Frameworks / NIST Cybersecurity Framework 2.0 / NIST-CSF-PR.PS-03 NIST Cybersecurity Framework 2.0
PR - Protect
NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-03: Hardware is maintained, replaced, and removed commensurate with risk Hardware is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 82 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CM-8(1) Updates During Installation and Removal MA-2 Controlled Maintenance MA-6 Timely Maintenance (MA-6) PE-16 Delivery and Removal SA-22 Unsupported System Components (SA-22) SR-11 Component Authenticity (SR-11) CM-8(1) Updates During Installation and Removal MA-2 Controlled Maintenance MA-6 Timely Maintenance (MA-6) PE-16 Delivery and Removal SA-22 Unsupported System Components (SA-22) SR-11 Component Authenticity (SR-11) SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure SOC2-C1.2 C1.2 Disposing of confidential information SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.5 CC6.5 Protecting data on assets until disposal SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure SOC2-P4.3 P4.3 Securely disposing of personal information 7.10 Storage media 7.13 Equipment maintenance 7.14 Secure disposal or re-use of equipment 8.1 User endpoint devices 8.10 Information deletion CIS-1.2 Address Unauthorized Assets CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-15.7 Securely Decommission Service Providers CIS-3.5 Securely Dispose of Data ISM-1550 IT equipment disposal processes and procedures ISM-1753 Replacing unsupported internet-facing network devices ISM-1982 Replacing unsupported networked IT equipment 7.13 Equipment maintenance 7.14 Secure disposal or re-use of equipment 8.10 Information deletion 12.3.4 12.3.4 Annual review of hardware and software technologies 9.4.6 9.4.6 Destruction of hard-copy materials 9.4.7 9.4.7 Destruction of electronic media ANSSI-HYG-34 Define an Update Policy for Information System Components ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems CCM-DCS-01 Off-Site Equipment Disposal Policy and Procedures CCM-DCS-06 Assets Cataloguing and Tracking PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets is performed and logged in a timely manner, with approved and controlled tools PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools E8-PATCHOS-ML3 Patch Operating Systems (ML3) ASD37-19 Patch operating systems (Essential) Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in PR - Protect NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated NIST-CSF-PR.AA-04 Identity assertions are protected, conveyed, and verified NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind NIST-CSF-PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done? NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 82 it maps to, and the evidence behind each claim, over MCP and REST.