NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.IR-04: Adequate resource capacity to ensure availability is maintained

Adequate resource capacity to ensure availability is maintained. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 122 controls across 56 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 6 controls

  • AU-4 Audit Log Storage Capacity
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • MA-6 Timely Maintenance (MA-6)
  • SC-5 Denial-of-Service Protection

FedRAMP Moderate · 6 controls

  • AU-4 Audit Log Storage Capacity
  • CP-7(2) Alternate Processing Site | Accessibility (CP-7(2))
  • CP-7(3) Alternate Processing Site | Priority of Service (CP-7(3))
  • CP-8(1) Telecommunications Services | Priority of Service Provisions (CP-8(1))
  • MA-6 Timely Maintenance (MA-6)
  • SC-5 Denial-of-Service Protection
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • ISM-1431 Discussing DoS mitigation with cloud providers
  • ISM-1579 Verifying CSP dynamic scaling for demand spikes
  • ISM-1581 Real-time capacity and availability monitoring

C5 (Germany) · 3 controls

  • C5-OPS-01 Capacity Management - Planning
  • C5-OPS-02 Capacity Management - Monitoring
  • C5-OPS-03 Capacity Management - Controlling of Resources
  • CFTC-SS-12 Capacity and Performance Planning Category
  • CFTC-SS-23 Resources Sufficient to Fulfil Obligations
  • CFTC-SS-26 Own Resources or Contractual Arrangements to Meet the Recovery Objective
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

NIST SP 800-53 Rev 5 · 3 controls

PCI P2PE · 3 controls

  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification

PCI PIN Security · 3 controls

  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures

PCI SSF · 3 controls

  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures

SOC 2 · 3 controls

  • SOC2-A1.1 A1.1 Managing processing capacity
  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.4 Resilience Testing

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO 27001:2022 · 2 controls

  • 7.11 Supporting utilities
  • 8.6 Capacity management

ISO 27002:2022 · 2 controls

  • 7.11 Supporting utilities
  • 8.6 Capacity management

ISO/IEC 27031:2011 · 2 controls

  • 27031-8.1 Exercising and Testing
  • 27031-B High availability embedded systems
  • NISTPF-6 Protect-P Data Security (PR.DS-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection

OSFI B-13 · 2 controls

  • OSFIB13-4 Third-Party Risk Management and Cloud
  • OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination

Open Banking Security · 2 controls

  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-2 Business Model Resilience
  • SOCI-S30BC Notification of critical cyber security incidents (12 hours)
  • SOCI-S30BD Notification of other cyber security incidents (72 hours)
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • SEMD-CS-3 Cyber Resilience
  • SEMD-ER-1 Emergency Exercise and Testing
  • CPS230-P25 Information and Technology Capability and Asset Health
  • ASD37-20 Multi-factor authentication (Essential)
  • BS65000-RM-03 Leadership and Culture

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • RMD-1 Reference Data Management

DORA · 1 control

  • CAT-D5-4 Resilience planning and testing

ISO 22301:2019 · 1 control

  • 8.3.4 Resource requirements

ISO 27701:2019 · 1 control

  • ISO20000-03 Capacity and availability management
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 42001:2023 · 1 control

  • A.4 Resources for AI systems

ITIL 4 · 1 control

  • ITIL4-03 Capacity and availability management

NIS2 Directive · 1 control

  • Art.21.2.c Business continuity, backup management, disaster recovery and crisis management
  • PR.DS-4 PR.DS-4: Adequate capacity to ensure availability is maintained
  • PR.DS-4 PR.DS-4: Adequate capacity to ensure availability is maintained
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

PCI DSS 4.0 · 1 control

  • 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • SOC-CY-A1 Availability Commitments
  • SSAE18-A1.1 A1.1 - Availability Commitments and Requirements
  • SAPAIA-2 Right of Access and Request Processes
  • UKAI-3 Bias Detection, Fairness, Validation
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • CERT-1 RRA Certification to EPA

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.IR-04 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.