Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.IR-01 What else in your programme already covers this This control maps to 179 controls across 41 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.3.1 1.3.1 Inbound CDE traffic restricted 1.3.2 1.3.2 Outbound CDE traffic restricted 1.3.3 1.3.3 NSCs between wireless networks and the CDE 1.4.1 1.4.1 NSCs between trusted and untrusted networks 1.4.2 1.4.2 Restricting traffic entering trusted networks from outside 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks 1.4.5 1.4.5 Internal IP and routing disclosure limited 1.5.1 1.5.1 Security controls on dual-connected devices 11.2.1 11.2.1 Detect authorized and rogue wireless access points 2.2.3 2.2.3 Primary functions with different security levels managed 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 6.4.2 6.4.2 Automated web attack detection and prevention 9.4.1 9.4.1 Physical security of all media 7.3.1 7.3.1 Need-to-know access control system covers all components ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-15 Protect Against Threats Related to Removable Media ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations ANSSI-HYG-19 Segment the Network and Partition the Zones ANSSI-HYG-20 Secure Wi-Fi Access Networks and Separate Usage ANSSI-HYG-22 Put in Place a Secure Internet Access Gateway ANSSI-HYG-23 Partition Internet Facing Services from the Rest of the Information System ANSSI-HYG-24 Protect the Corporate Mail Service ANSSI-HYG-25 Secure Dedicated Network Interconnections with Partners ANSSI-HYG-27 Prohibit Internet Access from Administration Workstations and Servers ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration ANSSI-HYG-32 Secure the Network Connection of Devices Used for Mobile Working CIS-1.2 Address Unauthorized Assets CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-13.4 Perform Traffic Filtering Between Network Segments CIS-13.9 Deploy Port-Level Access Control CIS-3.12 Segment Data Processing and Storage Based on Sensitivity CIS-4.4 Implement and Manage a Firewall on Servers CIS-4.5 Implement and Manage a Firewall on End-User Devices CIS-4.6 Securely Manage Enterprise Assets and Software CIS-6.3 Require MFA for Externally-Exposed Applications CIS-9.3 Maintain and Enforce Network-Based URL Filters ASD37-05 Automated dynamic analysis of email and web content (Excellent) ASD37-06 Email content filtering (Excellent) ASD37-07 Web content filtering (Excellent) ASD37-08 Deny direct internet connectivity (Excellent) ASD37-13 Control removable storage media (Very Good) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-24 Non-persistent virtualised sandboxed environment (Very Good) ASD37-25 Software firewall - inbound (Very Good) ASD37-26 Software firewall - outbound (Very Good) C5-COS-01 Technical safeguards C5-COS-02 Security requirements for connections in the Cloud Service Provider's network C5-COS-03 Monitoring of connections in the Cloud Service Provider's network C5-COS-04 Cross-network access C5-COS-06 Segregation of data traffic in jointly used network environments C5-DEV-10 Separation of environments C5-PSS-10 Software Defined Networking 5.15 Access control 6.7 Remote working 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks 8.23 Web filtering 8.3 Information access restriction 5.15 Access control 6.7 Remote working 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks 8.23 Web filtering SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal ASBv3-NS-10 Ensure Domain Name System (DNS) security ASBv3-NS-6 Deploy web application firewall NS-1 Establish network segmentation boundaries NS-2 Secure cloud services with network controls NS-3 Deploy firewall at the edge of enterprise network 6.10.1 Network security management 6.3.2 Mobile devices and teleworking 6.6 Access control 6.6.4 System and application access control PR.AC-3 PR.AC-3: Remote access is managed PR.AC-5 PR.AC-5: Network integrity is protected, incorporating network segregation where appropriate PR.DS-7 PR.DS-7: The development and testing environment(s) are separate from the production environment PR.PT-4 PR.PT-4: Communications and control networks are protected PR.AC-3 PR.AC-3: Remote access is managed PR.AC-5 PR.AC-5: Network integrity is protected (e.g., network segregation, network segmentation) PR.DS-7 PR.DS-7: The development and testing environment(s) are separate from the production environment PR.PT-4 PR.PT-4: Communications and control networks are protected CE-FW.1 Boundary Firewalls Deployed CE-FW.3 Block Unauthenticated Inbound Connections CE-FW.4 Approve and Document Inbound Rules CE-FW.6 Host-Based Firewall for Remote Workers ISM-0520 Blocking unauthorised network devices ISM-0631 Explicitly authorised gateway data flows ISM-1182 Restricting traffic between network segments 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources 3.13.1e Create Diversity in System Components to Limit Malicious Code Propagation 3.5.1e Identification of Systems, Components, and Devices ARCH-1 Establish a Cybersecurity Architecture Strategy ARCH-2 Implement Network Protections E8-ADMIN-ML1 Restrict Administrative Privileges (ML1) AWWA-3.1 Network Segmentation AUCDR-IS-2 Secure the network and systems within the data environment BE-CF-07 Boundary protection and segmentation BMA-24 Network Security Management ITSG33-SC System and Communications Protection (SC) 8.3.5 Implementation of solutions Art.21.2.g Basic cyber hygiene practices and cybersecurity training Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.IR-01 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 179 it maps to, and the evidence behind each claim, over MCP and REST.