04; SC-04; SC-05; SC-07
- SP 800-53 Rev 5.2.0: AC-03; AC-04; SC-04; SC-05; SC-07
- SP 800-81r3: 4.2.2; 4.3
- SSDF: PO.5.1
|
| PR.IR-02
|
The organization's technology assets are protected from environmental threats
|
- Ex1: Protect organizational equipment from known environmental threats, such as flooding, fire, wind, and excessive heat and humidity
- Ex2: Include protection from environmental threats and provisions for adequate operating infrastructure in requirements for service providers that operate systems on the organization's behalf
|
- CCMv4.0: DCS-03; DCS-13; DCS-14; DCS-15
- CRI Profile v2.0: PR.IR-02; PR.IR-02.01
- CSF v1.1: PR.IP-5
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 7.5; Control 7.5; Control 7.6; Control 7.7; Control 7.8; Control 7.11; Control 7.12; Control 7.13; Control 7.14
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-004; DD-WRL-006; DD-WRL-009; IO-WRL-004; OG-WRL-014
- PCI DSS: 9.1.1; 9.1.2; 12.10.1
- SCF: BCD-01; PES-01; PES-07; PES-07.5; PES-08; PES-09
- SP 800-53 Rev 5.1.1: CP-02; PE-09; PE-10; PE-11; PE-12; PE-13; PE-14; PE-15; PE-18; PE-23
- SP 800-53 Rev 5.2.0: CP-02; PE-09; PE-10; PE-11; PE-12; PE-13; PE-14; PE-15; PE-18; PE-23
|
| PR.IR-03
|
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
|
- Ex1: Avoid single points of failure in systems and infrastructure
- Ex2: Use load balancing to increase capacity and improve reliability
- Ex3: Use high-availability components like redundant storage and power supplies to improve system reliability
|
- AI-SOC: AI-SOC-07; AI-SOC-24
- CCMv4.0: BCR-11
- CRI Profile v2.0: PR.IR-03; PR.IR-03.01
- CSF v1.1: PR.PT-5
- ISO/IEC 27001:2022: Mandatory Clause: 4.2(b); Mandatory Clause: 6.1.1; Annex A Controls: 5.29; Annex A Controls: 8.14; Control 8.14; Control 8.17; Control 8.27
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-004; DD-WRL-006; DD-WRL-009; IO-WRL-004; OG-WRL-002; OG-WRL-014
- OWASP Top 10 LLM Applications: LLM10-2025
- PCI DSS: 12.10.1; 12.10.2; 12.10.6
- SCF: BCD-01; SEA-01; SEA-02
- SDOS: SDOS-EN-03; SDOS-IN-01; SDOS-IN-02
- SP 800-171 Rev 3: 03.16.01
- SP 800-53 Rev 5.1.1: CP; IR; SA-08; SC-06; SC-24; SC-36; SC-39; SI-13
- SP 800-53 Rev 5.2.0: CP; IR; SA-08; SA-24; SC-06; SC-24; SC-36; SC-39; SI-13
- SP 800-81r3: 1.2; 2.2.2; 2.3.1; 2.3.2; 3.8.6; 5.1; 5.3
|
| PR.IR-04
|
Adequate resource capacity to ensure availability is maintained
|
- Ex1: Monitor usage of storage, power, compute, network bandwidth, and other resources
- Ex2: Forecast future needs, and scale resources accordingly
|
- AI-SOC: AI-SOC-07; AI-SOC-24
- CCMv4.0: IVS-02
- CRI Profile v2.0: PR.IR-04; PR.IR-04.01; PR.IR-04.02
- CSF v1.1: PR.DS-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.6
- NICE Framework: DD-WRL-001; DD-WRL-002; DD-WRL-004; DD-WRL-006; DD-WRL-009; IO-WRL-004; OG-WRL-014
- OWASP Top 10 LLM Applications: LLM10-2025
- SCF: CAP-01; CAP-02; CAP-03
- SDOS: SDOS-EN-03; SDOS-RM-02; SDOS-RM-03
- SP 800-53 Rev 5.1.1: CP-06; CP-07; CP-08; PM-03; PM-09
- SP 800-53 Rev 5.2.0: CP-06; CP-07; CP-08; PM-03; PM-09
- SP 800-81r3: 2.1.2; 2.3.2
|
Identity Management, Authentication and Access Control (PR.AC)
[Withdrawn: Moved to PR.AA]
PR.AC Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.AC-01
|
[Withdrawn: Incorporated into PR.AA-01, PR.AA-05]
|
| PR.AC-02
|
[Withdrawn: Moved to PR.AA-06]
|
| PR.AC-03
|
[Withdrawn: Incorporated into PR.AA-03, PR.AA-05, PR.IR-01]
|
| PR.AC-04
|
[Withdrawn: Moved to PR.AA-05]
|
| PR.AC-05
|
[Withdrawn: Incorporated into PR.IR-01]
|
| PR.AC-06
|
[Withdrawn: Moved to PR.AA-02]
|
| PR.AC-07
|
[Withdrawn: Moved to PR.AA-03]
|
[Withdrawn: Incorporated into other Categories and Functions]
PR.IP Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.IP-01
|
[Withdrawn: Incorporated into PR.PS-01]
|
| PR.IP-02
|
[Withdrawn: Incorporated into ID.AM-08, PR.PS-06]
|
| PR.IP-03
|
[Withdrawn: Incorporated into PR.PS-01, ID.RA-07]
|
| PR.IP-04
|
[Withdrawn: Moved to PR.DS-11]
|
| PR.IP-05
|
[Withdrawn: Moved to PR.IR-02]
|
| PR.IP-06
|
[Withdrawn: Incorporated into ID.AM-08]
|
| PR.IP-07
|
[Withdrawn: Incorporated into ID.IM, ID.IM-03]
|
| PR.IP-08
|
[Withdrawn: Moved to ID.IM-03]
|
| PR.IP-09
|
[Withdrawn: Moved to ID.IM-04]
|
| PR.IP-10
|
[Withdrawn: Incorporated into ID.IM-02, ID.IM-04]
|
| PR.IP-11
|
[Withdrawn: Moved to GV.RR-04]
|
| PR.IP-12
|
[Withdrawn: Incorporated into ID.RA-01, PR.PS-02]
|
Maintenance (PR.MA)
[Withdrawn: Incorporated into ID.AM-08]
PR.MA Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.MA-01
|
[Withdrawn: Incorporated into ID.AM-08, PR.PS-03]
|
| PR.MA-02
|
[Withdrawn: Incorporated into ID.AM-08, PR.PS-02]
|
Protective Technology (PR.PT)
[Withdrawn: Incorporated into other Protect Categories]
PR.PT Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| PR.PT-01
|
[Withdrawn: Incorporated into PR.PS-04]
|
| PR.PT-02
|
[Withdrawn: Incorporated into PR.DS-01, PR.PS-01]
|
| PR.PT-03
|
[Withdrawn: Incorporated into PR.PS-01]
|
| PR.PT-04
|
[Withdrawn: Incorporated into PR.AA-06, PR.IR-01]
|
| PR.PT-05
|
[Withdrawn: Moved to PR.IR-03]
|
DETECT (DE)
Function DE
| Outcome
|
Possible cybersecurity attacks and compromises are found and analyzed
|
| Informative References
|
- CRI Profile v2.0: DE
- CSF v1.1: DE
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.16
- SCF: THR-01; THR-03; THR-07
|
Continuous Monitoring (DE.CM)
Category DE.CM
| Outcome
|
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
|
| Informative References
|
- CRI Profile v2.0: DE.CM
- CSF v1.1: DE.CM
- ISO/IEC 27001:2022: Mandatory Clause: 9.1; Annex A Controls: 8.16
- NICE Framework: DD-WRL-005; DD-WRL-007; IO-WRL-004; IO-WRL-005; IO-WRL-006; OG-WRL-016; PD-WRL-001; PD-WRL-004; PD-WRL-005
- SCF: MON-11.3; MON-16
- SP-800-37 Rev 2: RMF Monitor Step
|
DE.CM Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| DE.CM-01
|
Networks and network services are monitored to find potentially adverse events
|
- Ex1: Monitor DNS, BGP, and other network services for adverse events
- Ex2: Monitor wired and wireless networks for connections from unauthorized endpoints
- Ex3: Monitor facilities for unauthorized or rogue wireless networks
- Ex4: Compare actual network flows against baselines to detect deviations
- Ex5: Monitor network communications to identify changes in security postures for zero trust purposes
|
- AI-SOC: AI-SOC-02; AI-SOC-15
- CCMv4.0: IVS-03; IVS-09; LOG-01; LOG-03; LOG-05; LOG-08; TVM-02; TVM-10; UEM-10
- CIS Controls v8.0: 13.1
- CIS Controls v8.1: 13.1
- CRI Profile v2.0: DE.CM-01; DE.CM-01.01; DE.CM-01.02; DE.CM-01.03; DE.CM-01.04; DE.CM-01.05; DE.CM-01.06
- CSF v1.1: DE.CM-1; DE.CM-4; DE.CM-5; DE.CM-7
- IRP: IRP-Sec-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.16; Control 8.15
- NICE Framework: DD-WRL-007; IO-WRL-004; IO-WRL-006; OG-WRL-016; PD-WRL-001; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM10-2025
- PCI DSS: 10.2.1; 10.4.1; 11.2.1; 1.2.4
- SCF: MON-01; MON-01.1; MON-01.3; MON-01.4; MON-01.8
- SDOS: SDOS-AU-01; SDOS-AU-02; SDOS-EN-04
- SP 800-171 Rev 3: 03.01.01; 03.03.03; 03.04.03; 03.12.03; 03.13.01; 03.13.06; 03.14.06
- SP 800-53 Rev 5.1.1: AC-02; AU-12; CA-07; CM-03; SC-05; SC-07; SI-04
- SP 800-53 Rev 5.2.0: AC-02; AU-12; CA-07; CM-03; SC-05; SC-07; SI-04
- SP 800-81r3: 2.1.2; 2.1.3; 3.6.1; 3.6.2
|
| DE.CM-02
|
The physical environment is monitored to find potentially adverse events
|
- Ex1: Monitor logs from physical access control systems (e.g., badge readers) to find unusual access patterns (e.g., deviations from the norm) and failed access attempts
- Ex2: Review and monitor physical access records (e.g., from visitor registration, sign-in sheets)
- Ex3: Monitor physical access controls (e.g., locks, latches, hinge pins, alarms) for signs of tampering
- Ex4: Monitor the physical environment using alarm systems, cameras, and security guards
|
- CCMv4.0: DCS-09; DCS-10; DCS-14; LOG-01; LOG-03; LOG-05; LOG-08; LOG-12; TVM-10
- CRI Profile v2.0: DE.CM-02; DE.CM-02.01
- CSF v1.1: DE.CM-2
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 7.4
- NICE Framework: DD-WRL-007; IO-WRL-005; IO-WRL-006; OG-WRL-016; PD-WRL-001; PD-WRL-004
- PCI DSS: 9.3.1.1; 9.5.1.2; 9.4.1.2
- SCF: PES-01; PES-03; PES-03.3; PES-05
- SP 800-171 Rev 3: 03.10.02; 03.10.07; 03.12.03
- SP 800-53 Rev 5.1.1: CA-07; PE-03; PE-06; PE-20
- SP 800-53 Rev 5.2.0: CA-07; PE-03; PE-06; PE-20
|
| DE.CM-03
|
Personnel activity and technology usage are monitored to find potentially adverse events
|
- Ex1: Use behavior analytics software to detect anomalous user activity to mitigate insider threats
- Ex2: Monitor logs from logical access control systems to find unusual access patterns and failed access attempts
- Ex3: Continuously monitor deception technology, including user accounts, for any usage
|
- AI-SOC: AI-SOC-09; AI-SOC-19
- CCMv4.0: LOG-01; LOG-03; LOG-05; LOG-08; TVM-10
- CIS Controls v8.0: 10.7
- CIS Controls v8.1: 10.7
- CRI Profile v2.0: DE.CM-03; DE.CM-03.01; DE.CM-03.02; DE.CM-03.03
- CSF v1.1: DE.CM-3; DE.CM-7
- Guardian-SDK: GS-PF-03
- ISO/IEC 27001:2022: Mandatory Clause: 9.1; Annex A Controls: 7.4; Annex A Controls: 8.16; Control 8.16
- NICE Framework: DD-WRL-007; IO-WRL-006; OG-WRL-016; PD-WRL-001; PD-WRL-004; PD-WRL-005
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM06-2025
- PCI DSS: 10.2.1; 10.4.1; 8.2.2; 10.6.1
- SCF: MON-01; MON-16; NET-18
- SDOS: SDOS-AU-01; SDOS-AU-03
- SP 800-171 Rev 3: 03.01.01; 03.03.03; 03.12.03
- SP 800-53 Rev 5.1.1: AC-02; AU-12; AU-13; CA-07; CM-10; CM-11
- SP 800-53 Rev 5.2.0: AC-02; AU-12; AU-13; CA-07; CM-10; CM-11
- SP 800-81r3: 2.1.3
|
| DE.CM-04
|
[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]
|
| DE.CM-05
|
[Withdrawn: Incorporated into DE.CM-01, DE.CM-09]
|
| DE.CM-06
|
External service provider activities and services are monitored to find potentially adverse events
|
- Ex1: Monitor remote and onsite administration and maintenance activities that external providers perform on organizational systems
- Ex2: Monitor activity from cloud-based services, internet service providers, and other service providers for deviations from expected behavior
|
- AI-SOC: AI-SOC-26; AI-SOC-11
- CCMv4.0: LOG-01; LOG-03; LOG-05; LOG-08; TVM-10
- CIS Controls v8.0: 15.2; 15.6
- CIS Controls v8.1: 15.2; 15.6
- CRI Profile v2.0: DE.CM-06; DE.CM-06.01; DE.CM-06.02
- CSF v1.1: DE.CM-6; DE.CM-7
- Guardian-SDK: GS-AG-02
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.22; Annex A Controls: 8.16
- NICE Framework: DD-WRL-007; IO-WRL-006; OG-WRL-016; PD-WRL-001; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM03-2025
- PCI DSS: 12.8.4; 7.2.4; 10.2.1
- SCF: MON-01
- SDOS: SDOS-AU-02; SDOS-EN-04
- SP 800-171 Rev 3: 03.12.03; 03.14.06; 03.16.03
- SP 800-53 Rev 5.1.1: CA-07; PS-07; SA-04; SA-09; SI-04
- SP 800-53 Rev 5.2.0: CA-07; PS-07; SA-04; SA-09; SI-04
|
| DE.CM-07
|
[Withdrawn: Incorporated into DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09]
|
| DE.CM-08
|
[Withdrawn: Incorporated into ID.RA-01]
|
| DE.CM-09
|
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
|
- Ex1: Monitor email, web, file sharing, collaboration services, and other common attack vectors to detect malware, phishing, data leaks and exfiltration, and other adverse events
- Ex2: Monitor authentication attempts to identify attacks against credentials and unauthorized credential reuse
- Ex3: Monitor software configurations for deviations from security baselines
- Ex4: Monitor hardware and software for signs of tampering
- Ex5: Use technologies with a presence on endpoints to detect cyber health issues (e.g., missing patches, malware infections, unauthorized software), and redirect the endpoints to a remediation environment before access is authorized
|
- AI-SOC: AI-SOC-02; AI-SOC-03
- CCMv4.0: CCC-07; IVS-06; LOG-01; LOG-03; LOG-05; LOG-08; LOG-10; LOG-11; TVM-02; TVM-10; UEM-09; UEM-10; UEM-11
- CIS Controls v8.0: 10.1
- CIS Controls v8.1: 10.1
- CRI Profile v2.0: DE.CM-09; DE.CM-09.01; DE.CM-09.02; DE.CM-09.03
- CSF v1.1: PR.DS-6; PR.DS-8; DE.CM-4; DE.CM-5; DE.CM-7
- Guardian-SDK: GS-PF-01; GS-PF-02; GS-PF-04; GS-MM-01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.16; Control 8.6
- NICE Framework: DD-WRL-005; DD-WRL-007; IO-WRL-006; OG-WRL-016; PD-WRL-001; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM04-2025; LLM05-2025; LLM08-2025; LLM10-2025
- PCI DSS: 5.2.1; 5.2.2; 5.3.2; 11.3.1; 11.3.2; 6.4.3; 10.3.4
- SCF: MON-01; MON-01.7; END-01; END-04; END-06
- SDOS: SDOS-AU-02; SDOS-IN-01; SDOS-IN-03
- SP 800-171 Rev 3: 03.01.03; 03.03.03; 03.04.02; 03.04.03; 03.12.03; 03.14.06
- SP 800-53 Rev 5.1.1: AC-04; AC-09; AU-12; CA-07; CM-03; CM-06; CM-10; CM-11; SC-34; SC-35; SI-04; SI-07
- SP 800-53 Rev 5.2.0: AC-04; AC-09; AU-12; CA-07; CM-03; CM-06; CM-10; CM-11; SC-34; SC-35; SI-04; SI-07
- SP 800-81r3: 2.1.3; 3.6.3; 4.2.4
|
Adverse Event Analysis (DE.AE)
Category DE.AE
| Outcome
|
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
|
| Informative References
|
- CRI Profile v2.0: DE.AE
- CSF v1.1: DE.AE; DE.DP-2
- IRP: IRP-Sec-2
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26; Annex A Controls: 8.16
- NICE Framework: DD-WRL-004; DD-WRL-008; IO-WRL-001; IO-WRL-006; OG-WRL-002; OG-WRL-007; OG-WRL-010; OG-WRL-012; PD-WRL-001; PD-WRL-003; PD-WRL-005; PD-WRL-006; PD-WRL-007
- SCF: MON-01; MON-01.8; MON-01.12; IRO-01; IRO-02; IRO-02.4
|
DE.AE Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| DE.AE-01
|
[Withdrawn: Incorporated into ID.AM-03]
|
| DE.AE-02
|
Potentially adverse events are analyzed to better understand associated activities
|
- Ex1: Use security information and event management (SIEM) or other tools to continuously monitor log events for known malicious and suspicious activity
- Ex2: Utilize up-to-date cyber threat intelligence in log analysis tools to improve detection accuracy and characterize threat actors, their methods, and indicators of compromise
- Ex3: Regularly conduct manual reviews of log events for technologies that cannot be sufficiently monitored through automation
- Ex4: Use log analysis tools to generate reports on their findings
|
- AI-SOC: AI-SOC-01; AI-SOC-13
- CCMv4.0: LOG-03; LOG-05; SEF-05; SEF-06; UEM-09
- CIS Controls v8.0: 8.11
- CIS Controls v8.1: 8.11
- CRI Profile v2.0: DE.AE-02; DE.AE-02.01; DE.AE-02.02
- CSF v1.1: DE.AE-2
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.24; Annex A Controls: 5.25; Control 5.25
- NICE Framework: DD-WRL-008; IO-WRL-006; PD-WRL-001; PD-WRL-005; PD-WRL-006; PD-WRL-007
- OWASP Top 10 LLM Applications: LLM01-2025; LLM04-2025; LLM10-2025
- PCI DSS: 10.2.1; 10.4.1; 10.4.2.1; 10.3.3; 10.3.4; 6.3.1
- SCF: IRO-02; IRO-02.4
- SDOS: SDOS-DE-01; SDOS-DE-02
- SP 800-171 Rev 3: 03.03.05; 03.06.01; 03.12.03; 03.14.06
- SP 800-53 Rev 5.1.1: AU-06; CA-07; IR-04; SI-04
- SP 800-53 Rev 5.2.0: AU-06; CA-07; IR-04; SI-04
|
| DE.AE-03
|
Information is correlated from multiple sources
|
- Ex1: Constantly transfer log data generated by other sources to a relatively small number of log servers
- Ex2: Use event correlation technology (e.g., SIEM) to collect information captured by multiple sources
- Ex3: Utilize cyber threat intelligence to help correlate events among log sources
|
- AI-SOC: AI-SOC-11; AI-SOC-22
- CCMv4.0: LOG-03; LOG-05; SEF-05
- CRI Profile v2.0: DE.AE-03; DE.AE-03.01; DE.AE-03.02
- CSF v1.1: DE.AE-3
- Guardian-SDK: GS-PF-03
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.15; Annex A Controls: 8.16
- NICE Framework: IO-WRL-001; IO-WRL-006; PD-WRL-001; PD-WRL-006
- OWASP Top 10 LLM Applications: LLM01-2025; LLM04-2025
- PCI DSS: 10.2.1; 10.3.3; 10.4.1; 12.5.1; 1.2.4
- SCF: MON-02; MON-02.1; IRO-02; IRO-02.5
- SDOS: SDOS-AU-01; SDOS-AU-02
- SP 800-171 Rev 3: 03.03.05; 03.06.01; 03.06.02; 03.06.05; 03.12.03; 03.14.06
- SP 800-53 Rev 5.1.1: AU-06; CA-07; PM-16; IR-04; IR-05; IR-08; SI-04
- SP 800-53 Rev 5.2.0: AU-06; CA-07; PM-16; IR-04; IR-05; IR-08; SI-04
|
| DE.AE-04
|
The estimated impact and scope of adverse events are understood
|
- Ex1: Use SIEMs or other tools to estimate impact and scope, and review and refine the estimates
- Ex2: A person creates their own estimates of impact and scope
|
- AI-SOC: AI-SOC-06; AI-SOC-13
- CCMv4.0: LOG-03; SEF-05; SEF-06
- CRI Profile v2.0: DE.AE-04; DE.AE-04.01
- CSF v1.1: DE.AE-4
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.25
- NICE Framework: DD-WRL-004; IO-WRL-006; OG-WRL-002; OG-WRL-012; PD-WRL-001; PD-WRL-006
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM04-2025
- PCI DSS: 10.2.1; 10.4.1; 1.2.3; 1.2.4; 12.5.1
- SCF: IRO-02; IRO-02.4
- SDOS: SDOS-AU-01; SDOS-RM-01
- SP 800-53 Rev 5.1.1: PM-09; PM-11; PM-18; PM-28; PM-30
- SP 800-53 Rev 5.2.0: PM-09; PM-11; PM-18; PM-28; PM-30
|
| DE.AE-05
|
[Withdrawn: Moved to DE.AE-08]
|
| DE.AE-06
|
Information on adverse events is provided to authorized staff and tools
|
- Ex1: Use cybersecurity software to generate alerts and provide them to the security operations center (SOC), incident responders, and incident response tools
- Ex2: Incident responders and other authorized personnel can access log analysis findings at all times
- Ex3: Automatically create and assign tickets in the organization's ticketing system when certain types of alerts occur
- Ex4: Manually create and assign tickets in the organization's ticketing system when technical staff discover indicators of compromise
|
- CCMv4.0: CCC-07; LOG-03; LOG-05; LOG-13; SEF-05; SEF-06
- CRI Profile v2.0: DE.AE-06; DE.AE-06.01
- CSF v1.1: DE.DP-4
- Guardian-SDK: GS-CF-02
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: IO-WRL-006; PD-WRL-001; PD-WRL-005; PD-WRL-006; PD-WRL-007
- PCI DSS: 12.10.1; 10.3.1; 10.3.3; 12.10.3
- SCF: MON-01.8; MON-01.12; MON-02; MON-02.1; IRO-02; IRO-02.4; IRO-04; IRO-07; IRO-09; IRO-10
- SDOS: SDOS-AU-01; SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01
- SP 800-53 Rev 5.1.1: IR-04; PM-15; PM-16; RA-03; RA-10
- SP 800-53 Rev 5.2.0: IR-04; PM-15; PM-16; RA-04; RA-10
|
| DE.AE-07
|
Cyber threat intelligence and other contextual information are integrated into the analysis
|
- Ex1: Securely provide cyber threat intelligence feeds to detection technologies, processes, and personnel
- Ex2: Securely provide information from asset inventories to detection technologies, processes, and personnel
- Ex3: Rapidly acquire and analyze vulnerability disclosures for the organization's technologies from suppliers, vendors, and third-party security advisories
|
- AI-SOC: AI-SOC-05; AI-SOC-11
- CCMv4.0: LOG-03; LOG-05; SEF-06
- CRI Profile v2.0: DE.AE-07; DE.AE-07.01; DE.AE-07.02
- CSF v1.1: DE.AE-3
- Guardian-SDK: GS-PF-02
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.7
- NICE Framework: DD-WRL-008; IO-WRL-001; IO-WRL-006; PD-WRL-001; PD-WRL-006
- OWASP Top 10 LLM Applications: LLM01-2025; LLM03-2025; LLM04-2025
- PCI DSS: 6.3.1; 12.5.1; 12.3.4; 6.4.3
- SCF: THR-01; THR-03
- SDOS: SDOS-DE-01; SDOS-RM-03
- SP 800-171 Rev 3: 03.11.01
- SP 800-53 Rev 5.1.1: PM-16; RA-03; RA-10
- SP 800-53 Rev 5.2.0: PM-16; RA-03; RA-10
|
| DE.AE-08
|
Incidents are declared when adverse events meet the defined incident criteria
|
- Ex1: Apply incident criteria to known and assumed characteristics of activity in order to determine whether an incident should be declared
- Ex2: Take known false positives into account when applying incident criteria
|
- CCMv4.0: LOG-03; LOG-05; SEF-02; SEF-06; SEF-07
- CRI Profile v2.0: DE.AE-08; DE.AE-08.01
- CSF v1.1: DE.AE-5
- Guardian-SDK: GS-PF-01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.25; Annex A Controls: 5.26
- NICE Framework: IO-WRL-006; OG-WRL-007; OG-WRL-010; PD-WRL-001; PD-WRL-003; PD-WRL-006
- PCI DSS: 12.10.1; 12.10.2; 12.10.4
- SCF: IRO-02; IRO-02.4
- SDOS: SDOS-AU-02; SDOS-RS-01
- SP 800-171 Rev 3: 03.06.05
- SP 800-53 Rev 5.1.1: IR-04; IR-08
- SP 800-53 Rev 5.2.0: IR-04; IR-08
|
Detection Processes (DE.DP)
[Withdrawn: Incorporated into other Categories and Functions]
DE.DP Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| DE.DP-01
|
[Withdrawn: Incorporated into GV.RR-02]
|
| DE.DP-02
|
[Withdrawn: Incorporated into DE.AE]
|
| DE.DP-03
|
[Withdrawn: Incorporated into ID.IM-02]
|
| DE.DP-04
|
[Withdrawn: Incorporated into DE.AE-06]
|
| DE.DP-05
|
[Withdrawn: Incorporated into ID.IM, ID.IM-03]
|
RESPOND (RS)
Function RS
| Outcome
|
Actions regarding a detected cybersecurity incident are taken
|
| Informative References
|
- CRI Profile v2.0: RS
- CSF v1.1: RS
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- SCF: IRO-01; IRO-02; IRO-04; IRO-07; IRO-09; IRO-10
|
Incident Management (RS.MA)
Category RS.MA
| Outcome
|
Responses to detected cybersecurity incidents are managed
|
| Informative References
|
- CRI Profile v2.0: RS.MA
- CSF v1.1: RS.RP
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.24; Annex A Controls: 5.25; Annex A Controls: 5.26; Annex A Controls: 5.27; Annex A Controls: 5.28
- NICE Framework: IO-WRL-005; IO-WRL-006; IO-WRL-007; OG-WRL-007; OG-WRL-010; OG-WRL-015; PD-WRL-001; PD-WRL-002; PD-WRL-003; PD-WRL-004; PD-WRL-005; PD-WRL-006; PD-WRL-007
- SCF: IRO-02; IRO-04; IRO-07
- SP 800-171 Rev 3: 03.06.01; 03.06.02; 03.06.05
- SP 800-53 Rev 5.1.1: IR-04; IR-07; IR-08; IR-09
- SP 800-53 Rev 5.2.0: IR-04; IR-07; IR-08; IR-09
|
RS.MA Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RS.MA-01
|
The incident response plan is executed in coordination with relevant third parties once an incident is declared
|
- Ex1: Detection technologies automatically report confirmed incidents
- Ex2: Request incident response assistance from the organization's incident response outsourcer
- Ex3: Designate an incident lead for each incident
- Ex4: Initiate execution of additional cybersecurity plans as needed to support incident response (for example, business continuity and disaster recovery)
|
- AI-SOC: AI-SOC-12; AI-SOC-04
- CCMv4.0: BCR-07; IVS-09; SEF-01; SEF-03; SEF-07
- CIS Controls v8.0: 17.4
- CIS Controls v8.1: 17.4
- CRI Profile v2.0: RS.MA-01; RS.MA-01.01
- CSF v1.1: RS.RP-1; RS.CO-4
- CoP: D1
- IRP: IRP-Sec-6
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26; Annex A Controls: 5.27; Annex A Controls: 5.28; Control 5.26
- NICE Framework: IO-WRL-005; IO-WRL-007; OG-WRL-007; OG-WRL-010; PD-WRL-001; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025; LLM04-2025
- PCI DSS: 12.10.1; 12.10.3; 12.10.2; 12.8.2
- SCF: IRO-02; IRO-02.5; IRO-04; IRO-07; IRO-10
- SP 800-171 Rev 3: 03.06.02; 03.06.05; 03.17.03
- SP 800-53 Rev 5.1.1: IR-06; IR-07; IR-08; SR-03; SR-08
- SP 800-53 Rev 5.2.0: IR-06; IR-07; IR-08; SR-03; SR-08
|
| RS.MA-02
|
Incident reports are triaged and validated
|
- Ex1: Preliminarily review incident reports to confirm that they are cybersecurity-related and necessitate incident response activities
- Ex2: Apply criteria to estimate the severity of an incident
|
- AI-SOC: AI-SOC-04; AI-SOC-06
- CCMv4.0: SEF-06
- CRI Profile v2.0: RS.MA-02; RS.MA-02.01
- CSF v1.1: RS.AN-1; RS.AN-2
- CoP: D3
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.24; Annex A Controls: 5.26; Annex A Controls: 5.27; Annex A Controls: 5.28; Annex A Controls: 6.8
- NICE Framework: IO-WRL-005; IO-WRL-006; IO-WRL-007; PD-WRL-001; PD-WRL-002; PD-WRL-003; PD-WRL-005
- OWASP Top 10 LLM Applications: LLM01-2025; LLM02-2025
- PCI DSS: 10.4.1; 10.2.1; 12.10.1; 12.10.4
- SCF: IRO-02; IRO-04
- SDOS: SDOS-AU-01; SDOS-RS-01
- SP 800-171 Rev 3: 03.06.01; 03.06.02
- SP 800-53 Rev 5.1.1: IR-04; IR-05; IR-06
- SP 800-53 Rev 5.2.0: IR-04; IR-05; IR-06
|
| RS.MA-03
|
Incidents are categorized and prioritized
|
- Ex1: Further review and categorize incidents based on the type of incident (e.g., data breach, ransomware, DDoS, account compromise)
- Ex2: Prioritize incidents based on their scope, likely impact, and time-critical nature
- Ex3: Select incident response strategies for active incidents by balancing the need to quickly recover from an incident with the need to observe the attacker or conduct a more thorough investigation
|
- CCMv4.0: SEF-02; SEF-06
- CRI Profile v2.0: RS.MA-03; RS.MA-03.01
- CSF v1.1: RS.AN-4; RS.AN-2
- Guardian-SDK: GS-PF-04
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.25
- NICE Framework: IO-WRL-005; IO-WRL-006; IO-WRL-007; PD-WRL-001; PD-WRL-002; PD-WRL-003; PD-WRL-006
- PCI DSS: 12.10.1; 10.4.1; 12.10.2; 12.10.6
- SCF: IRO-02.4
- SDOS: SDOS-AU-01; SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01; 03.06.02
- SP 800-53 Rev 5.1.1: IR-04; IR-05; IR-06
- SP 800-53 Rev 5.2.0: IR-04; IR-05; IR-06
|
| RS.MA-04
|
Incidents are escalated or elevated as needed
|
- Ex1: Track and validate the status of all ongoing incidents
- Ex2: Coordinate incident escalation or elevation with designated internal and external stakeholders
|
- CCMv4.0: SEF-02
- CRI Profile v2.0: RS.MA-04; RS.MA-04.01
- CSF v1.1: RS.AN-2; RS.CO-4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: IO-WRL-005; IO-WRL-006; IO-WRL-007; PD-WRL-001; PD-WRL-003; PD-WRL-007
- PCI DSS: 12.10.3; 12.10.1; 12.10.2
- SCF: IRO-02; IRO-04; IRO-07
- SDOS: SDOS-DE-01; SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01; 03.06.02
- SP 800-53 Rev 5.1.1: IR-04; IR-05; IR-06; IR-07
- SP 800-53 Rev 5.2.0: IR-04; IR-05; IR-06; IR-07
|
| RS.MA-05
|
The criteria for initiating incident recovery are applied
|
- Ex1: Apply incident recovery criteria to known and assumed characteristics of the incident to determine whether incident recovery processes should be initiated
- Ex2: Take the possible operational disruption of incident recovery activities into account
|
- AI-SOC: AI-SOC-12; AI-SOC-04
- CCMv4.0: SEF-02
- CIS Controls v8.0: 17.9
- CIS Controls v8.1: 17.9
- CRI Profile v2.0: RS.MA-05; RS.MA-05.01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.25
- NICE Framework: IO-WRL-005; IO-WRL-007; OG-WRL-007; OG-WRL-010; OG-WRL-015; PD-WRL-001; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1; 12.10.2; 12.10.6
- SCF: BCD-01
- SDOS: SDOS-AU-01; SDOS-RM-01; SDOS-RS-01
- SP 800-171 Rev 3: 03.06.01; 03.06.05
- SP 800-53 Rev 5.1.1: IR-04; IR-08
- SP 800-53 Rev 5.2.0: IR-04; IR-08
|
Incident Analysis (RS.AN)
Category RS.AN
| Outcome
|
Investigations are conducted to ensure effective response and support forensics and recovery activities
|
| Informative References
|
- CRI Profile v2.0: RS.AN
- CSF v1.1: RS.AN
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26; Annex A Controls: 5.28
- NICE Framework: IO-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-006; OG-WRL-012; PD-WRL-002; PD-WRL-003; PD-WRL-004
- SCF: IRO-02; IRO-08
- SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
RS.AN Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RS.AN-01
|
[Withdrawn: Incorporated into RS.MA-02]
|
| RS.AN-02
|
[Withdrawn: Incorporated into RS.MA-02, RS.MA-03, RS.MA-04]
|
| RS.AN-03
|
Analysis is performed to establish what has taken place during an incident and the root cause of the incident
|
- Ex1: Determine the sequence of events that occurred during the incident and which assets and resources were involved in each event
- Ex2: Attempt to determine what vulnerabilities, threats, and threat actors were directly or indirectly involved in the incident
- Ex3: Analyze the incident to find the underlying, systemic root causes
- Ex4: Check any cyber deception technology for additional information on attacker behavior
|
- AI-SOC: AI-SOC-23; AI-SOC-13
- CCMv4.0: SEF-06
- CIS Controls v8.0: 17.8
- CIS Controls v8.1: 17.8
- CRI Profile v2.0: RS.AN-03; RS.AN-03.01
- CSF v1.1: RS.AN-3
- CoP: D4
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.25; Annex A Controls: 5.27
- NICE Framework: IO-WRL-001; IO-WRL-003; IO-WRL-006; OG-WRL-012; PD-WRL-002; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM04-2025; LLM05-2025
- PCI DSS: 10.2.1; 10.4.1; 6.3.1; 10.2.2
- SCF: IRO-13
- SDOS: SDOS-AU-01; SDOS-AU-02; SDOS-DE-02; SDOS-RS-01
- SP 800-171 Rev 3: 03.03.06; 03.06.01
- SP 800-53 Rev 5.1.1: AU-07; IR-04
- SP 800-53 Rev 5.2.0: AU-07; IR-04; SI-02(07)
|
| RS.AN-04
|
[Withdrawn: Moved to RS.MA-03]
|
| RS.AN-05
|
[Withdrawn: Moved to ID.RA-08]
|
| RS.AN-06
|
Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved
|
- Ex1: Require each incident responder and others (e.g., system administrators, cybersecurity engineers) who perform incident response tasks to record their actions and make the record immutable
- Ex2: Require the incident lead to document the incident in detail and be responsible for preserving the integrity of the documentation and the sources of all information being reported
|
- CRI Profile v2.0: RS.AN-06; RS.AN-06.01
- CSF v1.1: RS.AN-3
- Guardian-SDK: GS-CF-02
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.28
- NICE Framework: IO-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-006; PD-WRL-002; PD-WRL-003; PD-WRL-004
- PCI DSS: 10.3.2; 10.3.1; 10.3.3; 10.3.4; 10.6.1; 10.5.1
- SCF: IRO-02; IRO-08; IRO-09
- SDOS: SDOS-AU-01; SDOS-AU-03
- SP 800-171 Rev 3: 03.03.06; 03.06.01; 03.06.02
- SP 800-53 Rev 5.1.1: AU-07; IR-04; IR-06
- SP 800-53 Rev 5.2.0: AU-07; IR-04; IR-06
|
| RS.AN-07
|
Incident data and metadata are collected, and their integrity and provenance are preserved
|
- Ex1: Collect, preserve, and safeguard the integrity of all pertinent incident data and metadata (e.g., data source, date/time of collection) based on evidence preservation and chain-of-custody procedures
|
- AI-SOC: AI-SOC-23; AI-SOC-22
- CRI Profile v2.0: RS.AN-07; RS.AN-07.01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.28; Control 5.28
- NICE Framework: IO-WRL-001; IO-WRL-002; IO-WRL-003; IO-WRL-006; PD-WRL-002; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM02-2025; LLM04-2025
- PCI DSS: 10.2.1; 10.3.2; 10.3.3; 10.6.1; 10.2.2
- SCF: IRO-08
- SDOS: SDOS-AU-01; SDOS-AU-03
- SP 800-171 Rev 3: 03.03.06; 03.06.01; 03.06.02
- SP 800-53 Rev 5.1.1: AU-07; IR-04; IR-06
- SP 800-53 Rev 5.2.0: AU-07; IR-04; IR-06
- SP 800-81r3: 2.1.3
|
| RS.AN-08
|
An incident's magnitude is estimated and validated
|
- Ex1: Review other potential targets of the incident to search for indicators of compromise and evidence of persistence
- Ex2: Automatically run tools on targets to look for indicators of compromise and evidence of persistence
|
- AI-SOC: AI-SOC-06; AI-SOC-17
- CRI Profile v2.0: RS.AN-08; RS.AN-08.01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.25
- NICE Framework: IO-WRL-001; IO-WRL-003; IO-WRL-006; OG-WRL-012; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM02-2025; LLM04-2025
- PCI DSS: 10.4.1; 1.2.3; 1.2.4; 12.5.1
- SCF: IRO-02.4
- SDOS: SDOS-AU-01; SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01; 03.06.05; 03.11.01; 03.11.04
- SP 800-53 Rev 5.1.1: IR-04; IR-08; RA-03; RA-07
- SP 800-53 Rev 5.2.0: IR-04; IR-08; RA-03; RA-07
|
Incident Response Reporting and Communication (RS.CO)
Category RS.CO
| Outcome
|
Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies
|
| Informative References
|
- CRI Profile v2.0: RS.CO
- CSF v1.1: RS.CO
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-015; PD-WRL-003
- SCF: IRO-02; IRO-02.5; IRO-06.1; IRO-09; IRO-10; IRO-10.4
- SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
RS.CO Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RS.CO-01
|
[Withdrawn: Incorporated into PR.AT-01]
|
| RS.CO-02
|
Internal and external stakeholders are notified of incidents
|
- Ex1: Follow the organization's breach notification procedures after discovering a data breach incident, including notifying affected customers
- Ex2: Notify business partners and customers of incidents in accordance with contractual requirements
- Ex3: Notify law enforcement agencies and regulatory bodies of incidents based on criteria in the incident response plan and management approval
|
- AI-SOC: AI-SOC-30; AI-SOC-12
- CCMv4.0: DSP-18; SEF-02; SEF-07; SEF-08
- CIS Controls v8.0: 17.2
- CIS Controls v8.1: 17.2
- CRI Profile v2.0: RS.CO-02; RS.CO-02.01; RS.CO-02.02; RS.CO-02.03
- CSF v1.1: RS.CO-2; RS.CO-3
- Guardian-SDK: GS-CF-02
- ISO/IEC 27001:2022: Mandatory Clause: 7.4; Annex A Controls: 5.26
- NICE Framework: OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-015; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM02-2025
- PCI DSS: 12.10.1; 12.10.3; 12.8.2; 12.8.5
- SCF: IRO-02; IRO-10; IRO-10.4
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01; 03.06.02; 03.17.03
- SP 800-53 Rev 5.1.1: IR-04; IR-06; IR-07; SR-03; SR-08
- SP 800-53 Rev 5.2.0: IR-04; IR-06; IR-07; SR-03; SR-08
|
| RS.CO-03
|
Information is shared with designated internal and external stakeholders
|
- Ex1: Securely share information consistent with response plans and information sharing agreements
- Ex2: Voluntarily share information about an attacker's observed TTPs, with all sensitive data removed, with an Information Sharing and Analysis Center (ISAC)
- Ex3: Notify HR when malicious insider activity occurs
- Ex4: Regularly update senior leadership on the status of major incidents
- Ex5: Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
- Ex6: Coordinate crisis communication methods between the organization and its critical suppliers
|
- AI-SOC: AI-SOC-30; AI-SOC-12
- CCMv4.0: BCR-07; DSP-18; SEF-07; SEF-08
- CIS Controls v8.0: 17.2
- CIS Controls v8.1: 17.2
- CRI Profile v2.0: RS.CO-03; RS.CO-03.01; RS.CO-03.02
- CSF v1.1: RS.CO-3; RS.CO-5
- ISO/IEC 27001:2022: Mandatory Clause: 7.4; Annex A Controls: 5.26
- NICE Framework: OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-015; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM02-2025; LLM03-2025
- PCI DSS: 12.10.1; 12.8.2; 12.8.4; 12.10.6
- SCF: IRO-02; IRO-10; IRO-10.4
- SDOS: SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01; 03.06.02; 03.17.03
- SP 800-53 Rev 5.1.1: IR-04; IR-06; IR-07; SR-03; SR-08
- SP 800-53 Rev 5.2.0: IR-04; IR-06; IR-07; SR-03; SR-08
- SP 800-81r3: 2.3.3; 3.4.2
|
| RS.CO-04
|
[Withdrawn: Incorporated into RS.MA-01, RS.MA-04]
|
| RS.CO-05
|
[Withdrawn: Incorporated into RS.CO-03]
|
Incident Mitigation (RS.MI)
Category RS.MI
| Outcome
|
Activities are performed to prevent expansion of an event and mitigate its effects
|
| Informative References
|
- CRI Profile v2.0: RS.MI
- CSF v1.1: RS.MI
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: DD-WRL-001; IO-WRL-005; IO-WRL-007; OG-WRL-014; PD-WRL-003; PD-WRL-004
- SCF: IRO-01; IRO-02; IRO-04
- SP-800-37 Rev 2: RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
RS.MI Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RS.MI-01
|
Incidents are contained
|
- Ex1: Cybersecurity technologies (e.g., antivirus software) and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform containment actions
- Ex2: Allow incident responders to manually select and perform containment actions
- Ex3: Allow a third party (e.g., internet service provider, managed security service provider) to perform containment actions on behalf of the organization
- Ex4: Automatically transfer compromised endpoints to a remediation virtual local area network (VLAN)
|
- AI-SOC: AI-SOC-07; AI-SOC-24
- BXAIOS: Chapter 7 - Deploy the Governor
- CCMv4.0: CEK-19; CEK-20; IVS-09; SEF-02; UEM-09
- CRI Profile v2.0: RS.MI-01; RS.MI-01.01
- CSF v1.1: RS.MI-1
- Guardian-SDK: GS-PF-01; GS-PO-01; GS-AG-01
- IRP: IRP-Sec-5
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: DD-WRL-001; IO-WRL-005; IO-WRL-007; OG-WRL-014; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM04-2025; LLM06-2025; LLM10-2025
- PCI DSS: 12.10.1; 5.2.1; 5.2.2; 5.3.2
- SCF: IRO-02
- SDOS: SDOS-EN-01; SDOS-EN-03; SDOS-IN-02
- SP 800-171 Rev 3: 03.06.01
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.2.0: IR-04
- SP 800-81r3: 3.6.3
|
| RS.MI-02
|
Incidents are eradicated
|
- Ex1: Cybersecurity technologies and cybersecurity features of other technologies (e.g., operating systems, network infrastructure devices) automatically perform eradication actions
- Ex2: Allow incident responders to manually select and perform eradication actions
- Ex3: Allow a third party (e.g., managed security service provider) to perform eradication actions on behalf of the organization
|
- AI-SOC: AI-SOC-24; AI-SOC-08
- CCMv4.0: CEK-19; IVS-09; SEF-02; SEF-06
- CRI Profile v2.0: RS.MI-02; RS.MI-02.01
- CSF v1.1: RS.MI-2
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: DD-WRL-001; IO-WRL-005; IO-WRL-007; OG-WRL-014; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM01-2025; LLM03-2025; LLM04-2025
- PCI DSS: 12.10.1; 6.3.3; 5.2.2; 6.2.3; 2.2.1
- SCF: IRO-02
- SDOS: SDOS-GV-01; SDOS-IA-02
- SP 800-171 Rev 3: 03.06.01
- SP 800-53 Rev 5.1.1: IR-04
- SP 800-53 Rev 5.2.0: IR-04
|
| RS.MI-03
|
[Withdrawn: Incorporated into ID.RA-06]
|
Response Planning (RS.RP)
[Withdrawn: Incorporated into RS.MA]
RS.RP Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RS.RP-01
|
[Withdrawn: Incorporated into RS.MA-01]
|
Improvements (RS.IM)
[Withdrawn: Incorporated into ID.IM]
RS.IM Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RS.IM-01
|
[Withdrawn: Incorporated into ID.IM-03, ID.IM-04]
|
| RS.IM-02
|
[Withdrawn: Incorporated into ID.IM-03]
|
RECOVER (RC)
Function RC
| Outcome
|
Assets and operations affected by a cybersecurity incident are restored
|
| Informative References
|
- CRI Profile v2.0: RC
- CSF v1.1: RC
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.29; Annex A Controls: 8.13
- SCF: BCD-01; BCD-12
|
Incident Recovery Plan Execution (RC.RP)
Category RC.RP
| Outcome
|
Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents
|
| Informative References
|
- CRI Profile v2.0: RC.RP
- CSF v1.1: RC.RP
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.13
- NICE Framework: DD-WRL-002; IO-WRL-002; IO-WRL-005; OG-WRL-002; OG-WRL-007; OG-WRL-009; OG-WRL-010; OG-WRL-011; OG-WRL-014; OG-WRL-015; PD-WRL-003; PD-WRL-004
- SCF: BCD-01; BCD-01.4; BCD-02; BCD-02.1
- SP 800-53 Rev 5.1.1: CP-04; CP-10
- SP 800-53 Rev 5.2.0: CP-04; CP-10
|
RC.RP Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RC.RP-01
|
The recovery portion of the incident response plan is executed once initiated from the incident response process
|
- Ex1: Begin recovery procedures during or after incident response processes
- Ex2: Make all individuals with recovery responsibilities aware of the plans for recovery and the authorizations required to implement each aspect of the plans
|
- AI-SOC: AI-SOC-25; AI-SOC-24
- CCMv4.0: BCR-01; SEF-03
- CRI Profile v2.0: RC.RP-01; RC.RP-01.01
- CSF v1.1: RC.RP-1
- CoP: D1
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26; Control 5.29
- NICE Framework: DD-WRL-002; IO-WRL-005; OG-WRL-002; OG-WRL-009; OG-WRL-014; OG-WRL-015; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1; 12.10.3; 12.10.2
- SCF: BCD-12
- SP 800-171 Rev 3: 03.06.01; 03.06.05
- SP 800-53 Rev 5.1.1: CP-10; IR-04; IR-08
- SP 800-53 Rev 5.2.0: CP-10; IR-04; IR-08
|
| RC.RP-02
|
Recovery actions are selected, scoped, prioritized, and performed
|
- Ex1: Select recovery actions based on the criteria defined in the incident response plan and available resources
- Ex2: Change planned recovery actions based on a reassessment of organizational needs and resources
|
- AI-SOC: AI-SOC-25; AI-SOC-06
- CCMv4.0: SEF-06
- CRI Profile v2.0: RC.RP-02; RC.RP-02.01; RC.RP-02.02
- CSF v1.1: RC.RP-1
- Guardian-SDK: GS-PO-02
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26; Control 5.30
- NICE Framework: DD-WRL-002; IO-WRL-005; OG-WRL-014; OG-WRL-015; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM04-2025; LLM10-2025
- PCI DSS: 12.10.1; 12.10.2; 12.10.6; 1.2.3; 1.2.4
- SCF: BCD-01; BCD-01.4; BCD-02; BCD-02.1
- SDOS: SDOS-AU-01; SDOS-RM-01
- SP 800-171 Rev 3: 03.06.01; 03.06.05
- SP 800-53 Rev 5.1.1: CP-10; IR-04; IR-08
- SP 800-53 Rev 5.2.0: CP-10; IR-04; IR-08
|
| RC.RP-03
|
The integrity of backups and other restoration assets is verified before using them for restoration
|
- Ex1: Check restoration assets for indicators of compromise, file corruption, and other integrity issues before use
|
- AI-SOC: AI-SOC-25; AI-SOC-23
- CCMv4.0: BCR-08
- CIS Controls v8.0: 11.5
- CIS Controls v8.1: 11.5
- CRI Profile v2.0: RC.RP-03; RC.RP-03.01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 8.13
- NICE Framework: DD-WRL-002; IO-WRL-002; IO-WRL-005; OG-WRL-014; OG-WRL-015; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM04-2025
- PCI DSS: 12.10.1; 5.3.2; 9.4.1.1; 9.4.1.2
- SCF: BCD-13
- SDOS: SDOS-IN-01; SDOS-IN-02
- SP 800-171 Rev 3: 03.08.09
- SP 800-53 Rev 5.1.1: CP-02; CP-04; CP-09
- SP 800-53 Rev 5.2.0: CP-02; CP-04; CP-09
|
| RC.RP-04
|
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms
|
- Ex1: Use business impact and system categorization records (including service delivery objectives) to validate that essential services are restored in the appropriate order
- Ex2: Work with system owners to confirm the successful restoration of systems and the return to normal operations
- Ex3: Monitor the performance of restored systems to verify the adequacy of the restoration
|
- AI-SOC: AI-SOC-25; AI-SOC-24
- CRI Profile v2.0: RC.RP-04; RC.RP-04.01
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Annex A Controls: None
- NICE Framework: DD-WRL-002; IO-WRL-005; OG-WRL-011; OG-WRL-014; OG-WRL-015; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM09-2025
- PCI DSS: 12.10.1; 12.5.1; 1.2.3; 1.2.4; 10.2.1
- SCF: BCD-01; BCD-01.4; BCD-02; BCD-02.1
- SP 800-171 Rev 3: 03.06.05; 03.15.01
- SP 800-53 Rev 5.1.1: PM-08; PM-09; PM-11; IR-01; IR-08
- SP 800-53 Rev 5.2.0: PM-08; PM-09; PM-11; IR-01; IR-08
|
| RC.RP-05
|
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
|
- Ex1: Check restored assets for indicators of compromise and remediation of root causes of the incident before production use
- Ex2: Verify the correctness and adequacy of the restoration actions taken before putting a restored system online
|
- AI-SOC: AI-SOC-25; AI-SOC-02
- CRI Profile v2.0: RC.RP-05; RC.RP-05.01; RC.RP-05.02
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.26
- NICE Framework: DD-WRL-002; IO-WRL-002; IO-WRL-005; OG-WRL-014; OG-WRL-015; PD-WRL-003; PD-WRL-004
- OWASP Top 10 LLM Applications: LLM03-2025; LLM04-2025
- PCI DSS: 11.4.4; 6.2.3; 10.4.1
- SCF: BCD-12
- SDOS: SDOS-IA-02; SDOS-IN-01; SDOS-IN-03
- SP 800-53 Rev 5.1.1: CP-10
- SP 800-53 Rev 5.2.0: CP-10
|
| RC.RP-06
|
The end of incident recovery is declared based on criteria, and incident-related documentation is completed
|
- Ex1: Prepare an after-action report that documents the incident itself, the response and recovery actions taken, and lessons learned
- Ex2: Declare the end of incident recovery once the criteria are met
|
- CRI Profile v2.0: RC.RP-06; RC.RP-06.01
- ISO/IEC 27001:2022: Mandatory Clause: None; Annex A Controls: 5.27; Annex A Controls: 8.13
- NICE Framework: DD-WRL-002; IO-WRL-005; OG-WRL-007; OG-WRL-010; OG-WRL-014; OG-WRL-015; PD-WRL-003
- PCI DSS: 12.10.6; 12.10.2; 10.5.1
- SCF: IRO-02; IRO-09
- SDOS: SDOS-AU-01; SDOS-IN-01; SDOS-IN-03
- SP 800-171 Rev 3: 03.06.01; 03.06.05
- SP 800-53 Rev 5.1.1: IR-04; IR-08
- SP 800-53 Rev 5.2.0: IR-04; IR-08
|
Incident Recovery Communication (RC.CO)
Category RC.CO
| Outcome
|
Restoration activities are coordinated with internal and external parties
|
| Informative References
|
- CRI Profile v2.0: RC.CO
- CSF v1.1: RC.CO
- ISO/IEC 27001:2022: Mandatory Clause: 8.1; Annex A Controls: 5.28
- NICE Framework: IO-WRL-005; OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-011; OG-WRL-015; PD-WRL-003
- SCF: BCD-01.1; BCD-01.2
- SP-800-37 Rev 2: RMF Prepare Step (Organization & Mission/Business Levels): TASK P-2 Risk Management Strategy; RMF Monitor Step: TASK M-3 Ongoing Risk Response
|
RC.CO Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RC.CO-01
|
[Withdrawn: Incorporated into RC.CO-04]
|
| RC.CO-02
|
[Withdrawn: Incorporated into RC.CO-04]
|
| RC.CO-03
|
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders
|
- Ex1: Securely share recovery information, including restoration progress, consistent with response plans and information sharing agreements
- Ex2: Regularly update senior leadership on recovery status and restoration progress for major incidents
- Ex3: Follow the rules and protocols defined in contracts for incident information sharing between the organization and its suppliers
- Ex4: Coordinate crisis communication between the organization and its critical suppliers
|
- CRI Profile v2.0: RC.CO-03; RC.CO-03.01; RC.CO-03.02
- CSF v1.1: RC.CO-3
- ISO/IEC 27001:2022: Mandatory Clause: 7.4; Annex A Controls: 5.28
- NICE Framework: IO-WRL-005; OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-011; OG-WRL-015; PD-WRL-003
- PCI DSS: 12.10.1; 12.10.3; 12.8.2; 12.8.4
- SDOS: SDOS-AU-01; SDOS-AU-03
- SP 800-171 Rev 3: 03.06.01; 03.06.02
- SP 800-221A: GV.CO-1
- SP 800-53 Rev 5.1.1: IR-04; IR-06; SR-08
- SP 800-53 Rev 5.2.0: IR-04; IR-06; SR-08
|
| RC.CO-04
|
Public updates on incident recovery are shared using approved methods and messaging
|
- Ex1: Follow the organization's breach notification procedures for recovering from a data breach incident
- Ex2: Explain the steps being taken to recover from the incident and to prevent a recurrence
|
- AI-SOC: AI-SOC-30; AI-SOC-12
- CIS Controls v8.0: 17.2; 17.6
- CIS Controls v8.1: 17.2; 17.6
- CRI Profile v2.0: RC.CO-04; RC.CO-04.01
- CSF v1.1: RC.CO-1; RS.CO-2
- ISO/IEC 27001:2022: Mandatory Clause: 7.4; Annex A Controls: None
- NICE Framework: OG-WRL-006; OG-WRL-007; OG-WRL-008; OG-WRL-010; OG-WRL-015; PD-WRL-003
- OWASP Top 10 LLM Applications: LLM02-2025
- PCI DSS: 12.10.1; 12.10.3
- SCF: IRO-16
- SP 800-171 Rev 3: 03.06.01
- SP 800-221A: GV.CO-1
- SP 800-53 Rev 5.1.1: CP-02; IR-04
- SP 800-53 Rev 5.2.0: CP-02; IR-04
|
Improvements (RC.IM)
[Withdrawn: Incorporated into ID.IM]
RC.IM Subcategories
| Subcategory
|
Outcome
|
Implementation Examples
|
Informative References
|
| RC.IM-01
|
[Withdrawn: Incorporated into ID.IM-03, ID.IM-04]
|
| RC.IM-02
|
[Withdrawn: Incorporated into ID.IM-03]
|