Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-ID.IM-02 NIST Cybersecurity Framework 2.0
ID - Identify
NIST Cybersecurity Framework 2.0 NIST-CSF-ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 111 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-16.13 Conduct Application Penetration Testing CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities CIS-18.1 Establish and Maintain a Penetration Testing Program CIS-18.2 Perform Periodic External Penetration Tests CIS-18.4 Validate Security Measures CIS-18.5 Perform Periodic Internal Penetration Tests CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.2 Establish and Maintain a Remediation Process CIS-7.7 Remediate Detected Vulnerabilities 5.7.1 Monitoring, measurement, analysis and evaluation 5.7.2 Internal audit 5.8 Improvement 5.8.2 Continual improvement 6.11 Systems acquisition, development and maintenance 6.13.1 Management of information security incidents and improvements 6.15.2 Information security reviews 6.9.7 Information systems audit considerations 10.1 Nonconformity and corrective action 10.2 Continual improvement 8.6 Evaluation of business continuity documentation and capabilities 9.2 Internal audit 9.2.2 Audit programme(s) 9.3 Management review 10.1 Continual improvement 10.2 Nonconformity and corrective action 9.2 Internal audit 9.2.1 General 9.2.2 Internal audit programme 9.3 Management review CA-2 Control Assessments CA-5 Plan of Action and Milestones CA-7(1) Independent Assessment MA-3 Maintenance Tools (MA-3) CA-2 Control Assessments CA-5 Plan of Action and Milestones CA-7(1) Independent Assessment MA-3 Maintenance Tools (MA-3) 5.27 Learning from information security incidents 5.35 Independent review of information security 5.36 Compliance with policies, rules and standards for information security 8.32 Change management CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing CPS230-P30 Monitoring, Review and Testing of Control Effectiveness CPS234-22 Systematic Control Testing Program CPS234-25 Internal Audit Review of Information Security Controls CPS234-P30 Independence and Skill of Testing Personnel SEC01-BP08 Evaluate and implement new security services and features regularly SEC11-BP03 Perform regular penetration testing SEC11-BP07 Regularly assess security properties of the pipelines ISM-1563 Security assessment report ISM-1564 Plan of action and milestones ISM-1636 Security assessment by organisational or IRAP assessors DE.DP-3 DE.DP-3: Detection processes are tested ID.SC-5 ID.SC-5: Response and recovery planning and testing are conducted with suppliers and third-party providers PR.IP-10 PR.IP-10: Response and recovery plans are tested 53A-3.3 Conduct Control Assessments 53A-3.4 Analyze Assessment Report Results 53A-E Assessment Reports 11.3.1 11.3.1 Quarterly internal vulnerability scans 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews 7.2.4 7.2.4 User accounts and privileges reviewed every six months CPS220-11 Annual Audit Review of the Framework CPS220-18 Triennial Comprehensive Review of the Framework PV-2 Audit and enforce secure configurations PV-5 Perform vulnerability assessments C5-COM-03 Internal audits of the information security management system C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures DORA-Art.24 General requirements for the performance of digital operational resilience testing DORA-Art.50 Administrative penalties and remedial measures Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence DE.DP-3 DE.DP-3: Detection processes are tested PR.IP-10 PR.IP-10: Response and recovery plans are tested 3.11.5e Assess Effectiveness of Security Solutions 3.14.7e Verify Correctness of Security Functions SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16) SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17) ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions SPS220-48 Internal and External Audit Arrangements ADMF-6.2 Review controls associated with each category AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program IRAP-CAF-3 Stage 3 - Assess the controls 5.35 Independent review of information security ID.IM-02 ID.IM-02 Improvements identified from incident response tests and exercises 3(e) Sec. 3(e) (now 3(c)) Continually verify the cybersecurity of Federal space systems Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in ID - Identify You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-ID.IM-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 111 it maps to, and the evidence behind each claim, over MCP and REST.