NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-02: Software is maintained, replaced, and removed commensurate with risk

Software is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 94 controls across 31 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 14 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-2.2 Ensure Authorized Software is Currently Supported
  • CIS-2.3 Address Unauthorized Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

NIST SP 800-53 Rev 5 · 8 controls

  • ASD37-02 Patch applications (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-19 Patch operating systems (Essential)

ISO 27002:2022 · 5 controls

  • 7.14 Secure disposal or re-use of equipment
  • 8.19 Installation of software on operational systems
  • 8.32 Change management
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ISO 27701:2019 · 5 controls

  • 6.11 Systems acquisition, development and maintenance
  • 6.11.2 Security in development and support processes
  • 6.4.3 Termination and change of employment
  • 6.9.5 Control of operational software
  • 6.9.6 Technical vulnerability management

PCI DSS 4.0 · 5 controls

  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.6.1 12.6.1 Formal security awareness program
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 6.3.2 6.3.2 Inventory of bespoke software and components
  • 6.3.3 6.3.3 Timely installation of security patches
  • ISM-0304 Removing unsupported applications
  • ISM-1143 Patch management processes and procedures
  • ISM-1501 Replacing unsupported operating systems
  • ISM-1695 OS patches for workstations and internal systems within one month

CMMC 2.0 · 4 controls

UK Cyber Essentials · 4 controls

  • CE-SU.1 Software Licensed and Supported
  • CE-SU.2 Automatic Updates Enabled Where Possible
  • CE-SU.3 Critical and High Updates within 14 Days
  • CE-SU.4 Remove Out-of-Support Software
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • AM-3 Ensure security of asset lifecycle management
  • ASBv3-ES-3 Ensure anti-malware software and signatures are updated
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities

FedRAMP High · 3 controls

  • CM-8(1) Updates During Installation and Removal
  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation

FedRAMP Moderate · 3 controls

  • CM-8(1) Updates During Installation and Removal
  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation

ISO 27001:2022 · 3 controls

  • 8.19 Installation of software on operational systems
  • 8.8 Management of technical vulnerabilities
  • 8.9 Configuration management

ACSC Essential Eight · 2 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • PR.IP-12 PR.IP-12: A vulnerability management plan is developed and implemented
  • PR.MA-2 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access
  • PR.IP-12 PR.IP-12: A vulnerability management plan is developed and implemented
  • PR.MA-2 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

  • CPS230-P25 Information and Technology Capability and Asset Health
  • AUCDR-IS-4 Formal vulnerability management program

C5 (Germany) · 1 control

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept

DORA · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

NIST SP 800-172 · 1 control

  • 3.4.1e Authoritative Source for Software and Firmware

NIST SP 800-218 · 1 control

SOC 2 · 1 control

  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-02 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 94 it maps to, and the evidence behind each claim, over MCP and REST.