Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.IR-04 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.IR-04: Adequate resource capacity to ensure availability is maintained Adequate resource capacity to ensure availability is maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 122 controls across 56 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
AU-4 Audit Log Storage Capacity CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3)) CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1)) MA-6 Timely Maintenance (MA-6) SC-5 Denial-of-Service Protection AU-4 Audit Log Storage Capacity CP-7(2) Alternate Processing Site | Accessibility (CP-7(2)) CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3)) CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1)) MA-6 Timely Maintenance (MA-6) SC-5 Denial-of-Service Protection 4.3.2 Legal and Other Requirements 4.4.1 Resources, Roles, Responsibility, and Authority 4.4.2 Competence, Training, and Awareness ISM-1431 Discussing DoS mitigation with cloud providers ISM-1579 Verifying CSP dynamic scaling for demand spikes ISM-1581 Real-time capacity and availability monitoring C5-OPS-01 Capacity Management - Planning C5-OPS-02 Capacity Management - Monitoring C5-OPS-03 Capacity Management - Controlling of Resources CFTC-SS-12 Capacity and Performance Planning Category CFTC-SS-23 Resources Sufficient to Fulfil Obligations CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective FFIEC-11 Business continuity planning and testing FFIEC-12 Disaster recovery procedures FFIEC-14 Critical service identification PCI-P2PE-11 Business continuity planning and testing PCI-P2PE-12 Disaster recovery procedures PCI-P2PE-14 Critical service identification PCI-PIN-13 Third-party dependency management PCI-PIN-14 Critical service identification PCI-PIN-15 Communication and escalation procedures PCI-SSF-12 Disaster recovery procedures PCI-SSF-14 Critical service identification PCI-SSF-15 Communication and escalation procedures SOC2-A1.1 A1.1 Managing processing capacity SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-A1.3 A1.3 Testing recovery plan procedures IM8-DAT.2 Data Protection IM8-DSS.2 Service Reliability Standards IM8-RES.4 Resilience Testing CPS234-14 Definition of Information Security Roles and Responsibilities CPS234-15 Information Security Capability 62351-12 Resilience and security recommendations for DER 62351-13 Cyber-physical generation and storage resilience 7.11 Supporting utilities 8.6 Capacity management 7.11 Supporting utilities 8.6 Capacity management 27031-8.1 Exercising and Testing 27031-B High availability embedded systems NISTPF-6 Protect-P Data Security (PR.DS-P) NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection OSFIB13-4 Third-Party Risk Management and Cloud OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM SASB-1 Business Model + Innovation (BMI) SASB-BMI-2 Business Model Resilience SOCI-S30BC Notification of critical cyber security incidents (12 hours) SOCI-S30BD Notification of other cyber security incidents (72 hours) OB-API.4 MI Reporting Specification OB-OPS.1 API Availability Requirements SEMD-CS-3 Cyber Resilience SEMD-ER-1 Emergency Exercise and Testing CPS230-P25 Information and Technology Capability and Asset Health ASD37-20 Multi-factor authentication (Essential) BS65000-RM-03 Leadership and Culture COBIT-BAI04 Managed availability and capacity RMD-1 Reference Data Management CAT-D5-4 Resilience planning and testing 8.3.4 Resource requirements ISO20000-03 Capacity and availability management ISO-25012-4.13 Availability 27007-5.4 Establishing the Programme Resources A.4 Resources for AI systems ITIL4-03 Capacity and availability management Art.21.2.c Business continuity, backup management, disaster recovery and crisis management PR.DS-4 PR.DS-4: Adequate capacity to ensure availability is maintained PR.DS-4 PR.DS-4: Adequate capacity to ensure availability is maintained ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel PSDTWO-2 SCA Exemptions and Risk-Based Authentication SOC-CY-A1 Availability Commitments SSAE18-A1.1 A1.1 - Availability Commitments and Requirements SAPAIA-2 Right of Access and Request Processes UKAI-3 Bias Detection, Fairness, Validation UKOPRES-5 Third-Party Risk, Concentration Risk CERT-1 RRA Certification to EPA Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.IR-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.