Back to Frameworks
NIS
NIST CSF
v2.0ACTIVENIST Cybersecurity Framework
The U.S. National Institute of Standards and Technology Cybersecurity Framework. Widely adopted globally as a baseline for cybersecurity risk management.
15
Total Controls
6
Domains
11
Cross-Framework Mappings
International
Region
Detect
2DE.CM-01HIGH1 mappingNetworks and network services are monitored
DE.CM-01HIGH1 mappingNetworks and network services are monitored
Mapped to Other Frameworks
DE.CM-06MEDIUMExternal service provider activities are monitored
DE.CM-06MEDIUMExternal service provider activities are monitored
Govern
3GV.PO-01HIGH1 mappingCybersecurity risk management policy established
GV.PO-01HIGH1 mappingCybersecurity risk management policy established
Mapped to Other Frameworks
GV.RM-01HIGH1 mappingRisk management objectives established
GV.RM-01HIGH1 mappingRisk management objectives established
Mapped to Other Frameworks
GV.RR-01HIGH1 mappingOrganizational context for cybersecurity risk management
GV.RR-01HIGH1 mappingOrganizational context for cybersecurity risk management
Mapped to Other Frameworks
Identify
3ID.AM-01HIGHInventories of hardware managed by the organization
ID.AM-01HIGHInventories of hardware managed by the organization
ID.AM-02HIGHInventories of software managed by the organization
ID.AM-02HIGHInventories of software managed by the organization
ID.RA-01HIGH1 mappingVulnerabilities in assets are identified
ID.RA-01HIGH1 mappingVulnerabilities in assets are identified
Mapped to Other Frameworks
Protect
4PR.AA-01HIGH1 mappingIdentities and credentials for authorized users managed
PR.AA-01HIGH1 mappingIdentities and credentials for authorized users managed
Mapped to Other Frameworks
PR.AA-03HIGH1 mappingUsers, services, and hardware are authenticated
PR.AA-03HIGH1 mappingUsers, services, and hardware are authenticated
Mapped to Other Frameworks
PR.PS-01HIGH1 mappingConfiguration management practices established
PR.PS-01HIGH1 mappingConfiguration management practices established
Mapped to Other Frameworks
PR.PS-02HIGHSoftware is maintained, replaced, and removed
PR.PS-02HIGHSoftware is maintained, replaced, and removed
Recover
1RC.RP-01HIGH1 mappingRecovery plan is executed
RC.RP-01HIGH1 mappingRecovery plan is executed
Mapped to Other Frameworks
Respond
2RS.MA-01HIGH1 mappingIncident management plan is executed
RS.MA-01HIGH1 mappingIncident management plan is executed
Mapped to Other Frameworks
RS.MI-01HIGH1 mappingIncidents are contained
RS.MI-01HIGH1 mapping