CSF 2.0 outcome: analysis is performed to establish what has taken place during an incident and the root cause of the incident. Priority High. R1: determine the sequence of events during the incident and the assets and resources involved in each. R2: try to determine the vulnerabilities, threats and threat actors directly or indirectly involved. R3: analyze the incident for underlying or systemic root causes. R4: check any deployed cyber deception technology for more information on attacker behaviour. N1: this can also show risk management weaknesses to fix so that similar incidents do not recur.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.