NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected

The confidentiality, integrity, and availability of data-in-use are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 142 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 9 controls

FedRAMP High · 7 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AU-9 Protection of Audit Information
  • SC-39 Process Isolation
  • SC-4 Information in Shared System Resources
  • SC-8 Transmission Confidentiality and Integrity
  • SI-16 Memory Protection
  • SI-6 Security and Privacy Function Verification (SI-6)

FedRAMP Moderate · 7 controls

  • AC-17(2) Protection of Confidentiality and Integrity Using Encryption
  • AU-9 Protection of Audit Information
  • SC-39 Process Isolation
  • SC-4 Information in Shared System Resources
  • SC-8 Transmission Confidentiality and Integrity
  • SI-16 Memory Protection
  • SI-6 Security and Privacy Function Verification (SI-6)

SOC 2 · 7 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software

ISO 27001:2022 · 5 controls

  • 6.7 Remote working
  • 8.11 Data masking
  • 8.12 Data leakage prevention
  • 8.24 Use of cryptography
  • 8.33 Test information

ISO 27701:2019 · 4 controls

  • 6.6.4 System and application access control
  • 6.7.1 Cryptographic controls
  • 6.9.2 Protection from malware
  • 6.9.4 Logging and monitoring
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • ISM-0164 Preventing observation by unauthorised people
  • ISM-1686 Enabling Credential Guard
  • ISM-1861 Local Security Authority protection
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

ISO 27002:2022 · 3 controls

  • 8.11 Data masking
  • 8.12 Data leakage prevention
  • 8.24 Use of cryptography

PCI P2PE · 3 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI PIN Security · 3 controls

  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures

PCI SSF · 3 controls

  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

OSFI B-13 · 2 controls

  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

PCI DSS 4.0 · 2 controls

  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 3.4.1 3.4.1 PAN masked on display except for authorized roles

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-2 Business Model Resilience
  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • SEMD-CS-3 Cyber Resilience
  • SEMD-ER-1 Emergency Exercise and Testing
  • ASD37-20 Multi-factor authentication (Essential)
  • SEC07-BP04 Define scalable data lifecycle management
  • AUCDR-IS-3 Securely manage information assets over their lifecycle
  • BS65000-RM-03 Leadership and Culture

C5 (Germany) · 1 control

  • C5-OPS-24 Separation of Datasets in the Cloud Infrastructure

CIS Controls v8 · 1 control

  • CIS-3.13 Deploy a Data Loss Prevention Solution

CMMC 2.0 · 1 control

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • RMD-1 Reference Data Management
  • CAT-D5-4 Resilience planning and testing

HIPAA Security Rule · 1 control

  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIS2 Directive · 1 control

  • Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption
  • PR.DS-5 PR.DS-5: Protections against data leaks are implemented
  • PR.DS-5 PR.DS-5: Protections against data leaks are implemented
  • 03.13.04 Information in Shared System Resources
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • SOC-CY-A1 Availability Commitments
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SAPAIA-2 Right of Access and Request Processes
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 142 it maps to, and the evidence behind each claim, over MCP and REST.