April 16, 2018
Function
Cybersecurity Framework
Version 1.1
Category
Subcategory
Informative References
management of cybersecurity
risk.
ID.GV-2: Cybersecurity roles and
responsibilities are coordinated and aligned
with internal roles and external partners
CIS CSC 19
COBIT 5 APO01.02, APO10.03, APO13.02,
DSS05.04
ISA 62443-2-1:2009 4.3.2.3.3
ISO/IEC 27001:2013 A.6.1.1, A.7.2.1, A.15.1.1
NIST SP 800-53 Rev. 4 PS-7, PM-1, PM-2
ID.GV-3: Legal and regulatory
requirements regarding cybersecurity,
including privacy and civil liberties
obligations, are understood and managed
CIS CSC 19
COBIT 5 BAI02.01, MEA03.01, MEA03.04
ISA 62443-2-1:2009 4.4.3.7
ISO/IEC 27001:2013 A.18.1.1, A.18.1.2,
A.18.1.3, A.18.1.4, A.18.1.5
NIST SP 800-53 Rev. 4 -1 controls from all
security control families
ID.GV-4: Governance and risk
management processes address
cybersecurity risks
COBIT 5 EDM03.02, APO12.02, APO12.05,
DSS04.02
ISA 62443-2-1:2009 4.2.3.1, 4.2.3.3, 4.2.3.8,
4.2.3.9, 4.2.3.11, 4.3.2.4.3, 4.3.2.6.3
ISO/IEC 27001:2013 Clause 6
NIST SP 800-53 Rev. 4 SA-2, PM-3, PM-7, PM9, PM-10, PM-11
ID.RA-1: Asset vulnerabilities are
identified and documented
CIS CSC 4
COBIT 5 APO12.01, APO12.02, APO12.03,
APO12.04, DSS05.01, DSS05.02
ISA 62443-2-1:2009 4.2.3, 4.2.3.7, 4.2.3.9,
4.2.3.12
ISO/IEC 27001:2013 A.12.6.1, A.18.2.3
NIST SP 800-53 Rev. 4 CA-2, CA-7, CA-8, RA3, RA-5, SA-5, SA-11, SI-2, SI-4, SI-5
ID.RA-2: Cyber threat intelligence is
received from information sharing forums
and sources
CIS CSC 4
COBIT 5 BAI08.01
ISA 62443-2-1:2009 4.2.3, 4.2.3.9, 4.2.3.12
ISO/IEC 27001:2013 A.6.1.4
NIST SP 800-53 Rev. 4 SI-5, PM-15, PM-16
Risk Assessment (ID.RA): The
organization understands the
cybersecurity risk to
organizational operations
(including mission, functions,
image, or reputation),
organizational assets, and
individuals.
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
26