simpl.
Cybersecurity GRC 18 items

NIST Cybersecurity Framework 2.0 Program Assessment

Assesses a cybersecurity program against the six NIST CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.

NIST CSF 2.0

Free PDF · enter your email to download.

Govern (GV)

  • Is a cybersecurity risk management strategy established and communicated? *
  • Are cybersecurity roles, responsibilities, and authorities defined and enforced? *
  • Is organizational cybersecurity policy established and communicated? *
  • Is cybersecurity supply chain risk management integrated into governance? *

Identify (ID)

  • Are hardware, software, and data assets inventoried and managed? *
  • Are cybersecurity risks to assets identified, analyzed, and prioritized? *
  • Are improvements identified across all CSF functions on an ongoing basis? *

Protect (PR)

  • Is identity management, authentication, and access control implemented? *
  • Is security awareness and training provided to the workforce? *
  • Is data-at-rest and data-in-transit protected consistent with the risk strategy? *
  • Are platforms managed consistent with policy (configuration, maintenance)? *

Detect (DE)

  • Are networks, assets, and systems continuously monitored for adverse events? *
  • Are potential cybersecurity incidents analyzed to characterize events? *

Respond (RS)

  • Is an incident response plan executed and coordinated during and after an incident? *
  • Are incidents analyzed to support response and recovery activities? *
  • Are response activities communicated to internal and external stakeholders? *

Recover (RC)

  • Is a recovery plan executed to restore systems affected by incidents? *
  • Are recovery activities and progress communicated to stakeholders? *

Download the full NIST Cybersecurity Framework 2.0 Program Assessment checklist

Get it as a clean, printable PDF — free.