Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.DS-10 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-10: The confidentiality, integrity, and availability of data-in-use are protected The confidentiality, integrity, and availability of data-in-use are protected. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 142 controls across 58 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AC-17(2) Protection of Confidentiality and Integrity Using Encryption AU-9 Protection of Audit Information SC-39 Process Isolation SC-4 Information in Shared System Resources SC-8 Transmission Confidentiality and Integrity SI-16 Memory Protection SI-6 Security and Privacy Function Verification (SI-6) AC-17(2) Protection of Confidentiality and Integrity Using Encryption AU-9 Protection of Audit Information SC-39 Process Isolation SC-4 Information in Shared System Resources SC-8 Transmission Confidentiality and Integrity SI-16 Memory Protection SI-6 Security and Privacy Function Verification (SI-6) SOC2-A1.1 A1.1 Managing processing capacity SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures SOC2-C1.1 C1.1 Identifying and maintaining confidential information SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software 6.7 Remote working 8.11 Data masking 8.12 Data leakage prevention 8.24 Use of cryptography 8.33 Test information 6.6.4 System and application access control 6.7.1 Cryptographic controls 6.9.2 Protection from malware 6.9.4 Logging and monitoring 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness ISM-0164 Preventing observation by unauthorised people ISM-1686 Enabling Credential Guard ISM-1861 Local Security Authority protection FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification 8.11 Data masking 8.12 Data leakage prevention 8.24 Use of cryptography PCI-P2PE-11 Business continuity planning and testing PCI-P2PE-12 Disaster recovery procedures PCI-P2PE-14 Critical service identification PCI-PIN-13 Third-party dependency management PCI-PIN-14 Critical service identification PCI-PIN-15 Communication and escalation procedures PCI-SSF-12 Disaster recovery procedures PCI-SSF-14 Critical service identification PCI-SSF-15 Communication and escalation procedures IM8-DAT.2 Data Protection IM8-DSS.2 Service Reliability Standards IM8-RES.4 Resilience Testing CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience 27031-8.1 Exercising and Testing 27031-B High availability embedded systems NISTPF-6 Protect-P Data Security (PR.DS-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection OSFIB13-4 Third-Party Risk Management and Cloud OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 3.4.1 3.4.1 PAN masked on display except for authorized roles SASB-1 Business Model + Innovation (BMI) SASB-BMI-2 Business Model Resilience SOCI-S30BC Notification of critical cyber security incidents (12 hours) SOCI-S30BD Notification of other cyber security incidents (72 hours) OB-API.4 MI Reporting Specification OB-OPS.1 API Availability Requirements SEMD-CS-3 Cyber Resilience SEMD-ER-1 Emergency Exercise and Testing ASD37-20 Multi-factor authentication (Essential) SEC07-BP04 Define scalable data lifecycle management AUCDR-IS-3 Securely manage information assets over their lifecycle BS65000-RM-03 Leadership and Culture C5-OPS-24 Separation of Datasets in the Cloud Infrastructure CIS-3.13 Deploy a Data Loss Prevention Solution COBIT-BAI04 Managed availability and capacity RMD-1 Reference Data Management CAT-D5-4 Resilience planning and testing ISO20000-03 Capacity and availability management ISO-25012-4.13 Availability 27007-5.4 Establishing the Programme Resources ITIL4-03 Capacity and availability management Art.21.2.h Policies and procedures on the use of cryptography and, where appropriate, encryption PR.DS-5 PR.DS-5: Protections against data leaks are implemented PR.DS-5 PR.DS-5: Protections against data leaks are implemented 03.13.04 Information in Shared System Resources ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection PSDTWO-2 SCA Exemptions and Risk-Based Authentication SOC-CY-A1 Availability Commitments SSAE18-A1.1 A1.1 - Availability Commitments and Requirements SAPAIA-2 Right of Access and Request Processes UKAI-3 Bias Detection, Fairness, Validation UKOPRES-5 Third-Party Risk, Concentration Risk CERT-1 RRA Certification to EPA Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.DS-10 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 142 it maps to, and the evidence behind each claim, over MCP and REST.