NIST Cybersecurity Framework 2.0
ID - Identify

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.IM-03: Improvements are identified from execution of operational processes, procedures, and activities

Improvements are identified from execution of operational processes, procedures, and activities

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 79 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • DE.DP-5 DE.DP-5: Detection processes are continuously improved
  • PR.IP-7 PR.IP-7: Protection processes are continuously improved
  • PR.IP-8 PR.IP-8: Effectiveness of protection technologies is shared with appropriate parties
  • RC.IM-1 RC.IM-1: Recovery plans incorporate lessons learned
  • RC.IM-2 RC.IM-2: Recovery strategies are updated
  • RS.IM-1 RS.IM-1: Response plans incorporate lessons learned
  • RS.IM-2 RS.IM-2: Response strategies are updated
  • DE.DP-5 DE.DP-5: Detection processes are continuously improved
  • PR.IP-7 PR.IP-7: Protection processes are improved
  • PR.IP-8 PR.IP-8: Effectiveness of protection technologies is shared
  • RC.IM-1 RC.IM-1: Recovery plans incorporate lessons learned
  • RC.IM-2 RC.IM-2: Recovery strategies are updated
  • RS.IM-1 RS.IM-1: Response plans incorporate lessons learned
  • RS.IM-2 RS.IM-2: Response strategies are updated

NIST SP 800-53 Rev 5 · 7 controls

ISO 27701:2019 · 5 controls

  • 5.4.1 Actions to address risks and opportunities
  • 5.8 Improvement
  • 5.8.1 Nonconformity and corrective action
  • 5.8.2 Continual improvement
  • 6.13.1 Management of information security incidents and improvements

SOC 2 · 5 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

ISO 22301:2019 · 4 controls

  • 10.1 Nonconformity and corrective action
  • 10.2 Continual improvement
  • 8.5 Exercise programme
  • 9.3.2 Management review input
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P31 Remediation of Material Operational Risk Weaknesses
  • CPS230-P45 Annual Update of the Business Continuity Plan
  • CFTC-SS-16 Security Incident Response Plan and Testing
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies
  • CFTC-SS-24 Periodic Update of the Recovery Plan and Emergency Procedures

CIS Controls v8 · 3 controls

  • CIS-13.11 Tune Security Event Alerting Thresholds
  • CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities
  • CIS-17.8 Conduct Post-Incident Reviews

ISO/IEC 42001:2023 · 3 controls

  • 10.1 Continual improvement
  • 10.2 Nonconformity and corrective action
  • A.8.4 Communication of incidents

APRA CPS 234 · 2 controls

  • CPS234-P17 Active Maintenance of Capability Against Change
  • CPS234-P25 Response Plan Content and Escalation Mechanisms
  • ISM-1526 Continuous security monitoring by system owners
  • ISM-1909 Root cause analysis of vulnerabilities

FedRAMP High · 2 controls

  • CA-7 Continuous Monitoring
  • IR-4 Incident Handling

FedRAMP Moderate · 2 controls

  • CA-7 Continuous Monitoring
  • IR-4 Incident Handling

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-218 · 2 controls

  • ANSSI-HYG-40 Define a Security Incident Management Procedure
  • ADMF-6.5 Update policies, procedures and processes
  • SEC10-BP08 Establish a framework for learning from incidents
  • AEO-13 Measurement, Analyses and Improvement
  • ASBv3-IR-7 Post-incident activity - conduct lesson learned and retain evidence

C5 (Germany) · 1 control

CMMC 2.0 · 1 control

DORA · 1 control

HIPAA Security Rule · 1 control

ISO 27001:2022 · 1 control

  • 5.27 Learning from information security incidents

ISO 27002:2022 · 1 control

  • 5.27 Learning from information security incidents

NIS2 Directive · 1 control

  • Art.21.4 Take corrective measures without undue delay on finding that the measures are not met

NIST SP 800-172 · 1 control

  • 3.11.5e Assess Effectiveness of Security Solutions
  • ID.IM-03 ID.IM-03 Lessons learned from incident response and recovery feed improvement

PCI DSS 4.0 · 1 control

  • 12.10.6 12.10.6 Plan evolved from lessons learned and industry developments

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in ID - Identify

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-ID.IM-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 79 it maps to, and the evidence behind each claim, over MCP and REST.