NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-03: Hardware is maintained, replaced, and removed commensurate with risk

Hardware is maintained, replaced, and removed commensurate with risk. Control from NIST Cybersecurity Framework 2.0 framework, domain: PR - Protect.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 82 controls across 27 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 10 controls

FedRAMP High · 6 controls

  • CM-8(1) Updates During Installation and Removal
  • MA-2 Controlled Maintenance
  • MA-6 Timely Maintenance (MA-6)
  • PE-16 Delivery and Removal
  • SA-22 Unsupported System Components (SA-22)
  • SR-11 Component Authenticity (SR-11)

FedRAMP Moderate · 6 controls

  • CM-8(1) Updates During Installation and Removal
  • MA-2 Controlled Maintenance
  • MA-6 Timely Maintenance (MA-6)
  • PE-16 Delivery and Removal
  • SA-22 Unsupported System Components (SA-22)
  • SR-11 Component Authenticity (SR-11)

SOC 2 · 6 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SOC2-P4.3 P4.3 Securely disposing of personal information

ISO 27002:2022 · 5 controls

  • 7.10 Storage media
  • 7.13 Equipment maintenance
  • 7.14 Secure disposal or re-use of equipment
  • 8.1 User endpoint devices
  • 8.10 Information deletion

CIS Controls v8 · 4 controls

  • CIS-1.2 Address Unauthorized Assets
  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-15.7 Securely Decommission Service Providers
  • CIS-3.5 Securely Dispose of Data

CMMC 2.0 · 4 controls

NIST SP 800-171 Rev 3 · 4 controls

  • ISM-1550 IT equipment disposal processes and procedures
  • ISM-1753 Replacing unsupported internet-facing network devices
  • ISM-1982 Replacing unsupported networked IT equipment

C5 (Germany) · 3 controls

HIPAA Security Rule · 3 controls

ISO 27001:2022 · 3 controls

  • 7.13 Equipment maintenance
  • 7.14 Secure disposal or re-use of equipment
  • 8.10 Information deletion

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-66 Rev 2 · 3 controls

PCI DSS 4.0 · 3 controls

  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 9.4.6 9.4.6 Destruction of hard-copy materials
  • 9.4.7 9.4.7 Destruction of electronic media
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • CCM-DCS-01 Off-Site Equipment Disposal Policy and Procedures
  • CCM-DCS-06 Assets Cataloguing and Tracking
  • PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition
  • PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets is performed and logged in a timely manner, with approved and controlled tools
  • PR.DS-3 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition
  • PR.MA-1 PR.MA-1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools
  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)
  • ASD37-19 Patch operating systems (Essential)

ISO 27701:2019 · 1 control

NIS2 Directive · 1 control

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure

UK Cyber Essentials · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.PS-03 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 82 it maps to, and the evidence behind each claim, over MCP and REST.