Cybersecurity GRC 18 items
NIST Cybersecurity Framework 2.0 Program Assessment
Assesses a cybersecurity program against the six NIST CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.
NIST CSF 2.0
Free PDF · enter your email to download.
Govern (GV)
- Is a cybersecurity risk management strategy established and communicated? *
- Are cybersecurity roles, responsibilities, and authorities defined and enforced? *
- Is organizational cybersecurity policy established and communicated? *
- Is cybersecurity supply chain risk management integrated into governance? *
Identify (ID)
- Are hardware, software, and data assets inventoried and managed? *
- Are cybersecurity risks to assets identified, analyzed, and prioritized? *
- Are improvements identified across all CSF functions on an ongoing basis? *
Protect (PR)
- Is identity management, authentication, and access control implemented? *
- Is security awareness and training provided to the workforce? *
- Is data-at-rest and data-in-transit protected consistent with the risk strategy? *
- Are platforms managed consistent with policy (configuration, maintenance)? *
Detect (DE)
- Are networks, assets, and systems continuously monitored for adverse events? *
- Are potential cybersecurity incidents analyzed to characterize events? *
Respond (RS)
- Is an incident response plan executed and coordinated during and after an incident? *
- Are incidents analyzed to support response and recovery activities? *
- Are response activities communicated to internal and external stakeholders? *
Recover (RC)
- Is a recovery plan executed to restore systems affected by incidents? *
- Are recovery activities and progress communicated to stakeholders? *
Download the full NIST Cybersecurity Framework 2.0 Program Assessment checklist
Get it as a clean, printable PDF — free.
