Govern
Strategy, policy, accountability, vendor risk, compliance drivers, leadership reporting, and cybersecurity roles.
CISO-led NIST Cybersecurity Framework implementation for Orange County and Southern California organizations that need practical governance, control mapping, remediation priorities, evidence, and executive-ready reporting.
NIST CSF implementation should not stop at a checklist. OC Security Audit connects governance, technical controls, business risk, documentation, and remediation planning so your organization can improve security maturity and prepare for client reviews, vendor questionnaires, cyber insurance, and compliance readiness.
Gap analysis: compare current practices against NIST CSF 2.0 outcomes and identify missing evidence.
Roadmap: rank remediation by exposure, business impact, ownership, and implementation effort.
Documentation: build risk registers, evidence lists, policy gaps, and executive summaries.
Validation: support follow-up review so improvements can be measured and explained.

OC Security Audit maps each function to real business systems, users, controls, evidence, and owners.
Strategy, policy, accountability, vendor risk, compliance drivers, leadership reporting, and cybersecurity roles.
Assets, sensitive data, business processes, vulnerabilities, third-party dependencies, and risk context.
MFA, least privilege, secure configuration, patching, encryption, training, backup, and access controls.
Logging, monitoring, alerting, anomalous activity, visibility, and escalation paths for suspicious behavior.
Incident response playbooks, communications, containment, evidence preservation, and decision workflows.
Recovery planning, restore testing, business continuity, lessons learned, and resilience improvement.
The process is designed for organizations that need clear priorities, technical depth, and documentation that can support leadership and audit conversations.
Define business objectives, sensitive data, systems, users, compliance drivers, service dependencies, and deadlines.
Review governance, identity, endpoints, firewalls, network architecture, Microsoft 365, Azure, logging, backups, and evidence.
Map current controls to NIST CSF 2.0 outcomes and identify process, control, documentation, and evidence gaps.
Rank gaps by business impact, likelihood, exposure, implementation effort, compliance relevance, and operational dependency.
Create a practical roadmap with owners, evidence expectations, sequencing, business justification, and validation milestones.
Support follow-up review, executive reporting, evidence readiness, and recurring maturity improvement planning.
OC Security Audit keeps the NIST assessment, control mapping, and compliance-readiness work distinct. When findings require implementation, troubleshooting, project delivery, network design, Microsoft 365 or Azure administration, backup improvements, or managed IT support, related work can continue through IT Perfection.
For remediation projects, patching follow-through, help desk support, and ongoing operations.
For Microsoft 365, Azure, network infrastructure, firewall/VPN, and monitoring improvements.
Microsoft 365 managed services | Azure managed services | Network infrastructure
For backup planning, disaster recovery readiness, restore testing, and operational continuity support.
For endpoint support, monitoring, maintenance, and day-to-day troubleshooting after audit findings are prioritized.
Cybersecurity posture summary, NIST readiness scorecard, top risks, leadership action plan, investment priorities, and compliance overview.
Technical findings, vulnerability summary, identity and access findings, firewall/network findings, and Microsoft 365/Azure security findings.
NIST gap analysis, control mapping, risk register, policy gap list, evidence checklist, remediation roadmap, and validation checklist.
This matrix preserves the original 84 baseline checks across NIST CSF 2.0 functions and control areas. Use the internal scrollbars to review all rows and columns without making the whole page extremely long.
Organizational context, risk management, policy, oversight, supply chain, and accountability.
Assets, data, dependencies, vulnerabilities, business processes, and exposure visibility.
Access control, awareness, data protection, platform security, resilience, and secure configuration.
Monitoring, investigation, incident management, communication, recovery, and improvement.
Full matrix preserved: 85 rows including header, 17 columns, internal vertical and horizontal scrollbars.
| # | Control ID | CSF Function | NIST Category | Control Type | Control Domain | Recommended Control / Checklist Item | Evidence / Artifact to Review | Primary Owner | Risk Impact | Likelihood | Risk Score | Priority | Target Maturity | Assessment Status | Review Frequency | Source / Mapping |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | GV.OC-01 | Govern | Organizational Context | Administrative | Business Context | Document critical business objectives, mission-critical services, legal/regulatory expectations, and cybersecurity dependencies. | Business impact analysis, system inventory, compliance requirements register, executive approval. | CISO / CTO | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / major change | NIST CSF 2.0 |
| 2 | GV.OC-02 | Govern | Organizational Context | Administrative | Stakeholders | Identify internal and external stakeholders with cybersecurity expectations, including customers, vendors, regulators, insurers, and executives. | Stakeholder register, vendor requirements, insurance questionnaire, customer security requirements. | CISO / Compliance | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 3 | GV.OC-03 | Govern | Organizational Context | Administrative | Risk Tolerance | Define cybersecurity risk appetite and acceptable risk thresholds for business operations and technology decisions. | Risk appetite statement, risk acceptance criteria, board/leadership approval. | Executive Leadership | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 4 | GV.OC-04 | Govern | Organizational Context | Administrative | Dependency Mapping | Map business-critical dependencies, including cloud platforms, MSPs, ISPs, SaaS vendors, facilities, and managed security services. | Dependency map, vendor list, service criticality rating. | IT Manager / Procurement | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 5 | GV.RM-01 | Govern | Risk Management Strategy | Administrative | Risk Management | Establish a cybersecurity risk management strategy aligned with business objectives and enterprise risk management. | Risk management plan, risk register methodology, escalation thresholds. | CISO / vCISO | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 6 | GV.RM-02 | Govern | Risk Management Strategy | Administrative | Risk Register | Maintain a cybersecurity risk register with ratings, treatment decisions, owners, due dates, and evidence of closure. | Risk register, remediation tracker, risk acceptance records. | CISO / IT Manager | 5 | 5 | 25 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 7 | GV.RM-03 | Govern | Risk Management Strategy | Administrative | Risk Prioritization | Prioritize remediation by business impact, likelihood, exposure, exploitability, compliance relevance, and resource requirements. | Risk scoring matrix, remediation roadmap, vulnerability management dashboard. | CISO / Security Engineer | 5 | 5 | 25 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 8 | GV.RR-01 | Govern | Roles Responsibilities & Authorities | Administrative | Accountability | Assign cybersecurity roles, responsibilities, decision rights, and escalation paths across leadership, IT, security, HR, legal, and operations. | RACI matrix, job descriptions, incident escalation chart. | Executive Leadership / HR | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 9 | GV.RR-02 | Govern | Roles Responsibilities & Authorities | Administrative | Segregation of Duties | Define and enforce segregation of duties for administrative access, financial systems, security administration, and change approvals. | Access review records, admin role assignments, change approval workflow. | IT Manager / Compliance | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 10 | GV.RR-03 | Govern | Roles Responsibilities & Authorities | Administrative | Security Leadership | Designate a CISO, vCISO, security lead, or accountable executive for cybersecurity governance and reporting. | Security leadership charter, meeting minutes, reporting cadence. | CEO / Executive Leadership | 5 | 3 | 15 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 11 | GV.PO-01 | Govern | Policy | Administrative | Security Policies | Maintain approved cybersecurity policies covering acceptable use, access control, MFA, data protection, incident response, backup, vendor risk, and change management. | Policy library, approval records, annual review evidence. | CISO / Compliance | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 12 | GV.PO-02 | Govern | Policy | Administrative | Policy Exceptions | Track security policy exceptions, compensating controls, risk acceptance, expiration dates, and approval authority. | Exception register, risk acceptance form, compensating control evidence. | CISO / IT Manager | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 13 | GV.OV-01 | Govern | Oversight | Administrative | Security Metrics | Report cybersecurity metrics to leadership, including risk status, vulnerabilities, incidents, training completion, audit findings, and remediation progress. | Executive dashboard, board report, KPI/KRI report. | CISO / vCISO | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 14 | GV.OV-02 | Govern | Oversight | Administrative | Independent Review | Perform periodic independent security audits, risk assessments, penetration testing, or compliance readiness reviews. | Audit report, assessment report, corrective action plan. | Executive Leadership / CISO | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 15 | GV.OV-03 | Govern | Oversight | Administrative | Continuous Improvement | Review cybersecurity program effectiveness and update priorities based on incidents, threat intelligence, business changes, and audit results. | Lessons learned, program review minutes, updated roadmap. | CISO / IT Manager | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 16 | GV.SC-01 | Govern | Cybersecurity Supply Chain Risk Management | Administrative | Vendor Risk Program | Establish a vendor and third-party cybersecurity risk management program for suppliers, SaaS, MSPs, cloud providers, and critical service partners. | Vendor risk policy, questionnaires, supplier inventory. | Procurement / CISO | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 17 | GV.SC-02 | Govern | Cybersecurity Supply Chain Risk Management | Administrative | Vendor Due Diligence | Perform cybersecurity due diligence before onboarding critical vendors and renewing contracts. | Security questionnaires, SOC reports, contract security clauses. | Procurement / Legal | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 18 | GV.SC-03 | Govern | Cybersecurity Supply Chain Risk Management | Administrative | Vendor Access Control | Limit, monitor, and periodically review third-party access to networks, cloud systems, data, and administrative consoles. | Vendor access list, access logs, MFA evidence, review sign-off. | IT Manager / Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 19 | GV.SC-04 | Govern | Cybersecurity Supply Chain Risk Management | Administrative | Contractual Security | Include cybersecurity, privacy, incident notification, data handling, audit, and termination requirements in vendor contracts. | MSA/security addendum, DPA, incident notification SLA. | Legal / Procurement | 4 | 3 | 12 | Medium | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 20 | ID.AM-01 | Identify | Asset Management | Technical | Hardware Assets | Maintain a current inventory of servers, laptops, desktops, network devices, firewalls, wireless access points, mobile devices, and IoT assets. | Asset inventory, EDR/MDM export, network scan. | IT Manager | 5 | 5 | 25 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 21 | ID.AM-02 | Identify | Asset Management | Technical | Software Assets | Maintain a current inventory of operating systems, applications, SaaS platforms, licenses, versions, and unsupported software. | Software inventory, license report, vulnerability scan output. | IT Manager | 4 | 5 | 20 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 22 | ID.AM-03 | Identify | Asset Management | Administrative | Data Assets | Identify sensitive data types, data owners, storage locations, retention needs, and data flow between systems and vendors. | Data inventory, data flow diagram, data classification register. | Data Owner / Compliance | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 23 | ID.AM-04 | Identify | Asset Management | Technical | External Systems | Identify externally facing systems, public IP addresses, domains, cloud workloads, VPN portals, remote access systems, and internet-exposed applications. | External attack surface scan, DNS inventory, firewall NAT list. | Security Engineer | 5 | 5 | 25 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 24 | ID.AM-05 | Identify | Asset Management | Administrative | Asset Ownership | Assign business and technical owners for critical systems, applications, data repositories, and cloud services. | Asset owner register, CMDB ownership fields. | IT Manager / Business Owners | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 25 | ID.AM-06 | Identify | Asset Management | Physical | Facilities & Physical Assets | Inventory facilities, secure areas, wiring closets, server rooms, backup storage locations, and physical security dependencies. | Facility asset list, physical security review, access badge logs. | Facilities / IT Manager | 4 | 3 | 12 | Medium | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 26 | ID.RA-01 | Identify | Risk Assessment | Technical | Vulnerability Identification | Perform recurring vulnerability assessments across internal networks, external systems, endpoints, servers, cloud platforms, and applications. | Vulnerability scan reports, remediation tickets, validation scans. | Security Engineer | 5 | 5 | 25 | Critical | Defined | Baseline Control | Monthly / Quarterly | NIST CSF 2.0 |
| 27 | ID.RA-02 | Identify | Risk Assessment | Technical | Threat Intelligence | Use threat intelligence, vendor advisories, CISA alerts, and security bulletins to identify relevant threats and emerging risks. | Threat bulletin review, advisory tracking, change records. | Security Engineer / CISO | 4 | 4 | 16 | High | Defined | Baseline Control | Weekly | NIST CSF 2.0 |
| 28 | ID.RA-03 | Identify | Risk Assessment | Administrative | Risk Analysis | Analyze likelihood and impact of identified risks, including financial, operational, legal, reputational, and safety effects. | Risk assessment report, scoring matrix, executive risk summary. | CISO / vCISO | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 29 | ID.RA-04 | Identify | Risk Assessment | Administrative | Risk Treatment | Assign risk treatment decisions: mitigate, transfer, avoid, or accept, with documented approval for accepted risks. | Risk treatment plan, risk acceptance forms, cyber insurance records. | Executive Leadership / CISO | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 30 | ID.RA-05 | Identify | Risk Assessment | Technical | Penetration Testing | Perform penetration testing or targeted security validation for internet-facing systems, critical applications, and high-risk network zones. | Penetration test report, retest evidence, remediation plan. | CISO / Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / major change | NIST CSF 2.0 |
| 31 | ID.IM-01 | Identify | Improvement | Administrative | Improvement Roadmap | Maintain a prioritized cybersecurity improvement roadmap based on assessment findings, incident lessons, audit gaps, and business priorities. | Roadmap, project plan, risk reduction milestones. | CISO / IT Manager | 4 | 4 | 16 | High | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 32 | ID.IM-02 | Identify | Improvement | Administrative | Lessons Learned | Update controls, procedures, training, and tooling based on incidents, tabletop exercises, audit results, and recovery tests. | Lessons learned report, updated procedures, training updates. | CISO / Incident Manager | 4 | 4 | 16 | High | Defined | Baseline Control | After event | NIST CSF 2.0 |
| 33 | PR.AA-01 | Protect | Identity Management Authentication & Access Control | Technical | Identity Inventory | Maintain an inventory of user accounts, service accounts, privileged accounts, shared accounts, and external identities. | Identity export, account review report, service account register. | IT Manager / IAM Admin | 5 | 5 | 25 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 34 | PR.AA-02 | Protect | Identity Management Authentication & Access Control | Technical | MFA Enforcement | Enforce multi-factor authentication for remote access, cloud services, email, VPN, privileged accounts, and administrative consoles. | MFA policy screenshots, conditional access report, VPN settings. | IAM Admin / Security Engineer | 5 | 5 | 25 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 35 | PR.AA-03 | Protect | Identity Management Authentication & Access Control | Technical | Least Privilege | Apply least privilege access and role-based access control to systems, files, applications, databases, cloud platforms, and security tools. | Access control matrix, role assignments, permission review. | IT Manager / Data Owners | 5 | 4 | 20 | Critical | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 36 | PR.AA-04 | Protect | Identity Management Authentication & Access Control | Technical | Privileged Access Management | Protect administrator accounts using separate admin identities, just-in-time access, strong MFA, logging, and approval workflows. | Admin account list, PAM logs, privileged access review. | Security Engineer / IAM Admin | 5 | 4 | 20 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 37 | PR.AA-05 | Protect | Identity Management Authentication & Access Control | Administrative | Joiner-Mover-Leaver | Implement onboarding, transfer, and termination procedures to grant, modify, and remove access promptly. | HR ticket workflow, termination checklist, access removal evidence. | HR / IT Manager | 5 | 4 | 20 | Critical | Defined | Baseline Control | Per employee change | NIST CSF 2.0 |
| 38 | PR.AA-06 | Protect | Identity Management Authentication & Access Control | Technical | Remote Access Security | Secure VPN, RDP, SSH, cloud admin portals, and remote management tools with MFA, conditional access, logging, and restricted source access. | VPN config, remote access logs, firewall rules, MFA evidence. | Network Engineer | 5 | 5 | 25 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 39 | PR.AT-01 | Protect | Awareness & Training | Administrative | Security Awareness | Deliver cybersecurity awareness training covering phishing, passwords, data handling, reporting incidents, social engineering, and acceptable use. | Training completion report, curriculum, employee attestations. | HR / CISO | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / onboarding | NIST CSF 2.0 |
| 40 | PR.AT-02 | Protect | Awareness & Training | Administrative | Role-Based Training | Provide role-based security training for administrators, developers, executives, helpdesk, finance, HR, and personnel handling sensitive data. | Role-based training records, admin training evidence. | CISO / Department Heads | 4 | 3 | 12 | Medium | Defined | Baseline Control | Annual | NIST CSF 2.0 |
| 41 | PR.AT-03 | Protect | Awareness & Training | Administrative | Phishing Simulation | Conduct phishing simulations or practical exercises and remediate repeat failure patterns with targeted training. | Phishing campaign report, coaching records, trend metrics. | CISO / Security Engineer | 4 | 4 | 16 | High | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 42 | PR.DS-01 | Protect | Data Security | Technical | Data Classification | Classify data by sensitivity and apply handling requirements for confidential, regulated, customer, financial, and operational data. | Data classification policy, labeled repositories, data owner signoff. | Compliance / Data Owners | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 43 | PR.DS-02 | Protect | Data Security | Technical | Encryption at Rest | Encrypt sensitive data at rest on endpoints, servers, databases, backups, removable media, and cloud storage. | Encryption reports, BitLocker/FileVault status, storage encryption settings. | IT Manager / Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 44 | PR.DS-03 | Protect | Data Security | Technical | Encryption in Transit | Use secure protocols and encryption for email, VPN, web applications, file transfers, APIs, and administrative sessions. | TLS configuration, VPN settings, certificate inventory, scan report. | Network Engineer / App Owner | 5 | 4 | 20 | Critical | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 45 | PR.DS-04 | Protect | Data Security | Technical | Data Loss Prevention | Implement controls to detect or prevent unauthorized sharing, exfiltration, or exposure of sensitive data. | DLP policy, alerts, Microsoft Purview settings, sharing reports. | Security Engineer / Compliance | 5 | 4 | 20 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 46 | PR.DS-05 | Protect | Data Security | Administrative | Retention & Disposal | Define data retention, secure disposal, media sanitization, and destruction requirements for physical and digital records. | Retention schedule, disposal certificates, media sanitization logs. | Compliance / Records Manager | 4 | 3 | 12 | Medium | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 47 | PR.PS-01 | Protect | Platform Security | Technical | Secure Configuration Baselines | Establish secure configuration baselines for endpoints, servers, network devices, firewalls, cloud resources, and Microsoft 365. | CIS benchmark report, configuration baseline, GPO/Intune policies. | Security Engineer / IT Manager | 5 | 5 | 25 | Critical | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 48 | PR.PS-02 | Protect | Platform Security | Technical | Patch Management | Patch operating systems, applications, firmware, network devices, and cloud workloads based on severity and exposure. | Patch compliance dashboard, maintenance records, vulnerability closure evidence. | IT Operations | 5 | 5 | 25 | Critical | Defined | Baseline Control | Monthly / emergency | NIST CSF 2.0 |
| 49 | PR.PS-03 | Protect | Platform Security | Technical | Endpoint Protection | Deploy and monitor endpoint protection, EDR/XDR, host firewall, tamper protection, and malware prevention on supported endpoints and servers. | EDR console report, endpoint coverage list, alert review records. | Security Engineer | 5 | 5 | 25 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 50 | PR.PS-04 | Protect | Platform Security | Technical | Change Management | Control security-impacting changes through documented testing, approval, implementation, rollback, and post-change validation. | Change tickets, approvals, rollback plans, post-change review. | IT Manager / Change Advisory | 4 | 4 | 16 | High | Defined | Baseline Control | Per change | NIST CSF 2.0 |
| 51 | PR.PS-05 | Protect | Platform Security | Technical | Secure Email | Protect email with SPF, DKIM, DMARC, anti-phishing policies, attachment scanning, impersonation protection, and mailbox auditing. | DNS records, email security policy, phishing protection report. | Microsoft 365 Admin | 5 | 5 | 25 | Critical | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 52 | PR.IR-01 | Protect | Technology Infrastructure Resilience | Technical | Backups | Maintain reliable backups for critical systems, cloud data, endpoints, databases, and configurations using protected and immutable options where feasible. | Backup job reports, retention settings, immutable backup configuration. | IT Manager / Backup Admin | 5 | 5 | 25 | Critical | Defined | Baseline Control | Daily / continuous | NIST CSF 2.0 |
| 53 | PR.IR-02 | Protect | Technology Infrastructure Resilience | Technical | Backup Testing | Test backup restoration for critical systems and verify recovery time objectives and recovery point objectives. | Restore test report, RTO/RPO results, remediation tickets. | IT Manager / Business Owners | 5 | 4 | 20 | Critical | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 54 | PR.IR-03 | Protect | Technology Infrastructure Resilience | Technical | Network Segmentation | Segment networks to separate servers, users, guests, IoT, payment systems, sensitive data, management interfaces, and backup infrastructure. | Network diagram, VLAN/firewall rules, segmentation test results. | Network Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 55 | PR.IR-04 | Protect | Technology Infrastructure Resilience | Physical | Physical Access Controls | Restrict physical access to server rooms, network closets, backup media, wiring areas, and critical infrastructure. | Badge logs, access list, camera coverage review, lock inspection. | Facilities / IT Manager | 4 | 3 | 12 | Medium | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 56 | PR.IR-05 | Protect | Technology Infrastructure Resilience | Physical | Environmental Controls | Protect critical infrastructure with UPS, surge protection, cooling, fire suppression, water detection, and environmental monitoring where appropriate. | UPS test, sensor logs, maintenance records, facilities review. | Facilities / IT Manager | 4 | 3 | 12 | Medium | Defined | Baseline Control | Quarterly | NIST CSF 2.0 |
| 57 | DE.CM-01 | Detect | Continuous Monitoring | Technical | Security Logging | Collect and retain security logs from firewalls, VPN, identity providers, endpoints, servers, cloud platforms, email, and critical applications. | SIEM/log retention settings, data source list, log ingestion dashboard. | Security Engineer | 5 | 5 | 25 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 58 | DE.CM-02 | Detect | Continuous Monitoring | Technical | Account Monitoring | Monitor risky sign-ins, impossible travel, failed logins, privilege escalation, disabled MFA, mailbox rules, and suspicious admin activity. | Identity protection alerts, sign-in logs, investigation tickets. | Security Engineer / IAM Admin | 5 | 5 | 25 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 59 | DE.CM-03 | Detect | Continuous Monitoring | Technical | Network Monitoring | Monitor network traffic, firewall events, IDS/IPS alerts, VPN usage, DNS activity, and suspicious lateral movement. | Firewall logs, IDS alerts, NDR reports, weekly review evidence. | Network Engineer / SOC | 5 | 4 | 20 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 60 | DE.CM-04 | Detect | Continuous Monitoring | Technical | Endpoint Monitoring | Monitor endpoint events, malware alerts, behavioral detections, isolation events, and device health. | EDR alert records, investigation notes, endpoint coverage report. | Security Engineer / SOC | 5 | 5 | 25 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 61 | DE.CM-05 | Detect | Continuous Monitoring | Technical | Cloud Monitoring | Monitor Microsoft 365, Entra ID, Azure, SaaS platforms, and cloud resources for risky configurations, alerts, and anomalous activity. | Cloud security dashboard, M365 alerts, Azure Defender/Security Center report. | Cloud Admin / Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 62 | DE.CM-06 | Detect | Continuous Monitoring | Technical | Data Monitoring | Monitor unauthorized data access, mass downloads, abnormal sharing, sensitive data movement, and storage exposure. | DLP alerts, access logs, sharing reports, investigation tickets. | Data Owner / Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 63 | DE.AE-01 | Detect | Adverse Event Analysis | Technical | Alert Triage | Define alert triage procedures with severity, ownership, escalation, false positive handling, and response timelines. | Triage procedure, queue metrics, SLA report. | SOC / Security Engineer | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 64 | DE.AE-02 | Detect | Adverse Event Analysis | Technical | Event Correlation | Correlate events across identity, endpoint, network, cloud, and application logs to detect multi-stage attacks. | SIEM correlation rules, detection use cases, incident evidence. | Security Engineer / SOC | 5 | 4 | 20 | Critical | Defined | Baseline Control | Continuous | NIST CSF 2.0 |
| 65 | DE.AE-03 | Detect | Adverse Event Analysis | Administrative | Detection Tuning | Review detection rules and tune alerts based on false positives, new threats, business changes, and incident lessons. | Detection tuning log, use-case review, change tickets. | SOC / CISO | 4 | 4 | 16 | High | Defined | Baseline Control | Monthly | NIST CSF 2.0 |
| 66 | RS.MA-01 | Respond | Incident Management | Administrative | Incident Response Plan | Maintain a documented incident response plan covering preparation, detection, analysis, containment, eradication, recovery, and lessons learned. | Incident response plan, approval record, annual review. | CISO / Incident Manager | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 67 | RS.MA-02 | Respond | Incident Management | Administrative | Incident Roles | Assign incident commander, technical leads, communications lead, legal/privacy contact, executive sponsor, and external support contacts. | Incident RACI, call tree, contact list, retainer records. | CISO / Executive Leadership | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 68 | RS.MA-03 | Respond | Incident Management | Administrative | Tabletop Exercises | Conduct tabletop exercises for ransomware, business email compromise, data breach, cloud compromise, and outage scenarios. | Exercise agenda, attendance, after-action report, improvement plan. | CISO / IT Manager | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / semiannual | NIST CSF 2.0 |
| 69 | RS.AN-01 | Respond | Incident Analysis | Technical | Investigation Procedures | Define investigation procedures for preserving evidence, collecting logs, determining scope, identifying root cause, and documenting timelines. | Forensic checklist, evidence handling procedure, incident analysis template. | Security Engineer / Incident Manager | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 70 | RS.AN-02 | Respond | Incident Analysis | Technical | Forensic Readiness | Ensure key systems retain sufficient logs and time synchronization to support incident investigation and legal/regulatory needs. | NTP settings, log retention policy, SIEM retention report. | Security Engineer | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 71 | RS.CO-01 | Respond | Incident Reporting & Communication | Administrative | Incident Communications | Prepare internal and external communication procedures for executives, employees, customers, vendors, legal counsel, insurers, and law enforcement. | Communication plan, notification templates, escalation matrix. | Communications Lead / Legal | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 72 | RS.CO-02 | Respond | Incident Reporting & Communication | Administrative | Regulatory & Contractual Notification | Identify notification requirements for contracts, cyber insurance, privacy laws, regulators, and customer agreements. | Notification matrix, legal review, contract summary. | Legal / Compliance | 5 | 3 | 15 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 73 | RS.MI-01 | Respond | Incident Mitigation | Technical | Containment | Define technical containment actions for compromised accounts, endpoints, network segments, cloud resources, malicious email, and unauthorized access. | Containment playbooks, EDR isolation evidence, account disable records. | Security Engineer / IT Manager | 5 | 5 | 25 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 74 | RS.MI-02 | Respond | Incident Mitigation | Technical | Eradication | Remove malware, unauthorized accounts, persistence mechanisms, malicious mailbox rules, exposed credentials, and vulnerable services. | Eradication checklist, remediation tickets, validation scan. | Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 75 | RS.MI-03 | Respond | Incident Mitigation | Administrative | Post-Incident Improvement | Document lessons learned and update controls, training, policies, detections, and recovery procedures after incidents. | After-action report, control updates, roadmap revisions. | CISO / Incident Manager | 4 | 4 | 16 | High | Defined | Baseline Control | After event | NIST CSF 2.0 |
| 76 | RC.RP-01 | Recover | Incident Recovery Plan Execution | Administrative | Recovery Plan | Maintain recovery plans for ransomware, cloud outage, identity compromise, data loss, major system failure, and business continuity disruption. | BCDR plan, recovery runbooks, RTO/RPO mapping. | IT Manager / Business Continuity Lead | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 77 | RC.RP-02 | Recover | Incident Recovery Plan Execution | Technical | System Restoration | Restore systems from known-good backups and validate integrity, security configuration, patch levels, and monitoring before production return. | Restore records, validation checklist, post-recovery scan. | IT Operations / Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 78 | RC.RP-03 | Recover | Incident Recovery Plan Execution | Technical | Credential Recovery | Reset and rotate compromised credentials, API keys, certificates, service account secrets, and privileged credentials during recovery. | Password reset records, key rotation logs, certificate inventory updates. | IAM Admin / Security Engineer | 5 | 4 | 20 | Critical | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 79 | RC.CO-01 | Recover | Incident Recovery Communication | Administrative | Recovery Communications | Communicate recovery status, business impact, restoration priorities, and customer/vendor updates through approved channels. | Recovery communication logs, executive updates, customer notice templates. | Communications Lead / Executive Leadership | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 80 | RC.CO-02 | Recover | Incident Recovery Communication | Administrative | Recovery Validation | Obtain business owner validation that recovered systems, applications, and data are operational and secure. | Business sign-off, validation testing, user acceptance record. | Business Owners / IT Manager | 4 | 3 | 12 | Medium | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 81 | RC.CO-03 | Recover | Incident Recovery Communication | Administrative | Resilience Improvement | Update recovery strategy, architecture, vendor support, backup design, and budget priorities based on recovery lessons learned. | Improvement plan, budget request, updated architecture diagram. | Executive Leadership / CISO | 4 | 4 | 16 | High | Defined | Baseline Control | Annual / as changed | NIST CSF 2.0 |
| 82 | OCSA-NIST-01 | Govern | OC Security Audit Advisory | Administrative | Executive Readiness | Schedule an executive cybersecurity review to align NIST CSF priorities with leadership goals, compliance expectations, cyber insurance, and business risk. | Consultation notes, executive summary, prioritized roadmap. | OC Security Audit / Executive Team | 4 | 3 | 12 | Medium | Managed | Consulting Recommended | As needed | OC Security Audit |
| 83 | OCSA-NIST-02 | Identify | OC Security Audit Assessment | Technical | Network Assessment | Perform an OC Security Audit network, Microsoft 365, Azure, firewall, endpoint, and vulnerability assessment to validate current posture. | Assessment report, risk scorecard, vulnerability findings, cloud findings. | OC Security Audit / IT Manager | 5 | 4 | 20 | Critical | Managed | Consulting Recommended | Annual / quarterly | OC Security Audit |
| 84 | OCSA-NIST-03 | Protect | OC Security Audit Remediation | Technical | Security Hardening | Use OC Security Audit findings to harden identity, firewalls, endpoints, Microsoft 365, Azure, backup, segmentation, logging, and security policies. | Remediation tracker, configuration evidence, validation report. | OC Security Audit / Security Engineer | 5 | 4 | 20 | Critical | Managed | Consulting Recommended | Project-based | OC Security Audit |
This tool is for initial guidance only and does not replace a professional cybersecurity audit, compliance assessment, penetration test, or legal/compliance review.
When leadership needs a defensible view of exposure, begin with a cybersecurity risk assessment. Organizations preparing evidence for internal governance or an independent review can add an internal security audit or an external security audit, depending on the audience and assurance objective.
If the Current Profile identifies identity, cloud, network, or vulnerability uncertainty, use a focused Microsoft 365 security audit, Azure cloud security audit, firewall security audit, or network vulnerability assessment. The scope should follow the critical services, data flows, and attack paths identified during NIST profiling rather than treating every platform as equally urgent.
Recovery gaps can continue into a focused business continuity and disaster recovery review. Organizations that need ongoing risk ownership, leadership reporting, policy oversight, and roadmap governance can use vCISO and security leadership support to keep the NIST program connected to business decisions.
Organizations beginning with the framework can first review the practical NIST CSF 2.0 guide and then determine how the framework applies to their business or organization. These pages clarify the framework's role before teams commit time and budget to implementation.
Leadership and program owners can use the governance and risk-management guide, Current and Target Profile guidance, and the Implementation Tiers guide to define accountability, desired outcomes, and the rigor appropriate for the organization.
Technical teams can continue with the technical-control implementation guide, while compliance and audit teams can organize control evidence and documentation. Vendor-dependent organizations should also review supply-chain and third-party risk management.
When the organization is ready to move from findings to action, use the NIST CSF gap-analysis process and the implementation roadmap. Small organizations can follow the right-sized small-business path based on NIST's quick-start guidance.
For a lighter starting point, browse the free cybersecurity assessment tools or use the Compliance Readiness Assessment Wizard. The experience guiding this work is summarized on the Ali Hassani, CISO profile.
Ali Hassani is a CISO and cybersecurity consultant with practical experience across IT operations, cybersecurity, compliance auditing, Microsoft infrastructure, Microsoft 365 security, network security, firewall security, vulnerability management, cloud security, and infrastructure leadership. His background helps organizations connect executive risk, technical controls, and compliance readiness.
NIST CSF implementation is the process of aligning governance, risk management, identity, endpoints, network security, monitoring, incident response, recovery, policy, and evidence practices with NIST Cybersecurity Framework outcomes.
NIST CSF is a cybersecurity framework, not a certification program. Organizations use it to improve security maturity, prepare for vendor and customer reviews, support cyber insurance readiness, and communicate risk more clearly.
Yes. OC Security Audit evaluates Microsoft 365, Entra ID, Exchange Online, SharePoint, OneDrive, Teams, Azure security controls, logging, backup, and related cloud security practices as part of NIST-aligned implementation and readiness work.
OC Security Audit can help validate improvements and maintain readiness documentation. When the roadmap requires hands-on IT implementation, troubleshooting, project delivery, network design, managed IT, Microsoft 365, Azure, or backup work, IT Perfection can support the operational follow-through.
Speak with OC Security Audit about a NIST CSF 2.0 gap analysis, cybersecurity risk assessment, remediation roadmap, policy development, and audit-ready documentation for your organization.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.