Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-ID.IM-01 What else in your programme already covers this This control maps to 90 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CFTC-SS-11 Testing and Review of Business Continuity and Disaster Recovery Capabilities CFTC-SS-13 Vulnerability Testing CFTC-SS-14 External Penetration Testing CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies CFTC-SS-22 Business Continuity and Disaster Recovery Planning Category CFTC-SS-28 Synchronised Testing with Members and Market Participants CFTC-SS-34 Internal Penetration Testing CFTC-SS-5 Systems Development and Quality Assurance Category 11.4.1 11.4.1 Penetration testing methodology defined and implemented 11.4.2 11.4.2 Internal penetration testing annually and after change 11.4.3 11.4.3 External penetration testing annually and after change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 11.4.5 11.4.5 Annual segmentation penetration testing 12.10.2 12.10.2 Annual review and testing of the incident response plan 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments CIS-17.7 Conduct Routine Incident Response Exercises CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.3 Remediate Penetration Test Findings CIS-18.4 Validate Security Measures 5.24 Information security incident management planning and preparation 5.27 Learning from information security incidents 8.29 Security testing in development and acceptance 8.33 Test information SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC7.5 CC7.5 Recovering from security incidents SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure CPS230-33 Systematic BCP Testing Program CPS230-34 Tailoring of the Testing Program CPS230-P45 Annual Update of the Business Continuity Plan ISM-1037 Gateway testing after changes and six-monthly ISM-1163 Continuous monitoring plan ISM-1784 Annual exercising of incident response plan DORA-Art.13 Learning and evolving DORA-Art.24 General requirements for the performance of digital operational resilience testing DORA-Art.25 Testing of ICT tools and systems CA-8 Penetration Testing CP-4 Contingency Plan Testing IR-3 Incident Response Testing CA-8 Penetration Testing CP-4 Contingency Plan Testing IR-3 Incident Response Testing 10.1 Nonconformity and corrective action 8.5 Exercise programme 8.6 Evaluation of business continuity documentation and capabilities 5.27 Learning from information security incidents 5.35 Independent review of information security 8.29 Security testing in development and acceptance 5.8 Improvement 5.8.2 Continual improvement 6.13.1 Management of information security incidents and improvements CPS234-28 Escalation of Unremediated Testing Deficiencies CPS234-32 Annual Review and Testing of Response Plans C5-BCM-04 Verification, updating and testing of the business continuity C5-OPS-19 Managing Vulnerabilities, Malfunctions and Errors - Penetration Tests 3.12.1e Penetration Testing by Independent Agents 3.2.2e Practical Exercises in Awareness Training 53A-3.4 Analyze Assessment Report Results 53A-D Penetration Testing ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions ASD37-35 Business continuity and disaster recovery plans (Very Good) ADMF-6.4 Test data protection control effectiveness AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program BE-CF-22 Lessons learned and improvement 10.1 Continual improvement Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures ID.IM-01 ID.IM-01 Incident response program periodically evaluated Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ID - Identify NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.AM-05 Assets are prioritized based on classification, criticality, resources, and impact on the mission NIST-CSF-ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-ID.IM-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.