NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 111 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 9 controls

  • CIS-16.13 Conduct Application Penetration Testing
  • CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities
  • CIS-18.1 Establish and Maintain a Penetration Testing Program
  • CIS-18.2 Perform Periodic External Penetration Tests
  • CIS-18.4 Validate Security Measures
  • CIS-18.5 Perform Periodic Internal Penetration Tests
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.7 Remediate Detected Vulnerabilities

ISO 27701:2019 · 8 controls

  • 5.7.1 Monitoring, measurement, analysis and evaluation
  • 5.7.2 Internal audit
  • 5.8 Improvement
  • 5.8.2 Continual improvement
  • 6.11 Systems acquisition, development and maintenance
  • 6.13.1 Management of information security incidents and improvements
  • 6.15.2 Information security reviews
  • 6.9.7 Information systems audit considerations

ISO 22301:2019 · 6 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement
  • 8.6 Evaluation of business continuity documentation and capabilities
  • 9.2 Internal audit
  • 9.2.2 Audit programme(s)
  • 9.3 Management review

ISO/IEC 42001:2023 · 6 controls

  • 10.1 Continual improvement
  • 10.2 Nonconformity and corrective action
  • 9.2 Internal audit
  • 9.2.1 General
  • 9.2.2 Internal audit programme
  • 9.3 Management review

NIST SP 800-53 Rev 5 · 5 controls

FedRAMP High · 4 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-7(1) Independent Assessment
  • MA-3 Maintenance Tools (MA-3)

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-7(1) Independent Assessment
  • MA-3 Maintenance Tools (MA-3)

ISO 27001:2022 · 4 controls

  • 5.27 Learning from information security incidents
  • 5.35 Independent review of information security
  • 5.36 Compliance with policies, rules and standards for information security
  • 8.32 Change management
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPS230-P30 Monitoring, Review and Testing of Control Effectiveness

APRA CPS 234 · 3 controls

  • CPS234-22 Systematic Control Testing Program
  • CPS234-25 Internal Audit Review of Information Security Controls
  • CPS234-P30 Independence and Skill of Testing Personnel
  • SEC01-BP08 Evaluate and implement new security services and features regularly
  • SEC11-BP03 Perform regular penetration testing
  • SEC11-BP07 Regularly assess security properties of the pipelines
  • ISM-1563 Security assessment report
  • ISM-1564 Plan of action and milestones
  • ISM-1636 Security assessment by organisational or IRAP assessors
  • DE.DP-3 DE.DP-3: Detection processes are tested
  • ID.SC-5 ID.SC-5: Response and recovery planning and testing are conducted with suppliers and third-party providers
  • PR.IP-10 PR.IP-10: Response and recovery plans are tested

NIST SP 800-171 Rev 3 · 3 controls

  • 53A-3.3 Conduct Control Assessments
  • 53A-3.4 Analyze Assessment Report Results
  • 53A-E Assessment Reports

PCI DSS 4.0 · 3 controls

  • 11.3.1 11.3.1 Quarterly internal vulnerability scans
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • CPS220-11 Annual Audit Review of the Framework
  • CPS220-18 Triennial Comprehensive Review of the Framework
  • PV-2 Audit and enforce secure configurations
  • PV-5 Perform vulnerability assessments

C5 (Germany) · 2 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-OPS-20 Managing Vulnerabilities, Malfunctions and Errors - Measurements, Analyses and Assessments of Procedures

CMMC 2.0 · 2 controls

DORA · 2 controls

  • DORA-Art.24 General requirements for the performance of digital operational resilience testing
  • DORA-Art.50 Administrative penalties and remedial measures

NIS2 Directive · 2 controls

  • Art.21.2.f Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  • Art.32 Cooperate with supervision: inspections, security audits, scans and requests for information and evidence
  • DE.DP-3 DE.DP-3: Detection processes are tested
  • PR.IP-10 PR.IP-10: Response and recovery plans are tested

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-172 · 2 controls

  • 3.11.5e Assess Effectiveness of Security Solutions
  • 3.14.7e Verify Correctness of Security Functions

SOC 2 · 2 controls

  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • ANSSI-HYG-38 Carry Out Regular Security Checks and Audits and Apply the Corrective Actions
  • SPS220-48 Internal and External Audit Arrangements
  • ADMF-6.2 Review controls associated with each category
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program
  • IRAP-CAF-3 Stage 3 - Assess the controls

HIPAA Security Rule · 1 control

ISO 27002:2022 · 1 control

  • 5.35 Independent review of information security

NIST SP 800-218 · 1 control

  • ID.IM-02 ID.IM-02 Improvements identified from incident response tests and exercises
  • 3(e) Sec. 3(e) (now 3(c)) Continually verify the cybersecurity of Federal space systems

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.IM-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 111 it maps to, and the evidence behind each claim, over MCP and REST.