Analyze/catalog/frameworks/nist-csf.json

{
  "key": "NIST CSF",
  "order": 6,
  "name": "NIST Cybersecurity Framework",
  "shortName": "NIST CSF v2.0",
  "version": "2.0",
  "publisher": "National Institute of Standards and Technology (NIST)",
  "type": "framework",
  "url": "https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final",
  "retrieved": "2026-09-24",
  "mapping": "jsolve",
  "note": "Mapping by JSolve B.V.: which tests evidence a control is JSolve's assessment, not the publisher's. A control with tests is fully assessed only when they check everything about it that Azure configuration can show. Controls that do not concern the Azure environment (people, physical security, organization-wide governance, end-user devices, software development) are not applicable; the other controls without a test need evidence outside configuration. Subcategory texts are NIST's (public domain).",
  "controls": {
    "GV.OC-01": {"title":"The organizational mission is understood and informs cybersecurity risk management","applicability":"notApplicable"},
    "GV.OC-02": {"title":"Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered","applicability":"notApplicable"},
    "GV.OC-03": {"title":"Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed","applicability":"notApplicable"},
    "GV.OC-04": {"title":"Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated","applicability":"notApplicable"},
    "GV.OC-05": {"title":"Outcomes, capabilities, and services that the organization depends on are understood and communicated","applicability":"notApplicable"},
    "GV.RM-01": {"title":"Risk management objectives are established and agreed to by organizational stakeholders","applicability":"notApplicable"},
    "GV.RM-02": {"title":"Risk appetite and risk tolerance statements are established, communicated, and maintained","applicability":"notApplicable"},
    "GV.RM-03": {"title":"Cybersecurity risk management activities and outcomes are included in enterprise risk management processes","applicability":"notApplicable"},
    "GV.RM-04": {"title":"Strategic direction that describes appropriate risk response options is established and communicated","applicability":"notApplicable"},
    "GV.RM-05": {"title":"Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties","applicability":"notApplicable"},
    "GV.RM-06": {"title":"A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated","applicability":"notApplicable"},
    "GV.RM-07": {"title":"Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions","applicability":"notApplicable"},
    "GV.RR-01": {"title":"Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving","applicability":"notApplicable"},
    "GV.RR-02": {"title":"Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced","applicability":"notApplicable"},
    "GV.RR-03": {"title":"Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies","applicability":"notApplicable"},
    "GV.RR-04": {"title":"Cybersecurity is included in human resources practices","applicability":"notApplicable"},
    "GV.PO-01": {"title":"Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced","applicability":"notApplicable"},
    "GV.PO-02": {"title":"Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission","applicability":"notApplicable"},
    "GV.OV-01": {"title":"Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction","applicability":"notApplicable"},
    "GV.OV-02": {"title":"The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks","applicability":"notApplicable"},
    "GV.OV-03": {"title":"Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed","applicability":"notApplicable"},
    "GV.SC-01": {"title":"A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders","applicability":"notApplicable"},
    "GV.SC-02": {"title":"Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally","applicability":"notApplicable"},
    "GV.SC-03": {"title":"Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes","applicability":"notApplicable"},
    "GV.SC-04": {"title":"Suppliers are known and prioritized by criticality","applicability":"notApplicable"},
    "GV.SC-05": {"title":"Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties","applicability":"notApplicable"},
    "GV.SC-06": {"title":"Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships","applicability":"notApplicable"},
    "GV.SC-07": {"title":"The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship","applicability":"notApplicable"},
    "GV.SC-08": {"title":"Relevant suppliers and other third parties are included in incident planning, response, and recovery activities","applicability":"notApplicable"},
    "GV.SC-09": {"title":"Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle","applicability":"notApplicable"},
    "GV.SC-10": {"title":"Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement","applicability":"notApplicable"},
    "ID.AM-01": {"title":"Inventories of hardware managed by the organization are maintained","applicability":"notApplicable"},
    "ID.AM-02": {"title":"Inventories of software, services, and systems managed by the organization are maintained","coverage":"partial","tests":["AZ-VM-013"]},
    "ID.AM-03": {"title":"Representations of the organization's authorized network communication and internal and external network data flows are maintained","applicability":"manual"},
    "ID.AM-04": {"title":"Inventories of services provided by suppliers are maintained","coverage":"partial","tests":["AZ-IAM-025"]},
    "ID.AM-05": {"title":"Assets are prioritized based on classification, criticality, resources, and impact on the mission","applicability":"manual"},
    "ID.AM-07": {"title":"Inventories of data and corresponding metadata for designated data types are maintained","coverage":"partial","tests":["AZ-DEF-024"]},
    "ID.AM-08": {"title":"Systems, hardware, software, services, and data are managed throughout their life cycles","coverage":"partial","tests":["AZ-APIM-007","AZ-APP-012","AZ-GOV-006","AZ-GOV-007","AZ-GOV-008","AZ-GOV-011","AZ-LOGIC-007","AZ-LOGIC-008","AZ-LOGIC-010","AZ-NET-022","AZ-VM-009"]},
    "ID.RA-01": {"title":"Vulnerabilities in assets are identified, validated, and recorded","coverage":"partial","tests":["AZ-DEF-001","AZ-DEF-003","AZ-DEF-008","AZ-DEF-009","AZ-DEF-015","AZ-DEF-017","AZ-DFA-003","AZ-GOV-010","AZ-SQL-009","AZ-VM-005"]},
    "ID.RA-02": {"title":"Cyber threat intelligence is received from information sharing forums and sources","coverage":"partial","tests":["AZ-NET-019"]},
    "ID.RA-03": {"title":"Internal and external threats to the organization are identified and recorded","applicability":"notApplicable"},
    "ID.RA-04": {"title":"Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded","applicability":"notApplicable"},
    "ID.RA-05": {"title":"Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization","applicability":"notApplicable"},
    "ID.RA-06": {"title":"Risk responses are chosen, prioritized, planned, tracked, and communicated","applicability":"notApplicable"},
    "ID.RA-07": {"title":"Changes and exceptions are managed, assessed for risk impact, recorded, and tracked","coverage":"partial","tests":["AZ-GOV-003"]},
    "ID.RA-08": {"title":"Processes for receiving, analyzing, and responding to vulnerability disclosures are established","applicability":"notApplicable"},
    "ID.RA-09": {"title":"The authenticity and integrity of hardware and software are assessed prior to acquisition and use","applicability":"manual"},
    "ID.RA-10": {"title":"Critical suppliers are assessed prior to acquisition","applicability":"notApplicable"},
    "ID.IM-01": {"title":"Improvements are identified from evaluations","applicability":"notApplicable"},
    "ID.IM-02": {"title":"Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties","applicability":"notApplicable"},
    "ID.IM-03": {"title":"Improvements are identified from execution of operational processes, procedures, and activities","applicability":"notApplicable"},
    "ID.IM-04": {"title":"Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved","applicability":"notApplicable"},
    "PR.AA-01": {"title":"Identities and credentials for authorized users, services, and hardware are managed by the organization","coverage":"partial","tests":["AZ-ACR-001","AZ-ACR-004","AZ-ACR-005","AZ-ADF-001","AZ-AI-001","AZ-AI-007","AZ-AKS-001","AZ-AKS-002","AZ-AKS-008","AZ-APIM-003","AZ-APP-004","AZ-APP-006","AZ-AUTO-001","AZ-AUTO-002","AZ-BOT-002","AZ-COS-001","AZ-FUNC-002","AZ-IAM-006","AZ-IAM-007","AZ-IAM-013","AZ-IAM-014","AZ-IAM-020","AZ-IAM-022","AZ-KV-006","AZ-KV-011","AZ-LOGIC-003","AZ-LOGIC-004","AZ-LOGIC-005","AZ-LOGIC-006","AZ-MSG-001","AZ-MY-003","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SEC-001","AZ-SEC-002","AZ-SEC-003","AZ-SEC-004","AZ-SQL-003","AZ-SQL-004","AZ-STG-005","AZ-STG-011","AZ-STG-012","AZ-STG-013","AZ-STG-023","AZ-STG-024"]},
    "PR.AA-02": {"title":"Identities are proofed and bound to credentials based on the context of interactions","applicability":"notApplicable"},
    "PR.AA-03": {"title":"Users, services, and hardware are authenticated","coverage":"partial","tests":["AZ-ACR-001","AZ-ACR-004","AZ-ACR-005","AZ-AI-001","AZ-AI-007","AZ-AKS-001","AZ-AKS-002","AZ-APIM-005","AZ-APP-004","AZ-BOT-002","AZ-COS-001","AZ-IAM-024","AZ-IAM-026","AZ-IAM-027","AZ-IAM-029","AZ-IAM-030","AZ-MSG-001","AZ-MY-003","AZ-NET-021","AZ-PAAS-002","AZ-PG-004","AZ-RED-002","AZ-SQL-003","AZ-SQL-004","AZ-STG-005","AZ-STG-011","AZ-STG-023","AZ-VM-004"]},
    "PR.AA-04": {"title":"Identity assertions are protected, conveyed, and verified","coverage":"partial","tests":["AZ-IAM-022"]},
    "PR.AA-05": {"title":"Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties","coverage":"partial","tests":["AZ-ACR-002","AZ-AKS-002","AZ-AKS-005","AZ-APIM-004","AZ-APP-009","AZ-APP-014","AZ-COS-003","AZ-FUNC-004","AZ-GOV-005","AZ-IAM-001","AZ-IAM-002","AZ-IAM-003","AZ-IAM-004","AZ-IAM-005","AZ-IAM-006","AZ-IAM-007","AZ-IAM-008","AZ-IAM-009","AZ-IAM-010","AZ-IAM-011","AZ-IAM-012","AZ-IAM-015","AZ-IAM-016","AZ-IAM-017","AZ-IAM-018","AZ-IAM-019","AZ-IAM-020","AZ-IAM-021","AZ-IAM-023","AZ-IAM-025","AZ-IAM-028","AZ-KV-002","AZ-KV-009","AZ-LOGIC-001","AZ-MSG-001","AZ-NET-001","AZ-NET-002","AZ-NET-011","AZ-NET-023","AZ-STG-003","AZ-STG-004"]},
    "PR.AA-06": {"title":"Physical access to assets is managed, monitored, and enforced commensurate with risk","applicability":"notApplicable"},
    "PR.AT-01": {"title":"Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind","applicability":"notApplicable"},
    "PR.AT-02": {"title":"Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind","applicability":"notApplicable"},
    "PR.DS-01": {"title":"The confidentiality, integrity, and availability of data-at-rest are protected","coverage":"partial","tests":["AZ-ACR-002","AZ-ADF-001","AZ-ADX-002","AZ-ADX-003","AZ-AI-003","AZ-AI-006","AZ-AKS-009","AZ-APIM-003","AZ-APP-009","AZ-APP-014","AZ-AUTO-001","AZ-BCK-005","AZ-FUNC-004","AZ-KV-001","AZ-KV-005","AZ-KV-007","AZ-KV-010","AZ-LOGIC-001","AZ-LOGIC-004","AZ-NET-007","AZ-SEC-001","AZ-SEC-002","AZ-SEC-003","AZ-SEC-004","AZ-SQL-007","AZ-SQL-008","AZ-STG-003","AZ-STG-004","AZ-STG-010","AZ-STG-020","AZ-STG-021","AZ-STG-025","AZ-STG-026","AZ-SYN-001","AZ-VM-001","AZ-VM-002"]},
    "PR.DS-02": {"title":"The confidentiality, integrity, and availability of data-in-transit are protected","coverage":"partial","tests":["AZ-APIM-002","AZ-APIM-005","AZ-APIM-006","AZ-APP-001","AZ-APP-002","AZ-APP-003","AZ-BOT-003","AZ-CAPP-001","AZ-KV-008","AZ-MY-001","AZ-NET-013","AZ-PAAS-003","AZ-PG-001","AZ-RED-001","AZ-SQL-006","AZ-STG-001","AZ-STG-002","AZ-STG-018","AZ-STG-019"]},
    "PR.DS-10": {"title":"The confidentiality, integrity, and availability of data-in-use are protected","coverage":"partial","tests":["AZ-SQL-010"]},
    "PR.DS-11": {"title":"Backups of data are created, protected, maintained, and tested","coverage":"partial","tests":["AZ-BCK-001","AZ-BCK-002","AZ-BCK-003","AZ-BCK-004","AZ-BCK-005","AZ-BCK-006","AZ-BCK-007","AZ-BCK-008","AZ-BCK-009","AZ-BCK-010","AZ-GOV-004","AZ-STG-014","AZ-STG-015","AZ-STG-016","AZ-STG-017","AZ-STG-022","AZ-VM-010"]},
    "PR.PS-01": {"title":"Configuration management practices are established and applied","coverage":"partial","tests":["AZ-ADF-002","AZ-AKS-004","AZ-APIM-001","AZ-APP-005","AZ-APP-007","AZ-DEF-001","AZ-DFA-004","AZ-GOV-001","AZ-GOV-002","AZ-GOV-009","AZ-NET-014","AZ-NET-022","AZ-VM-003","AZ-VM-007"]},
    "PR.PS-02": {"title":"Software is maintained, replaced, and removed commensurate with risk","coverage":"partial","tests":["AZ-AKS-006","AZ-APIM-007","AZ-APP-012","AZ-DFA-002","AZ-DFA-003","AZ-GOV-008","AZ-GOV-010","AZ-VM-009"]},
    "PR.PS-03": {"title":"Hardware is maintained, replaced, and removed commensurate with risk","applicability":"notApplicable"},
    "PR.PS-04": {"title":"Log records are generated and made available for continuous monitoring","coverage":"partial","tests":["AZ-DBX-005","AZ-LOG-001","AZ-LOG-002","AZ-LOG-014","AZ-LOG-015","AZ-LOG-016","AZ-LOG-019","AZ-LOG-021","AZ-LOG-022","AZ-LOG-024","AZ-LOG-025","AZ-LOG-026","AZ-MY-002","AZ-PG-002","AZ-PG-003","AZ-SQL-001","AZ-SQL-002","AZ-VM-008"]},
    "PR.PS-05": {"title":"Installation and execution of unauthorized software are prevented","applicability":"manual"},
    "PR.PS-06": {"title":"Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle","applicability":"notApplicable"},
    "PR.IR-01": {"title":"Networks and environments are protected from unauthorized logical access and usage","coverage":"partial","tests":["AZ-ACI-001","AZ-ACR-003","AZ-ADX-001","AZ-AI-002","AZ-AI-003","AZ-AI-005","AZ-AI-006","AZ-AI-007","AZ-AKS-003","AZ-AKS-007","AZ-APP-008","AZ-AVD-001","AZ-BOT-001","AZ-CAPP-002","AZ-COS-002","AZ-DB-001","AZ-DB-002","AZ-DBX-001","AZ-DBX-002","AZ-DBX-003","AZ-DBX-004","AZ-DBX-006","AZ-KV-003","AZ-KV-004","AZ-NET-001","AZ-NET-002","AZ-NET-003","AZ-NET-004","AZ-NET-005","AZ-NET-006","AZ-NET-007","AZ-NET-008","AZ-NET-009","AZ-NET-010","AZ-NET-011","AZ-NET-012","AZ-NET-015","AZ-NET-016","AZ-NET-017","AZ-NET-018","AZ-NET-019","AZ-NET-020","AZ-NET-023","AZ-PAAS-001","AZ-SQL-005","AZ-STG-006","AZ-STG-007","AZ-STG-008","AZ-STG-009","AZ-SYN-001","AZ-VM-011","AZ-VM-012"]},
    "PR.IR-02": {"title":"The organization's technology assets are protected from environmental threats","applicability":"notApplicable"},
    "PR.IR-03": {"title":"Mechanisms are implemented to achieve resilience requirements in normal and adverse situations","coverage":"partial","tests":["AZ-BCK-004","AZ-BCK-007","AZ-BCK-009","AZ-BCK-011","AZ-BCK-012","AZ-NET-010","AZ-STG-022"]},
    "PR.IR-04": {"title":"Adequate resource capacity to ensure availability is maintained","coverage":"partial","tests":["AZ-GOV-012"]},
    "DE.CM-01": {"title":"Networks and network services are monitored to find potentially adverse events","coverage":"partial","tests":["AZ-LOG-017","AZ-LOG-018","AZ-LOG-020","AZ-LOG-023","AZ-NET-012","AZ-NET-015","AZ-NET-016","AZ-NET-017","AZ-NET-018","AZ-NET-020","AZ-NET-024","AZ-NET-025"]},
    "DE.CM-02": {"title":"The physical environment is monitored to find potentially adverse events","applicability":"notApplicable"},
    "DE.CM-03": {"title":"Personnel activity and technology usage are monitored to find potentially adverse events","coverage":"partial","tests":["AZ-DEF-011","AZ-LOG-001","AZ-LOG-002","AZ-LOG-003","AZ-LOG-004","AZ-LOG-005","AZ-LOG-006","AZ-LOG-007","AZ-LOG-008","AZ-LOG-009","AZ-LOG-010","AZ-LOG-011","AZ-LOG-012"]},
    "DE.CM-06": {"title":"External service provider activities and services are monitored to find potentially adverse events","coverage":"partial","tests":["AZ-LOG-013"]},
    "DE.CM-09": {"title":"Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events","coverage":"partial","tests":["AZ-DEF-002","AZ-DEF-003","AZ-DEF-004","AZ-DEF-005","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-010","AZ-DEF-011","AZ-DEF-012","AZ-DEF-013","AZ-DEF-014","AZ-DEF-016","AZ-DEF-025","AZ-DFA-001","AZ-VM-006","AZ-VM-013"]},
    "DE.AE-02": {"title":"Potentially adverse events are analyzed to better understand associated activities","coverage":"partial","tests":["AZ-DEF-002","AZ-DEF-003","AZ-DEF-004","AZ-DEF-005","AZ-DEF-006","AZ-DEF-007","AZ-DEF-008","AZ-DEF-009","AZ-DEF-010","AZ-DEF-011","AZ-DEF-012","AZ-DEF-013","AZ-DEF-022","AZ-LOG-003","AZ-LOG-004","AZ-LOG-005","AZ-LOG-006","AZ-LOG-007","AZ-LOG-008","AZ-LOG-009","AZ-LOG-010","AZ-LOG-011","AZ-LOG-012","AZ-LOG-020","AZ-LOG-023"]},
    "DE.AE-03": {"title":"Information is correlated from multiple sources","coverage":"partial","tests":["AZ-DEF-023"]},
    "DE.AE-04": {"title":"The estimated impact and scope of adverse events are understood","applicability":"notApplicable"},
    "DE.AE-06": {"title":"Information on adverse events is provided to authorized staff and tools","coverage":"partial","tests":["AZ-DEF-018","AZ-DEF-019","AZ-DEF-020","AZ-DEF-021","AZ-DEF-023"]},
    "DE.AE-07": {"title":"Cyber threat intelligence and other contextual information are integrated into the analysis","coverage":"partial","tests":["AZ-NET-019"]},
    "DE.AE-08": {"title":"Incidents are declared when adverse events meet the defined incident criteria","applicability":"notApplicable"},
    "RS.MA-01": {"title":"The incident response plan is executed in coordination with relevant third parties once an incident is declared","applicability":"notApplicable"},
    "RS.MA-02": {"title":"Incident reports are triaged and validated","coverage":"partial","tests":["AZ-DEF-022"]},
    "RS.MA-03": {"title":"Incidents are categorized and prioritized","applicability":"notApplicable"},
    "RS.MA-04": {"title":"Incidents are escalated or elevated as needed","applicability":"notApplicable"},
    "RS.MA-05": {"title":"The criteria for initiating incident recovery are applied","applicability":"notApplicable"},
    "RS.AN-03": {"title":"Analysis is performed to establish what has taken place during an incident and the root cause of the incident","applicability":"notApplicable"},
    "RS.AN-06": {"title":"Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved","applicability":"notApplicable"},
    "RS.AN-07": {"title":"Incident data and metadata are collected, and their integrity and provenance are preserved","applicability":"notApplicable"},
    "RS.AN-08": {"title":"An incident's magnitude is estimated and validated","applicability":"notApplicable"},
    "RS.CO-02": {"title":"Internal and external stakeholders are notified of incidents","applicability":"manual"},
    "RS.CO-03": {"title":"Information is shared with designated internal and external stakeholders","applicability":"notApplicable"},
    "RS.MI-01": {"title":"Incidents are contained","applicability":"notApplicable"},
    "RS.MI-02": {"title":"Incidents are eradicated","applicability":"notApplicable"},
    "RC.RP-01": {"title":"The recovery portion of the incident response plan is executed once initiated from the incident response process","applicability":"notApplicable"},
    "RC.RP-02": {"title":"Recovery actions are selected, scoped, prioritized, and performed","applicability":"notApplicable"},
    "RC.RP-03": {"title":"The integrity of backups and other restoration assets is verified before using them for restoration","applicability":"notApplicable"},
    "RC.RP-04": {"title":"Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms","applicability":"notApplicable"},
    "RC.RP-05": {"title":"The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed","applicability":"notApplicable"},
    "RC.RP-06": {"title":"The end of incident recovery is declared based on criteria, and incident-related documentation is completed","applicability":"notApplicable"},
    "RC.CO-03": {"title":"Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders","applicability":"notApplicable"},
    "RC.CO-04": {"title":"Public updates on incident recovery are shared using approved methods and messaging","applicability":"notApplicable"}
  }
}