Skip to content

Evidence request lists

NIST Cybersecurity Framework 2.0

Evidence request list. 106 controls, 106 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

DE - Detect

NIST-CSF-DE.AE-02
Potentially adverse events are analyzed to better understand associated activities

Potentially adverse events are analyzed to better understand associated activities. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.

Artefacts an auditor will ask for
  • SIEM correlation rule library with detection logic versioning
  • Adverse event triage runbook with severity scoring criteria
  • Analyst case notes documenting activity reconstruction
  • Threat hunting reports tied to correlated events
  • MITRE ATT&CK technique mapping for detected behaviors
Where this commonly fails
  • Correlation rules tuned only for known IOC patterns, missing behavioral chains
  • No documented hypothesis when escalating events to incidents
  • Analyst notes stored in chat threads rather than the case system
  • ATT&CK mapping inconsistent across analysts
NIST-CSF-DE.AE-03
Information is correlated from multiple sources

Information is correlated from multiple sources. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.

Artefacts an auditor will ask for
  • Log source inventory with coverage matrix against asset register
  • Data normalization schema for SIEM ingest pipelines
  • Cross-source correlation queries (network, endpoint, identity, cloud)
  • SOAR playbooks that enrich events with threat intelligence
  • Sample correlated alert with multi-source citation trail
Where this commonly fails
  • SaaS and PaaS logs not piped to the SIEM
  • Timestamp skew across sources defeats correlation joins
  • Identity provider logs not joined to endpoint telemetry
  • Enrichment relies on stale threat feeds
NIST-CSF-DE.AE-04
The estimated impact and scope of adverse events are understood

The estimated impact and scope of adverse events are understood

Artefacts an auditor will ask for
  • Impact scoring rubric tied to business service catalog
  • Blast radius assessment template populated for recent events
  • Service dependency map referenced during triage
  • Data classification overlay used to estimate exposure
  • Severity decision log with assessor identity and timestamp
Where this commonly fails
  • Impact estimates not linked to the service catalog
  • No method to estimate scope when telemetry is partial
  • Data classification missing on cloud storage assets
  • Severity overridden without rationale captured
NIST-CSF-DE.AE-06
Information on adverse events is provided to authorized staff and tools

Information on adverse events is provided to authorized staff and tools

Artefacts an auditor will ask for
  • Notification matrix mapping event severity to recipient roles
  • Ticketing workflow with mandatory acknowledgement step
  • On-call rotation roster with paging path tested quarterly
  • Distribution list governance with review log
  • Sample notification trace from event detection to receipt
Where this commonly fails
  • Recipients lists outdated when staff change roles
  • Pager fatigue causes acknowledgement timeouts
  • Critical vendors not in notification matrix
  • No closed loop confirming receipt by named individual
NIST-CSF-DE.AE-07
Cyber threat intelligence and other contextual information are integrated into the analysis

Cyber threat intelligence and other contextual information are integrated into the analysis

Artefacts an auditor will ask for
  • Threat intelligence platform integration with SIEM
  • Indicator lifecycle policy with expiry and tiering
  • Analyst pivot guide combining CTI with internal context
  • Subscription roster with feed quality scoring
  • Quarterly CTI value assessment report
Where this commonly fails
  • CTI feeds duplicated rather than deduplicated
  • No mapping of CTI to crown jewel assets
  • Stale indicators inflate false positive rate
  • Intel only consumed in SOC, not informing IR or risk
NIST-CSF-DE.AE-08
Incidents are declared when adverse events meet the defined incident criteria

Incidents are declared when adverse events meet the defined incident criteria

Artefacts an auditor will ask for
  • Incident declaration criteria document with examples
  • Triage decision tree from event to incident
  • Declared incident log with criteria citation
  • Tabletop exercise demonstrating declaration thresholds
  • Post-incident review on declaration timing
Where this commonly fails
  • Criteria framed in security jargon, not business outcomes
  • Analysts hesitant to declare due to escalation overhead
  • No retro on declarations that should have been earlier
  • Criteria not refreshed after major architecture changes
NIST-CSF-DE.CM-01
Networks and network services are monitored to find potentially adverse events

Networks and network services are monitored to find potentially adverse events. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.

Artefacts an auditor will ask for
  • Network flow telemetry coverage map by segment
  • IDS or NDR sensor inventory with placement diagram
  • DNS query analytics pipeline configuration
  • East-west traffic monitoring sample alerts
  • Egress monitoring policy and exception register
Where this commonly fails
  • Encrypted traffic not inspected at chokepoints
  • Container and service mesh traffic invisible
  • Egress rules logged but not alerted on
  • DNS sinkhole only covers known bad domains
NIST-CSF-DE.CM-02
The physical environment is monitored to find potentially adverse events

The physical environment is monitored to find potentially adverse events. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.

Artefacts an auditor will ask for
  • Physical access logs integrated with security operations
  • CCTV coverage map with retention policy
  • Environmental sensor telemetry feed (door, temperature, motion)
  • Tailgating detection review records
  • Visitor management system reports with anomaly flags
Where this commonly fails
  • Physical and logical SOCs operate in silos
  • Co-location facilities outside the monitoring scope
  • CCTV retention shorter than incident discovery windows
  • Sensor alerts not joined to identity context
NIST-CSF-DE.CM-03
Personnel activity and technology usage are monitored to find potentially adverse events

Personnel activity and technology usage are monitored to find potentially adverse events. Control from NIST Cybersecurity Framework 2.0 framework, domain: DE - Detect.

Artefacts an auditor will ask for
  • User and entity behavior analytics deployment scope
  • Insider risk indicator catalog with thresholds
  • DLP policy library with detection telemetry
  • Privileged session recording configuration
  • Acceptable use monitoring notice and acknowledgement records
Where this commonly fails
  • Behavior baselines stale after org changes
  • DLP only covers email, not cloud sharing
  • Privileged sessions recorded but not reviewed
  • Workforce notice not refreshed for new monitoring tools
NIST-CSF-DE.CM-06
External service provider activities and services are monitored to find potentially adverse events

External service provider activities and services are monitored to find potentially adverse events

Artefacts an auditor will ask for
  • Vendor monitoring agreement with telemetry obligations
  • Third party access logging configuration
  • Continuous control monitoring reports from MSP
  • Vendor risk dashboard with anomaly indicators
  • Joint monitoring runbook with named contacts
Where this commonly fails
  • Vendor logs not ingested into the central SIEM
  • Privileged third party access not separately tagged
  • No alerting on vendor anomalies, only periodic review
  • Contract clauses not enforced when telemetry stops
NIST-CSF-DE.CM-09
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Artefacts an auditor will ask for
  • EDR coverage report by asset class
  • File integrity monitoring baseline and drift alerts
  • Software inventory reconciliation with allowlist
  • Hardware tamper detection telemetry
  • Patch and configuration drift dashboard
Where this commonly fails
  • EDR exclusions accumulate without review
  • FIM only on a subset of critical systems
  • Ephemeral workloads outside the monitoring scope
  • Drift alerts tuned out due to false positive volume

GV - Govern

NIST-CSF-GV.OC-01
The organizational mission is understood and informs cybersecurity risk management

The organizational mission is understood and informs cybersecurity risk management

Artefacts an auditor will ask for
  • Cybersecurity mission statement endorsed by leadership
  • Business context analysis tying cyber program to strategy
  • Stakeholder map for cybersecurity governance
  • Organizational chart showing security accountability
  • Annual context review minutes
Where this commonly fails
  • Context document predates major business changes
  • Cybersecurity mission not referenced in strategy decks
  • Subsidiaries outside the stated scope
  • No record of board endorsement
NIST-CSF-GV.OC-02
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered

Artefacts an auditor will ask for
  • Stakeholder register with cybersecurity interests captured
  • Internal and external stakeholder communication plan
  • Workshop notes from stakeholder discovery sessions
  • Regulator and customer engagement log
  • Board reporting cadence for cyber matters
Where this commonly fails
  • Customers as stakeholders not represented
  • Stakeholder needs never re-validated
  • Regulators only contacted in incidents
  • Internal audit not in the stakeholder map
NIST-CSF-GV.OC-03
Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed

Artefacts an auditor will ask for
  • Legal and regulatory obligations register with owners
  • Contractual security clauses summary across customer base
  • Compliance calendar tracking filings and attestations
  • Counsel sign off on obligations interpretation
  • Change log when new obligations are added
Where this commonly fails
  • Register not maintained when laws change
  • Customer contracts not parsed for security clauses
  • Cross border data flows missing from the register
  • No owner assigned to emerging regulations
NIST-CSF-GV.OC-04
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

Artefacts an auditor will ask for
  • Critical service catalog with objectives and tolerances
  • Business impact analysis aligned to critical objectives
  • Capability map linking security to mission outcomes
  • RTO and RPO commitments per critical service
  • Annual critical service review minutes
Where this commonly fails
  • BIA outputs not referenced in security investment
  • Critical services list inconsistent across teams
  • Tolerances expressed in IT terms, not customer outcomes
  • Service catalog and CMDB diverge
NIST-CSF-GV.OC-05
Outcomes, capabilities, and services that the organization depends on are understood and communicated

Outcomes, capabilities, and services that the organization depends on are understood and communicated

Artefacts an auditor will ask for
  • Dependency map covering people, process, technology, suppliers
  • Outcome statements for each critical service
  • Resilience scenarios spanning interdependencies
  • Supplier dependency overlay on the service map
  • Annual dependency walkthrough records
Where this commonly fails
  • Dependency map limited to internal systems
  • Fourth party dependencies invisible
  • Outcomes stated for IT, not for the customer
  • Scenarios assume single point failures only
NIST-CSF-GV.PO-01
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

Artefacts an auditor will ask for
  • Cybersecurity risk management policy approved by leadership
  • Policy linkage matrix to standards and procedures
  • Risk based rationale documented for policy positions
  • Policy distribution and acknowledgement records
  • Policy exceptions register with approver identities
Where this commonly fails
  • Policy boilerplate not tailored to context
  • Standards drift from the parent policy
  • Acknowledgement coverage gaps for contractors
  • Exceptions granted with no expiry
NIST-CSF-GV.PO-02
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission

Artefacts an auditor will ask for
  • Policy review schedule with last and next review dates
  • Change log per policy with rationale and approver
  • Communication plan for policy updates
  • Enforcement evidence (audit findings, disciplinary records redacted)
  • Annual policy effectiveness review report
Where this commonly fails
  • Reviews slip beyond declared cadence
  • Updates not communicated to all populations
  • No metrics on enforcement outcomes
  • Effectiveness review treated as a tick box
NIST-CSF-GV.RM-01
Risk management objectives are established and agreed to by organizational stakeholders

Risk management objectives are established and agreed to by organizational stakeholders

Artefacts an auditor will ask for
  • Risk management charter with objectives and KPIs
  • Board approved risk objectives statement
  • Mapping of cyber objectives to enterprise objectives
  • Risk committee terms of reference
  • Annual objectives attestation
Where this commonly fails
  • Objectives generic and not measurable
  • No mapping to enterprise strategy
  • Charter not refreshed after restructures
  • Committee minutes lack decision records
NIST-CSF-GV.RM-02
Risk appetite and risk tolerance statements are established, communicated, and maintained

Risk appetite and risk tolerance statements are established, communicated, and maintained

Artefacts an auditor will ask for
  • Risk appetite statement signed by the board
  • Tolerance thresholds expressed quantitatively where feasible
  • Cascade of appetite into operational limits
  • Breach handling procedure for appetite excursions
  • Annual appetite review minutes
Where this commonly fails
  • Appetite stated qualitatively only
  • Operational limits not aligned to appetite
  • Breaches not surfaced to the board
  • No appetite for emerging threats
NIST-CSF-GV.RM-03
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

Artefacts an auditor will ask for
  • ERM framework with cyber risk integrated
  • Risk taxonomy shared across enterprise and cyber registers
  • Cross register reconciliation reports
  • Joint risk committee meeting records
  • Combined risk reporting pack for the board
Where this commonly fails
  • Cyber register siloed from enterprise register
  • Different scoring scales prevent comparison
  • Reconciliation manual and infrequent
  • Combined reporting summarized to invisibility
NIST-CSF-GV.RM-04
Strategic direction that describes appropriate risk response options is established and communicated

Strategic direction that describes appropriate risk response options is established and communicated

Artefacts an auditor will ask for
  • Cybersecurity strategy document with three to five year horizon
  • Roadmap aligned to strategic pillars and resourcing
  • Strategy approval record from executive leadership
  • Annual strategy review and refresh records
  • Strategy traceability matrix to investments
Where this commonly fails
  • Strategy reads as a backlog rather than direction
  • Roadmap unfunded beyond year one
  • No traceability from strategy to capability outcomes
  • Strategy refreshed only when leadership changes
NIST-CSF-GV.RM-05
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

Artefacts an auditor will ask for
  • Communication plan for cyber risk across stakeholder tiers
  • Reporting templates tailored by audience
  • Escalation pathway from analyst to board
  • Feedback loop records on report usefulness
  • Sample board report with decision asks
Where this commonly fails
  • Same report sent to every audience
  • Escalation only triggered by incidents
  • Feedback never incorporated
  • Reports lack a decision request
NIST-CSF-GV.RM-06
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

Artefacts an auditor will ask for
  • Documented risk calculation methodology
  • Calibration sessions for likelihood and impact estimates
  • Worked examples applied to recent risks
  • Methodology peer review notes
  • Tooling configuration enforcing the method
Where this commonly fails
  • Method exists on paper, not in tooling
  • Estimators not calibrated
  • Methodology bypassed for time pressure risks
  • No peer review of high impact assessments
NIST-CSF-GV.RM-07
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions

Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions

Artefacts an auditor will ask for
  • Risk assessment outputs tagged for improvement opportunities
  • Improvement backlog seeded from assessments
  • Closure tracking from finding to remediation
  • Trend analysis on recurring assessment themes
  • Annual improvement review by the risk committee
Where this commonly fails
  • Findings closed without verifying remediation
  • No trending across assessment cycles
  • Improvements stuck in backlog beyond SLA
  • Committee not informed of recurrence
NIST-CSF-GV.RR-01
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving

Artefacts an auditor will ask for
  • Board cyber accountability charter
  • Executive cyber scorecard with named owners
  • Leadership performance objectives tied to cyber outcomes
  • Minutes showing leadership challenge of cyber decisions
  • Public statement of leadership accountability
Where this commonly fails
  • Accountability assigned to CISO only
  • Board lacks cyber literacy training
  • Performance objectives lack measurable cyber criteria
  • No leadership challenge captured in minutes
NIST-CSF-GV.RR-02
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

Artefacts an auditor will ask for
  • RACI matrix across cyber roles
  • Job descriptions with cyber duties for non security roles
  • Delegations of authority for security decisions
  • Annual role review minutes
  • Onboarding pack confirming role responsibilities
Where this commonly fails
  • RACI exists but not enforced
  • Cyber duties missing from line manager roles
  • Delegations stale after reorganizations
  • Onboarding pack out of date
NIST-CSF-GV.RR-03
Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

Artefacts an auditor will ask for
  • Cyber budget with multi year planning
  • Headcount plan tied to capability roadmap
  • Tool spend reconciliation against outcomes
  • Investment business cases approved by finance
  • Resource constraint risks recorded in the register
Where this commonly fails
  • Budget tracked but capability outcomes unclear
  • Headcount frozen while scope expands
  • Tool spend not retired when consolidating
  • Constraint risks not visible to leadership
NIST-CSF-GV.RR-04
Cybersecurity is included in human resources practices

Cybersecurity is included in human resources practices. Control from NIST Cybersecurity Framework 2.0 framework, domain: GV - Govern.

Artefacts an auditor will ask for
  • HR policies covering hiring, transfer, and termination security
  • Background screening standards by role sensitivity
  • Disciplinary procedure for security violations
  • Joiner mover leaver workflow with security gates
  • HR audit findings on security integration
Where this commonly fails
  • Background screening not refreshed for role changes
  • Leaver process delayed beyond same day for cloud assets
  • Disciplinary outcomes not measured
  • Contractor lifecycle ignored
NIST-CSF-GV.SC-01
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

Artefacts an auditor will ask for
  • Third party risk management program charter
  • Supplier risk policy with tiering criteria
  • Program governance committee minutes
  • Annual TPRM maturity assessment
  • Tooling inventory supporting TPRM workflow
Where this commonly fails
  • Program exists for direct suppliers only
  • Tiering criteria not enforced consistently
  • Maturity self assessed without independent challenge
  • Tooling fragmented across business units
NIST-CSF-GV.SC-02
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally

Artefacts an auditor will ask for
  • Supplier security roles and responsibilities matrix
  • Vendor management organization chart with cyber liaison
  • Internal owners assigned per critical supplier
  • Joint operating model documentation
  • Annual review of supplier accountability
Where this commonly fails
  • No internal owner for critical suppliers
  • Liaison role unfilled during turnover
  • Joint operating model exists only for top tier
  • Annual review not performed
NIST-CSF-GV.SC-03
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

Artefacts an auditor will ask for
  • Supply chain risks recorded in the enterprise register
  • Combined risk reporting incorporating supplier risk
  • Reconciliation between TPRM and enterprise risk teams
  • Joint scenario planning exercises
  • Board reporting on supply chain exposure
Where this commonly fails
  • TPRM operates as a separate silo
  • Risk taxonomy differs from enterprise
  • Board only sees supplier risk after incidents
  • Scenarios omit cascading vendor failures
NIST-CSF-GV.SC-04
Suppliers are known and prioritized by criticality

Suppliers are known and prioritized by criticality. Control from NIST Cybersecurity Framework 2.0 framework, domain: GV - Govern.

Artefacts an auditor will ask for
  • Supplier inventory with criticality scoring
  • Crown jewel mapping to supplier dependencies
  • Concentration risk analysis by service
  • Quarterly tiering refresh records
  • Supplier exit plan summary for top tier
Where this commonly fails
  • Inventory limited to procurement records
  • Shadow IT vendors not captured
  • Concentration risk underestimated
  • Exit plans absent for critical vendors
NIST-CSF-GV.SC-05
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

Artefacts an auditor will ask for
  • Standard supplier security requirements catalog
  • Contract clause library with cyber obligations
  • Requirements tailoring guide by supplier tier
  • Negotiation log capturing accepted deviations
  • Contract management workflow with security review gate
Where this commonly fails
  • Requirements not enforced in long term contracts
  • Deviations approved without risk acceptance
  • Clauses lack audit and notification provisions
  • Renewals not re assessed against current standard
NIST-CSF-GV.SC-06
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

Artefacts an auditor will ask for
  • Due diligence questionnaire with risk based depth
  • Pre contract security assessment reports
  • Independent attestations collected during diligence
  • Risk acceptance decisions tied to diligence outputs
  • Onboarding checklist closing residual gaps
Where this commonly fails
  • Diligence skipped for urgent procurement
  • Attestations accepted without scope verification
  • Risk acceptance not signed at appropriate level
  • Onboarding gaps never closed
NIST-CSF-GV.SC-07
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship

Artefacts an auditor will ask for
  • Continuous monitoring evidence for critical suppliers
  • Periodic reassessment schedule and completion records
  • Threat intelligence on supplier ecosystem
  • Performance review minutes with security topics
  • Findings remediation tracker per supplier
Where this commonly fails
  • Continuous monitoring only via marketing dashboards
  • Reassessments slip beyond cycle
  • Findings never closed
  • Performance reviews skip security topics
NIST-CSF-GV.SC-08
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

Artefacts an auditor will ask for
  • Joint incident response playbooks with key suppliers
  • Contact directory tested through tabletop exercises
  • Notification clauses in contracts with timelines
  • Joint tabletop exercise after action reports
  • Lessons learned shared with procurement and legal
Where this commonly fails
  • No supplier participation in tabletops
  • Notification clauses lack timelines
  • Contacts stale at the supplier
  • Lessons learned not flowing back to contracts
NIST-CSF-GV.SC-09
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

Artefacts an auditor will ask for
  • Secure development and operations standards extended to suppliers
  • Software bill of materials policy and evidence
  • Code provenance verification records
  • Build pipeline integrity attestations
  • Sourcing controls for hardware components
Where this commonly fails
  • SBOM collection inconsistent
  • Provenance verification absent for open source
  • Hardware sourcing not vetted for tamper risk
  • Pipeline integrity assumed rather than tested
NIST-CSF-GV.SC-10
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

Artefacts an auditor will ask for
  • Supplier offboarding checklist with data return and destruction
  • Acquisition integration runbook with cyber gates
  • Termination notification workflow
  • Asset return tracking for departing suppliers
  • Post acquisition cyber assessment reports
Where this commonly fails
  • Offboarding focuses on logical access only
  • Data return certificates not collected
  • Acquired entities granted full access immediately
  • Post acquisition findings never closed

Govern

NIST-CSF-GV.OV-01
Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction

Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction

Artefacts an auditor will ask for
  • Strategy review meeting cadence and minutes
  • KPI/KRI dashboard tied to strategic objectives
  • Adjustments documented after strategy reviews
  • Annual cyber strategy refresh record
  • Action items from prior reviews and their closure status
  • Comparison of strategy targets vs. actual outcomes
Where this commonly fails
  • Strategy reviews are perfunctory with no resulting adjustments
  • KPIs defined but not reviewed at the strategic level
  • Action items raised in reviews never tracked to closure
  • Strategy updates not linked to outcome data
  • Review cadence absent or longer than annual
NIST-CSF-GV.OV-02
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

Artefacts an auditor will ask for
  • Coverage assessment comparing strategy against requirements and risks
  • Gap analysis output with remediation plans
  • Strategy adjustment records and approval
  • Mapping of risk register categories to strategy elements
  • Internal audit reports addressing strategy coverage
  • Executive briefings on coverage status
Where this commonly fails
  • Strategy never explicitly mapped against the risk register
  • Emerging risks (AI, supply chain) not covered by current strategy
  • Gap analyses produced but not acted upon
  • Coverage assessments rely only on internal viewpoints
  • Adjustments approved verbally with no audit trail
NIST-CSF-GV.OV-03
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

Artefacts an auditor will ask for
  • Performance metrics catalog with targets and actuals
  • Internal audit reports on cyber program performance
  • Continuous improvement backlog with prioritized items
  • Maturity assessment results (e.g., CSF tier ratings)
  • Lessons learned from incidents driving performance adjustments
  • Executive scorecard tracking program performance over time
Where this commonly fails
  • Metrics measure activity (patches applied) rather than outcomes (risk reduced)
  • Internal audit cycles too infrequent to influence direction
  • Improvement backlog grows but nothing closes
  • Maturity assessments performed but never compared year-over-year
  • No formal channel from lessons learned to strategy

ID - Identify

NIST-CSF-ID.AM-01
Inventories of hardware managed by the organization are maintained

Inventories of hardware managed by the organization are maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Artefacts an auditor will ask for
  • Hardware inventory with last seen and owner fields
  • Automated discovery feeds reconciled against CMDB
  • Onboarding and decommissioning workflows
  • Asset tagging policy and audit findings
  • Quarterly inventory completeness report
Where this commonly fails
  • OT and IoT assets missing from inventory
  • Owner field defaults to a generic team
  • Discovery overlaps cause duplicates
  • Decommission status untracked
NIST-CSF-ID.AM-02
Inventories of software, services, and systems managed by the organization are maintained

Inventories of software, services, and systems managed by the organization are maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Artefacts an auditor will ask for
  • Software inventory with licensing and version data
  • SaaS application register with owner and data class
  • Allowlist and denylist with review cadence
  • Discovery feed from endpoint and network tools
  • Quarterly software lifecycle review
Where this commonly fails
  • Shadow SaaS not captured
  • Allowlist drift over time
  • Versioning unreliable for plugins
  • Lifecycle review not performed
NIST-CSF-ID.AM-03
Representations of the organization's authorized network communication and internal and external network data flows are maintained

Representations of the organization's authorized network communication and internal and external network data flows are maintained

Artefacts an auditor will ask for
  • Network diagrams with current data flow annotations
  • Authorized communication matrix with allowed protocols
  • Data flow diagrams covering regulated data
  • Firewall rule base traceable to authorized flows
  • Annual flow validation walkthrough records
Where this commonly fails
  • Diagrams outdated after migrations
  • Cloud and partner flows missing
  • Firewall rules outlive their justification
  • No flow validation performed
NIST-CSF-ID.AM-04
Inventories of services provided by suppliers are maintained

Inventories of services provided by suppliers are maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Artefacts an auditor will ask for
  • Inventory of services delivered by suppliers
  • Mapping of supplier services to business services
  • Service criticality scores
  • Renewal and end of life tracking
  • Service ownership matrix
Where this commonly fails
  • Inventory derived from procurement records only
  • Mapping to business services missing
  • End of life dates not tracked
  • Ownership unclear for shared services
NIST-CSF-ID.AM-05
Assets are prioritized based on classification, criticality, resources, and impact on the mission

Assets are prioritized based on classification, criticality, resources, and impact on the mission

Artefacts an auditor will ask for
  • Asset prioritization scoring model
  • Criticality ratings stored in CMDB
  • Resource allocation justification per tier
  • Impact based exception register
  • Annual prioritization review minutes
Where this commonly fails
  • Scoring inconsistent across teams
  • Critical assets identified informally
  • Resource allocation not aligned to tier
  • Annual review skipped
NIST-CSF-ID.AM-07
Inventories of data and corresponding metadata for designated data types are maintained

Inventories of data and corresponding metadata for designated data types are maintained

Artefacts an auditor will ask for
  • Data inventory with classification and location
  • Metadata tagging policy enforced in storage
  • Records of processing activities updated routinely
  • Discovery scans for unstructured data
  • Annual data inventory attestation
Where this commonly fails
  • Unstructured stores omitted from inventory
  • Tagging inconsistent across regions
  • ROPA outdated
  • Discovery scans limited to sanctioned platforms
NIST-CSF-ID.AM-08
Systems, hardware, software, services, and data are managed throughout their life cycles

Systems, hardware, software, services, and data are managed throughout their life cycles

Artefacts an auditor will ask for
  • Asset lifecycle policy from acquisition to disposal
  • Stage gates for build, run, retire
  • Secure disposal records with chain of custody
  • Lifecycle dashboard with stage age metrics
  • Lifecycle audit findings and remediation
Where this commonly fails
  • Retired assets remain reachable
  • Disposal certificates incomplete
  • Stage gates skipped for fast track projects
  • Dashboard not used by operations
NIST-CSF-ID.IM-01
Improvements are identified from evaluations

Improvements are identified from evaluations

Artefacts an auditor will ask for
  • Penetration test report library with severity and status
  • Red team exercise after action reviews
  • Tabletop output catalogued with improvement actions
  • Improvement backlog with owners and due dates
  • Trend analysis across testing programs
Where this commonly fails
  • Improvements actioned only after the next test
  • Tabletop outputs lost in chat logs
  • Trend analysis not performed
  • Tests scoped to easy wins
NIST-CSF-ID.IM-02
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

Artefacts an auditor will ask for
  • Risk and control assessment findings tracker
  • Internal audit cyber findings with management responses
  • External assessment reports with action plans
  • Closure verification evidence per finding
  • Trend report across assessment cycles
Where this commonly fails
  • Closure declared without retest
  • Findings aggregated and forgotten
  • Management responses lack measurable actions
  • Trends not surfaced to leadership
NIST-CSF-ID.IM-03
Improvements are identified from execution of operational processes, procedures, and activities

Improvements are identified from execution of operational processes, procedures, and activities

Artefacts an auditor will ask for
  • Operations metrics dashboard with anomaly indicators
  • Incident lessons learned register
  • Near miss reporting workflow
  • Process improvement initiatives tied to operations data
  • Quarterly improvement retro records
Where this commonly fails
  • Lessons learned never close out
  • Near misses not reported because no impact occurred
  • Improvement initiatives lose momentum
  • Retros skipped during busy periods
NIST-CSF-ID.IM-04
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

Artefacts an auditor will ask for
  • Incident response plan with version history
  • Business continuity and disaster recovery plans linked to IR
  • Communications plan for incidents
  • Plan approval records from leadership
  • Annual plan test results
Where this commonly fails
  • Plans inconsistent across business units
  • IR and BC plans not aligned
  • Approval expired
  • Tests narrow in scope
NIST-CSF-ID.RA-01
Vulnerabilities in assets are identified, validated, and recorded

Vulnerabilities in assets are identified, validated, and recorded. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Artefacts an auditor will ask for
  • Vulnerability scanning coverage report
  • Vulnerability triage workflow with severity SLAs
  • Validated findings with proof and remediation status
  • Asset coverage exceptions register
  • Trend analysis on vulnerability backlog
Where this commonly fails
  • Coverage gaps for cloud and container workloads
  • SLAs missed for high severity items
  • Findings closed without re scan
  • Trend backlog growing over time
NIST-CSF-ID.RA-02
Cyber threat intelligence is received from information sharing forums and sources

Cyber threat intelligence is received from information sharing forums and sources

Artefacts an auditor will ask for
  • Threat intelligence subscriptions and ISAC memberships
  • Intelligence ingestion workflow with curation
  • Intelligence consumption metrics by team
  • Strategic threat briefings to leadership
  • Annual intel program effectiveness review
Where this commonly fails
  • Information sharing one way only
  • Curation lacks analyst time
  • Briefings recycled without refresh
  • Effectiveness review skipped
NIST-CSF-ID.RA-03
Internal and external threats to the organization are identified and recorded

Internal and external threats to the organization are identified and recorded

Artefacts an auditor will ask for
  • Threat catalog with internal and external sources
  • Insider threat assessment findings
  • Geopolitical threat watch reports
  • Threat modeling outputs for critical systems
  • Periodic threat refresh meeting minutes
Where this commonly fails
  • Insider threat scope limited to malicious cases
  • Geopolitical analysis absent
  • Threat modeling done once at design only
  • Refresh cadence inconsistent
NIST-CSF-ID.RA-04
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded

Artefacts an auditor will ask for
  • Risk scenario library with impact and likelihood scores
  • Scenario simulation outputs and decisions
  • Quantitative loss exposure analyses where applicable
  • Cross functional risk workshop notes
  • Validation of scenarios by independent reviewers
Where this commonly fails
  • Scenarios limited to known historical events
  • Likelihoods estimated without calibration
  • Workshops dominated by single perspective
  • Validation skipped
NIST-CSF-ID.RA-05
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization

Artefacts an auditor will ask for
  • Inherent risk register with scoring rationale
  • Risk heat map and prioritization output
  • Linkage from inherent to residual risk
  • Methodology document shared across teams
  • Annual register attestation
Where this commonly fails
  • Inherent risk inflated to justify spending
  • Heat map static between reviews
  • Residual calculation opaque
  • Methodology applied inconsistently
NIST-CSF-ID.RA-06
Risk responses are chosen, prioritized, planned, tracked, and communicated

Risk responses are chosen, prioritized, planned, tracked, and communicated. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Artefacts an auditor will ask for
  • Risk treatment plan per risk
  • Approval records for risk acceptance
  • Tracking dashboard for treatment progress
  • Communication to stakeholders on chosen responses
  • Periodic re evaluation of treatment effectiveness
Where this commonly fails
  • Treatments default to acceptance
  • Acceptance approvals not at appropriate level
  • Dashboard tracks tasks, not outcomes
  • Re evaluation skipped
NIST-CSF-ID.RA-07
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

Changes and exceptions are managed, assessed for risk impact, recorded, and tracked. Control from NIST Cybersecurity Framework 2.0 framework, domain: ID - Identify.

Artefacts an auditor will ask for
  • Change management workflow with risk assessment gate
  • Exception register with risk impact analysis
  • Emergency change reviews and post change validation
  • Risk impact decisions logged with approver identity
  • Audit findings on change risk integration
Where this commonly fails
  • Emergency changes bypass risk review
  • Exceptions accumulate without sunset
  • Validation absent for high risk changes
  • Approver identity captured but not verified
NIST-CSF-ID.RA-08
Processes for receiving, analyzing, and responding to vulnerability disclosures are established

Processes for receiving, analyzing, and responding to vulnerability disclosures are established

Artefacts an auditor will ask for
  • Control effectiveness testing reports
  • Key risk indicator trending with thresholds
  • Risk response effectiveness review minutes
  • Independent validation of high risk responses
  • Closure tracking when responses fail
Where this commonly fails
  • Control testing infrequent
  • KRIs flat with no investigation
  • Effectiveness reviews narrative only
  • Independent validation absent
NIST-CSF-ID.RA-09
The authenticity and integrity of hardware and software are assessed prior to acquisition and use

The authenticity and integrity of hardware and software are assessed prior to acquisition and use

Artefacts an auditor will ask for
  • Quality assurance procedure for risk assessments
  • Peer review records on assessment outputs
  • Source citation requirements for risk inputs
  • Audit trail of changes to risk records
  • Independent validation of high impact assessments
Where this commonly fails
  • Peer review absent for time pressured assessments
  • Sources not cited for risk inputs
  • Audit trail incomplete
  • Validation overridden by leadership
NIST-CSF-ID.RA-10
Critical suppliers are assessed prior to acquisition

Critical suppliers are assessed prior to acquisition

Artefacts an auditor will ask for
  • Critical supplier risk assessment reports
  • Supplier risk register with scoring
  • Continuous monitoring summaries for top tier suppliers
  • Risk acceptance decisions for supplier residual risk
  • Annual critical supplier risk review
Where this commonly fails
  • Critical suppliers defined by spend, not risk
  • Assessments rely on supplier self attestation
  • Continuous monitoring superficial
  • Acceptance decisions not refreshed

PR - Protect

NIST-CSF-PR.AA-01
Identities and credentials for authorized users, services, and hardware are managed by the organization

Identities and credentials for authorized users, services, and hardware are managed by the organization

Artefacts an auditor will ask for
  • Identity management platform configuration baseline
  • Joiner mover leaver workflow with timing SLAs
  • Service account inventory with owners
  • Hardware credential inventory and reconciliation
  • Quarterly identity hygiene reports
Where this commonly fails
  • Service accounts owned by individuals who have left
  • Hardware credentials manual and stale
  • JML SLAs missed for non production systems
  • Inventory misses contractor identities
NIST-CSF-PR.AA-02
Identities are proofed and bound to credentials based on the context of interactions

Identities are proofed and bound to credentials based on the context of interactions. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Identity proofing policy aligned to risk tiers
  • Issuance and binding records for credentials
  • Re proofing triggers for elevated access
  • Identity verification audit logs
  • Exception register for proofing variances
Where this commonly fails
  • Proofing relies on email only
  • Binding records incomplete
  • Re proofing never triggered
  • Exceptions never reviewed
NIST-CSF-PR.AA-03
Users, services, and hardware are authenticated

Users, services, and hardware are authenticated. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Multi factor authentication coverage report
  • Phishing resistant authentication rollout plan
  • Authentication failure analytics
  • Workload identity authentication policy
  • Periodic authentication strength review
Where this commonly fails
  • MFA fatigue not addressed
  • Legacy protocols still enabled
  • Workload identities use static secrets
  • Failure analytics not investigated
NIST-CSF-PR.AA-04
Identity assertions are protected, conveyed, and verified

Identity assertions are protected, conveyed, and verified. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Token and assertion configuration standards
  • Federation trust relationships inventory
  • Token signing key management procedures
  • Assertion validation telemetry
  • Federation incident response plan
Where this commonly fails
  • Token lifetimes too long for sensitive apps
  • Federation trust list not reviewed
  • Signing keys rotated only on incident
  • Assertion validation telemetry not monitored
NIST-CSF-PR.AA-05
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Artefacts an auditor will ask for
  • Access policy framework with role definitions
  • Privileged access management deployment evidence
  • Periodic access reviews with sign off
  • Segregation of duties matrix
  • Just in time access workflow records
Where this commonly fails
  • Standing privileges still common
  • Access reviews rubber stamped
  • SoD conflicts unresolved
  • JIT scoped to operations only
NIST-CSF-PR.AA-06
Physical access to assets is managed, monitored, and enforced commensurate with risk

Physical access to assets is managed, monitored, and enforced commensurate with risk

Artefacts an auditor will ask for
  • Physical access control system inventory
  • Badge issuance and revocation records
  • Visitor management policy and logs
  • Anti tailgating measures with effectiveness review
  • Sensitive area access audit reports
Where this commonly fails
  • Badge revocation lags terminations
  • Visitor escorts not enforced
  • Tailgating measures not tested
  • Audits skipped for low traffic areas
NIST-CSF-PR.AT-01
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

Artefacts an auditor will ask for
  • Security awareness program curriculum
  • Completion records by population
  • Phishing simulation results and trends
  • Awareness campaign artefacts (posters, emails)
  • Annual program effectiveness review
Where this commonly fails
  • Annual training only with no reinforcement
  • Phishing simulations easy and not realistic
  • Contractors excluded from awareness
  • Effectiveness measured by completion rate only
NIST-CSF-PR.AT-02
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

Artefacts an auditor will ask for
  • Role based training matrix for security sensitive roles
  • Specialized course completion records
  • Skills assessments tied to role requirements
  • Continuous learning budget records
  • Certification tracking for security staff
Where this commonly fails
  • Role based training delayed for new hires
  • Skills assessments absent
  • Certification lapses untracked
  • Specialized training reserved for security team only
NIST-CSF-PR.DS-01
The confidentiality, integrity, and availability of data-at-rest are protected

The confidentiality, integrity, and availability of data-at-rest are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Data at rest encryption inventory by store type
  • Key management standards and rotation evidence
  • Storage configuration baselines with attestation
  • Sensitive data discovery findings remediated
  • Audit findings on data at rest protection
Where this commonly fails
  • Encryption inventory misses backup media
  • Key rotation manual and missed
  • Baselines drift in cloud projects
  • Sensitive data outside sanctioned stores
NIST-CSF-PR.DS-02
The confidentiality, integrity, and availability of data-in-transit are protected

The confidentiality, integrity, and availability of data-in-transit are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • TLS configuration standards and scan results
  • VPN and zero trust network access policy
  • Email transport encryption configuration
  • API security policy with mutual authentication
  • Network traffic encryption audit
Where this commonly fails
  • Weak ciphers still permitted for legacy clients
  • Internal traffic unencrypted
  • API mutual authentication absent
  • Email encryption opportunistic only
NIST-CSF-PR.DS-10
The confidentiality, integrity, and availability of data-in-use are protected

The confidentiality, integrity, and availability of data-in-use are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Memory protection technology deployment evidence
  • Confidential computing usage for regulated data
  • Application level protections for data in use
  • Tokenization and masking standards
  • Audit on data in use exposure during processing
Where this commonly fails
  • Data in use unprotected during analytics
  • Confidential computing pilot only
  • Masking absent in non production environments
  • Memory protection disabled for compatibility
NIST-CSF-PR.DS-11
Backups of data are created, protected, maintained, and tested

Backups of data are created, protected, maintained, and tested. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Backup policy with frequency and retention
  • Backup integrity test reports
  • Immutable backup configuration evidence
  • Restoration test records with success criteria
  • Backup access control and audit logs
Where this commonly fails
  • Restoration tests narrow in scope
  • Immutability not configured on all critical systems
  • Backups exposed via shared admin credentials
  • Retention not aligned to recovery objectives
NIST-CSF-PR.IR-01
Networks and environments are protected from unauthorized logical access and usage

Networks and environments are protected from unauthorized logical access and usage

Artefacts an auditor will ask for
  • Network segmentation design with zones and trust levels
  • Firewall and access control list governance
  • Zero trust network access deployment evidence
  • External attack surface management reports
  • Segmentation effectiveness testing results
Where this commonly fails
  • Segmentation flat across business units
  • Firewall rules grow without rationalization
  • Attack surface assets unknown
  • Effectiveness testing never performed
NIST-CSF-PR.IR-02
The organization's technology assets are protected from environmental threats

The organization's technology assets are protected from environmental threats. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Environmental controls inventory (HVAC, power, fire)
  • Site risk assessments with mitigation status
  • Cloud region selection rationale for resilience
  • Building maintenance and inspection records
  • Environmental incident response procedures
Where this commonly fails
  • Single region deployments for critical services
  • Site risk assessments stale
  • Building inspections lapsed
  • Environmental incidents not exercised
NIST-CSF-PR.IR-03
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Resilience architecture patterns for critical services
  • Failover and failback tested with evidence
  • Capacity planning and load testing reports
  • Chaos engineering exercise outcomes
  • Resilience targets traced to business outcomes
Where this commonly fails
  • Failback never tested
  • Resilience patterns inconsistent across teams
  • Chaos engineering absent in production
  • Targets not refreshed against business change
NIST-CSF-PR.IR-04
Adequate resource capacity to ensure availability is maintained

Adequate resource capacity to ensure availability is maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Capacity forecasts with growth assumptions
  • Performance monitoring telemetry
  • Scaling automation configuration evidence
  • Reserved capacity and burst contract records
  • Availability SLO and error budget reports
Where this commonly fails
  • Forecasts not refreshed with demand spikes
  • Scaling automation untested under load
  • Reserved capacity contracts expired
  • SLOs lack error budget enforcement
NIST-CSF-PR.PS-01
Configuration management practices are established and applied

Configuration management practices are established and applied. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Configuration management standards by platform
  • Hardening baselines and compliance reports
  • Configuration drift monitoring telemetry
  • Approved change management records
  • Configuration audit findings and remediation
Where this commonly fails
  • Baselines absent for cloud native services
  • Drift monitoring noisy and ignored
  • Hardening exceptions accumulate
  • Audit findings linger past SLA
NIST-CSF-PR.PS-02
Software is maintained, replaced, and removed commensurate with risk

Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Software lifecycle policy with end of support tracking
  • Patch management cadence and exception register
  • End of life replacement plan
  • Software risk assessments for unsupported tools
  • Software retirement records
Where this commonly fails
  • EOL software in production beyond plan
  • Patch SLAs missed for embedded systems
  • Replacement plans unfunded
  • Retirement records incomplete
NIST-CSF-PR.PS-03
Hardware is maintained, replaced, and removed commensurate with risk

Hardware is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Hardware lifecycle policy
  • Firmware patch management workflow
  • Asset refresh schedule
  • End of life decommissioning records
  • Hardware risk register
Where this commonly fails
  • Firmware patching neglected
  • Refresh schedule slipping
  • Decommissioning ad hoc
  • Risk register lacks hardware entries
NIST-CSF-PR.PS-04
Log records are generated and made available for continuous monitoring

Log records are generated and made available for continuous monitoring. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Artefacts an auditor will ask for
  • Logging policy by data class and system tier
  • Centralized log collection architecture
  • Log retention configuration evidence
  • Log integrity protections and audit findings
  • Periodic logging coverage review
Where this commonly fails
  • Critical systems missing from log feed
  • Retention shorter than incident windows
  • Log integrity not validated
  • Coverage review skipped
NIST-CSF-PR.PS-05
Installation and execution of unauthorized software are prevented

Installation and execution of unauthorized software are prevented

Artefacts an auditor will ask for
  • Application allowlist policy and tooling configuration
  • Endpoint protection deployment reports
  • Software install request workflow
  • Unauthorized software detection alerts
  • Periodic review of installed software baselines
Where this commonly fails
  • Allowlist exceptions overgrown
  • Detection alerts only for sanctioned populations
  • Install workflow bypassed by admins
  • Review of installed software not performed
NIST-CSF-PR.PS-06
Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

Artefacts an auditor will ask for
  • Secure SDLC standard with control gates
  • Threat modeling outputs per project
  • Static and dynamic analysis pipeline configuration
  • Software composition analysis findings
  • Pre release security sign off records
Where this commonly fails
  • Threat modeling skipped for fast track projects
  • Pipeline analysis breaks but does not block
  • Composition analysis findings unprioritized
  • Sign off absent for emergency releases

RC - Recover

NIST-CSF-RC.CO-03
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

Artefacts an auditor will ask for
  • Stakeholder communication plan for recovery
  • Status update templates with cadence
  • Distribution evidence for recovery updates
  • Stakeholder feedback collection records
  • Lessons learned on communication effectiveness
Where this commonly fails
  • Updates technical, not business focused
  • Cadence drops during long recoveries
  • Distribution lists outdated
  • Feedback not collected
NIST-CSF-RC.CO-04
Public updates on incident recovery are shared using approved methods and messaging

Public updates on incident recovery are shared using approved methods and messaging

Artefacts an auditor will ask for
  • Public communications policy with approval workflow
  • Approved spokesperson list and training records
  • Holding statement templates for recovery
  • Crisis communications drill outcomes
  • Sample public updates issued during incidents
Where this commonly fails
  • Spokespeople untrained
  • Templates lack regulatory specifics
  • Drills omit recovery phase
  • Updates inconsistent across channels
NIST-CSF-RC.RP-01
The recovery portion of the incident response plan is executed once initiated from the incident response process

The recovery portion of the incident response plan is executed once initiated from the incident response process

Artefacts an auditor will ask for
  • Recovery plan with triggers and decision rights
  • Execution log of recovery activities
  • Recovery team roster with on call coverage
  • Plan invocation tests and outcomes
  • Post execution review records
Where this commonly fails
  • Triggers unclear in the plan
  • Execution log incomplete during incidents
  • Roster outdated
  • Tests omit the invocation step
NIST-CSF-RC.RP-02
Recovery actions are selected, scoped, prioritized, and performed

Recovery actions are selected, scoped, prioritized, and performed

Artefacts an auditor will ask for
  • Recovery prioritization criteria
  • Decision log capturing scope and sequencing
  • Recovery sequencing diagrams for critical services
  • Resource allocation records during recovery
  • Stakeholder sign off on prioritization
Where this commonly fails
  • Criteria not used under pressure
  • Sequencing diagrams outdated
  • Resource decisions ad hoc
  • Sign off skipped
NIST-CSF-RC.RP-03
The integrity of backups and other restoration assets is verified before using them for restoration

The integrity of backups and other restoration assets is verified before using them for restoration

Artefacts an auditor will ask for
  • Backup integrity testing standard
  • Pre restoration verification records
  • Cryptographic hash validation evidence
  • Tabletop exercise on compromised backup scenarios
  • Restoration test outcomes
Where this commonly fails
  • Integrity checks bypassed under time pressure
  • Hash validation absent for some media
  • Tabletop scenarios shallow
  • Test outcomes not retained
NIST-CSF-RC.RP-04
Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms

Artefacts an auditor will ask for
  • Recovery time objective tracking dashboard
  • Service restoration verification procedure
  • User acceptance evidence per restored service
  • Recovery deviation records and rationale
  • Post restoration monitoring reports
Where this commonly fails
  • RTO measured but not enforced
  • Verification absent for dependent services
  • User acceptance signed off generically
  • Post restoration monitoring brief
NIST-CSF-RC.RP-05
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

Artefacts an auditor will ask for
  • Integrity verification procedure for restored systems
  • File integrity comparison reports
  • Application transaction validation records
  • Identity and access verification post restore
  • Independent verification by an alternate team
Where this commonly fails
  • Verification limited to file checksums
  • Application level validation absent
  • Identity reconciliation skipped
  • Independent verification not performed
NIST-CSF-RC.RP-06
The end of incident recovery is declared based on criteria, and incident-related documentation is completed

The end of incident recovery is declared based on criteria, and incident-related documentation is completed

Artefacts an auditor will ask for
  • End of recovery criteria document
  • Sign off records from business owners
  • Recovery closure communications
  • Transition to steady state operations plan
  • Lessons learned scheduled and conducted
Where this commonly fails
  • End of recovery declared informally
  • Business owners not consulted
  • Transition plan absent
  • Lessons learned never scheduled

RS - Respond

NIST-CSF-RS.AN-03
Analysis is performed to establish what has taken place during an incident and the root cause of the incident

Analysis is performed to establish what has taken place during an incident and the root cause of the incident

Artefacts an auditor will ask for
  • Incident investigation procedure
  • Forensic analysis reports with timeline reconstruction
  • Tooling evidence list (memory captures, disk images, log exports)
  • Analyst peer review records
  • Quality assurance findings on investigation outputs
Where this commonly fails
  • Procedure assumes on premise scenarios only
  • Timelines rely on system clocks not synchronized
  • Memory captures absent for cloud workloads
  • Peer review skipped under time pressure
NIST-CSF-RS.AN-06
Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved

Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved

Artefacts an auditor will ask for
  • Investigation action log per incident
  • Tooling audit trail (queries run, evidence pulled)
  • Chain of custody records for evidence
  • Decision log for investigative pivots
  • QA review on action log completeness
Where this commonly fails
  • Actions captured in chat rather than the case system
  • Chain of custody incomplete
  • Decision rationale missing
  • QA review not conducted
NIST-CSF-RS.AN-07
Incident data and metadata are collected, and their integrity and provenance are preserved

Incident data and metadata are collected, and their integrity and provenance are preserved

Artefacts an auditor will ask for
  • Evidence collection standard with integrity controls
  • Hash validated evidence storage
  • Access controls and audit logs on evidence repository
  • Retention schedule for incident evidence
  • Independent integrity verification reports
Where this commonly fails
  • Evidence stored on shared drives
  • Hashes computed but not validated later
  • Access logs not reviewed
  • Retention undefined
NIST-CSF-RS.AN-08
An incident's magnitude is estimated and validated

An incident's magnitude is estimated and validated

Artefacts an auditor will ask for
  • Root cause analysis procedure
  • Five whys or similar method evidence
  • RCA report with contributing factors and lessons
  • Action plan from RCA with owners and due dates
  • Closure verification of RCA actions
Where this commonly fails
  • RCA reduced to a single root cause
  • Contributing factors omitted
  • Action plans without owners
  • Closure verification absent
NIST-CSF-RS.CO-02
Internal and external stakeholders are notified of incidents

Internal and external stakeholders are notified of incidents. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Artefacts an auditor will ask for
  • Incident notification policy and timing matrix
  • Internal stakeholder communication templates
  • Regulator notification templates with jurisdiction matrix
  • Customer notification records
  • Notification audit trail
Where this commonly fails
  • Notification timing tracked but missed
  • Templates generic across jurisdictions
  • Customer notification delayed by legal review
  • Audit trail incomplete
NIST-CSF-RS.CO-03
Information is shared with designated internal and external stakeholders

Information is shared with designated internal and external stakeholders. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Artefacts an auditor will ask for
  • Information sharing agreements with partners
  • Sharing playbook with content controls
  • Records of intelligence shared with ISAC and peers
  • Internal sharing logs across business units
  • Sharing effectiveness review records
Where this commonly fails
  • Sharing agreements signed but unused
  • Sharing one way (consume only)
  • Internal sharing fragmented across teams
  • Effectiveness reviewed only after incidents
NIST-CSF-RS.MA-01
The incident response plan is executed in coordination with relevant third parties once an incident is declared

The incident response plan is executed in coordination with relevant third parties once an incident is declared

Artefacts an auditor will ask for
  • Incident response plan with third party invocation
  • Retainer contract evidence for IR vendor
  • Joint exercise records with the IR vendor
  • Coordination procedure with law enforcement
  • Vendor activation log during real incidents
Where this commonly fails
  • Retainer in place but contact path untested
  • Coordination with law enforcement absent
  • Joint exercises infrequent
  • Activation log incomplete
NIST-CSF-RS.MA-02
Incident reports are triaged and validated

Incident reports are triaged and validated. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Artefacts an auditor will ask for
  • Incident intake workflow with validation steps
  • Triage decision criteria
  • Sample report validation evidence
  • Triage analyst quality reviews
  • Trend analysis of false positives
Where this commonly fails
  • Validation skipped under volume
  • Criteria inconsistent across shifts
  • Quality reviews not performed
  • False positives not analyzed for tuning
NIST-CSF-RS.MA-03
Incidents are categorized and prioritized

Incidents are categorized and prioritized. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Artefacts an auditor will ask for
  • Incident categorization taxonomy
  • Severity scoring rubric
  • Incident ticket evidence showing categories and severity
  • Periodic review of taxonomy completeness
  • Reporting metrics by category and severity
Where this commonly fails
  • Taxonomy stale relative to current threats
  • Severity downgraded informally
  • Tickets miss category assignment
  • Metrics not used for trend analysis
NIST-CSF-RS.MA-04
Incidents are escalated or elevated as needed

Incidents are escalated or elevated as needed. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Artefacts an auditor will ask for
  • Escalation procedure with named roles
  • Escalation tree tested through drills
  • Escalation decision logs
  • Executive notification protocols
  • After action reviews on escalation timing
Where this commonly fails
  • Escalation tree outdated
  • Drills omit night and weekend conditions
  • Decision logs incomplete
  • Reviews skip escalation analysis
NIST-CSF-RS.MA-05
The criteria for initiating incident recovery are applied

The criteria for initiating incident recovery are applied

Artefacts an auditor will ask for
  • Recovery initiation criteria documented
  • Decision log linking response to recovery handoff
  • Joint review by IR and recovery teams
  • Tabletop coverage of the response to recovery boundary
  • Closure of recovery initiation actions
Where this commonly fails
  • Recovery initiation criteria absent
  • Handoff informal and verbal
  • Joint reviews not held
  • Tabletops omit recovery handoff
NIST-CSF-RS.MI-01
Incidents are contained

Incidents are contained. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Artefacts an auditor will ask for
  • Containment playbook by incident type
  • Network isolation tooling deployment evidence
  • Account suspension workflow
  • Containment effectiveness review post incident
  • Approval records for containment actions with business impact
Where this commonly fails
  • Containment delayed pending approvals
  • Tooling exists but operators untrained
  • Effectiveness review absent
  • Approvals not captured
NIST-CSF-RS.MI-02
Incidents are eradicated

Incidents are eradicated. Control from NIST Cybersecurity Framework 2.0 framework, domain: RS - Respond.

Artefacts an auditor will ask for
  • Eradication procedure by attack technique
  • Malware removal verification records
  • Persistence removal evidence
  • Re imaging and rebuilding policy
  • Post eradication validation testing
Where this commonly fails
  • Eradication relies on antivirus signatures only
  • Persistence checks superficial
  • Re imaging avoided for time pressure
  • Validation testing not retained
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.