{
  "code": "NIST-CSF-2",
  "name": "NIST Cybersecurity Framework 2.0",
  "version": "2.0",
  "issuing_body": "National Institute of Standards and Technology",
  "description": "Framework for Improving Critical Infrastructure Cybersecurity",
  "regions": ["us", "global"],
  "industries": ["all"],
  "effective_date": "2024-02-26",
  "is_global": true,
  "requirements": [
    {
      "reference_code": "GV",
      "title": "GOVERN",
      "requirement_type": "mandatory",
      "category": "Govern",
      "description": "The organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.",
      "children": [
        { "reference_code": "GV.OC", "title": "Organizational Context", "description": "The circumstances surrounding the organization's cybersecurity risk management decisions are understood.", "requirement_type": "mandatory" },
        { "reference_code": "GV.RM", "title": "Risk Management Strategy", "description": "The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used.", "requirement_type": "mandatory" },
        { "reference_code": "GV.RR", "title": "Roles, Responsibilities, and Authorities", "description": "Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement.", "requirement_type": "mandatory" },
        { "reference_code": "GV.PO", "title": "Policy", "description": "Organizational cybersecurity policy is established, communicated, and enforced.", "requirement_type": "mandatory" },
        { "reference_code": "GV.OV", "title": "Oversight", "description": "Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust.", "requirement_type": "mandatory" },
        { "reference_code": "GV.SC", "title": "Cybersecurity Supply Chain Risk Management", "description": "Cyber supply chain risk management processes are identified, established, managed, monitored, and improved.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "ID",
      "title": "IDENTIFY",
      "requirement_type": "mandatory",
      "category": "Identify",
      "description": "The organization's current cybersecurity risks are understood.",
      "children": [
        { "reference_code": "ID.AM", "title": "Asset Management", "description": "Assets that enable the organization to achieve business purposes are identified and managed consistent with their relative importance.", "requirement_type": "mandatory" },
        { "reference_code": "ID.RA", "title": "Risk Assessment", "description": "The cybersecurity risk to the organization, assets, and individuals is identified and understood.", "requirement_type": "mandatory" },
        { "reference_code": "ID.IM", "title": "Improvement", "description": "Improvements to organizational cybersecurity risk management processes are identified.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "PR",
      "title": "PROTECT",
      "requirement_type": "mandatory",
      "category": "Protect",
      "description": "Safeguards to manage the organization's cybersecurity risks are used.",
      "children": [
        { "reference_code": "PR.AA", "title": "Identity Management, Authentication, and Access Control", "description": "Access to physical and logical assets is limited to authorized users, services, and hardware.", "requirement_type": "mandatory" },
        { "reference_code": "PR.AT", "title": "Awareness and Training", "description": "The organization's personnel are provided with cybersecurity awareness and training.", "requirement_type": "mandatory" },
        { "reference_code": "PR.DS", "title": "Data Security", "description": "Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability.", "requirement_type": "mandatory" },
        { "reference_code": "PR.PS", "title": "Platform Security", "description": "The hardware, software (including firmware and operating systems), and services of physical and virtual platforms are managed.", "requirement_type": "mandatory" },
        { "reference_code": "PR.IR", "title": "Technology Infrastructure Resilience", "description": "Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "DE",
      "title": "DETECT",
      "requirement_type": "mandatory",
      "category": "Detect",
      "description": "Possible cybersecurity attacks and compromises are found and analyzed.",
      "children": [
        { "reference_code": "DE.CM", "title": "Continuous Monitoring", "description": "Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events.", "requirement_type": "mandatory" },
        { "reference_code": "DE.AE", "title": "Adverse Event Analysis", "description": "Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "RS",
      "title": "RESPOND",
      "requirement_type": "mandatory",
      "category": "Respond",
      "description": "Actions regarding a detected cybersecurity incident are taken.",
      "children": [
        { "reference_code": "RS.MA", "title": "Incident Management", "description": "Responses to detected cybersecurity incidents are managed.", "requirement_type": "mandatory" },
        { "reference_code": "RS.AN", "title": "Incident Analysis", "description": "Investigations are conducted to ensure effective response and support forensics and recovery activities.", "requirement_type": "mandatory" },
        { "reference_code": "RS.CO", "title": "Incident Response Reporting and Communication", "description": "Response activities are coordinated with internal and external stakeholders.", "requirement_type": "mandatory" },
        { "reference_code": "RS.MI", "title": "Incident Mitigation", "description": "Activities are performed to prevent expansion of an event and mitigate its effects.", "requirement_type": "mandatory" }
      ]
    },
    {
      "reference_code": "RC",
      "title": "RECOVER",
      "requirement_type": "mandatory",
      "category": "Recover",
      "description": "Assets and operations affected by a cybersecurity incident are restored.",
      "children": [
        { "reference_code": "RC.RP", "title": "Incident Recovery Plan Execution", "description": "Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents.", "requirement_type": "mandatory" },
        { "reference_code": "RC.CO", "title": "Incident Recovery Communication", "description": "Restoration activities are coordinated with internal and external parties.", "requirement_type": "mandatory" }
      ]
    }
  ]
}
