Document Comparison
Mapping-PCI-DSS-to-NIST-Framework.pdf
→
PCI_DSS_v4_0_1_NIST_CSF_2.0_Mapping.pdf
8% similar
35 → 13
Pages
13365 → 5739
Words
55
Content Changes
Content Changes
55 content changes. 53 administrative changes (dates, page numbers) hidden.
Added
p. 2
PCI DSS v4.0.1 and NIST CSF 2.0 share the common goal of enhancing data security. The PCI DSS to NIST CSF 2.0 Mapping provides a tool for stakeholders to use in understanding how to align security efforts to meet objectives in both PCI DSS and NIST CSF.
The NIST CSF 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization
• regardless of its size, sector, or maturity
• to better understand, assess, prioritize, and communicate its cybersecurity efforts. The NIST CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes.
Both PCI DSS and NIST CSF are solid security approaches that address common security goals and principles as relevant to specific risks. While …
The NIST CSF 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization
• regardless of its size, sector, or maturity
• to better understand, assess, prioritize, and communicate its cybersecurity efforts. The NIST CSF does not prescribe how outcomes should be achieved. Rather, it links to online resources that provide additional guidance on practices and controls that could be used to achieve those outcomes.
Both PCI DSS and NIST CSF are solid security approaches that address common security goals and principles as relevant to specific risks. While …
Added
p. 4
• including privacy and civil liberties obligations
Removed
p. 2
The NIST Framework provides an overarching security and risk-management structure for voluntary use by U.S. critical infrastructure owners and operators. The NIST Framework core components consists of security Functions, Categories, and Subcategories of actions. These Subcategories reference globally recognized standards for cybersecurity. As the NIST Framework is broadly focused on organizational risk management, achieving the outcomes stated therein does not provide assurance that payment data is also protected.
Both PCI DSS and the NIST Framework are solid security approaches that address common security goals and principles as relevant to specific risks. While the NIST Framework identifies general security outcomes and activities, PCI DSS provides specific direction and guidance on how to meet security outcomes for payment environments. Because PCI DSS and the NIST Framework are intended for different audiences and uses, they are not interchangeable, and neither one is a replacement for the other.
Both PCI DSS and the NIST Framework are solid security approaches that address common security goals and principles as relevant to specific risks. While the NIST Framework identifies general security outcomes and activities, PCI DSS provides specific direction and guidance on how to meet security outcomes for payment environments. Because PCI DSS and the NIST Framework are intended for different audiences and uses, they are not interchangeable, and neither one is a replacement for the other.
Modified
p. 2
PCI DSS is focused on the unique security threats and risks present in the payments industry. It defines security requirements for the protection of payment card data, as well as validation procedures and guidance to help organizations understand the intent of the requirements. PCI SSC works with merchants, service providers, financial institutions, technology vendors, and others in the payments industry, as well as our assessor and forensic investigator communities. This keeps all stakeholders aware of current risks to payment data …
PCI DSS is focused on the unique security threats and risks present in the payments industry. It defines security requirements for the protection of payment data, as well as validation procedures and guidance to help organizations understand the intent of the requirements. PCI SSC works with merchants, service providers, financial institutions, technology vendors, and others in the payments industry, as well as our assessor and forensic investigator communities. This keeps all stakeholders aware of current risks to payment data and …
Modified
p. 2
Mapping PCI DSS to the NIST Framework This mapping is based on PCI DSS v3.2.1 and the Cybersecurity Framework v1.1, using the 2018-04-16_framework_v.1.1_core” spreadsheet1. PCI SSC evaluated each NIST Framework outcome (for example, ID.AM-1) against PCI DSS requirements and identified the relevant PCI DSS requirements for each outcome. The resultant mapping shows where the NIST Framework and PCI DSS contribute to the same security outcomes. PCI DSS requirements that map to an outcome are noted as “Informative References” in blue …
Mapping PCI DSS to NIST CSF This mapping is based on PCI DSS v4.0.1 and NIST CSF 2.0. PCI SSC BoA participants evaluated each NIST CSF outcome (for example, ID.AM-1) against PCI DSS requirements and identified the relevant PCI DSS requirements for each outcome. The resultant mapping shows where NIST CSF and PCI DSS contribute to the same security outcomes.
Modified
p. 2
The mapping covers all NIST Framework Functions and Categories, with PCI DSS requirements directly mapping to 96 of the 108 Subcategories. The mapping illustrates how meeting PCI DSS requirements may help entities demonstrate how NIST Framework outcomes are achieved for payment environments.
The PCI DSS to NIST CSF mapping covers all Framework Functions and Categories, with PCI DSS requirements mapping to 103 of the 106 Subcategories. The mapping illustrates how meeting PCI DSS requirements can help toward achieving NIST CSF outcomes for payment environments.
Modified
p. 3
The mapping is not a tool for demonstrating compliance to either PCI DSS or the NIST Framework, nor does meeting either a PCI DSS requirement or its corresponding NIST Framework outcome result in the other being met.
The mapping is not a tool for demonstrating compliance to either PCI DSS or NIST CSF, nor does meeting either a PCI DSS requirement or its corresponding NIST CSF category outcome result in the other being met.
Removed
p. 4
CATEGORY SUBCATEGORY INFORMATIVE REFERENCES3 FUNCTION: IDENTIFY (ID) Asset Management (ID.AM): The data, personnel, devices, systems, and facilities that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization’s risk strategy.
ID.AM-1: Physical devices and systems within the organization are inventoried.
• COBIT 5 BAI09.01, BAI09.02
ID.AM-1: Physical devices and systems within the organization are inventoried.
• COBIT 5 BAI09.01, BAI09.02
Removed
p. 4
• NIST SP 800-53 Rev. 4 CM-8, PM-5
• NIST SP 800-53 Rev. 4 CM-8, PM-5
• PCI DSS v3.2.1 2.4, 9.9, 11.1.1, 12.3.3 ID.AM-2: Software platforms and applications within the organization are inventoried.
• COBIT 5 BAI09.01, BAI09.02, BAI09.05
• NIST SP 800-53 Rev. 4 CM-8, PM-5
• PCI DSS v3.2.1 2.4, 9.9, 11.1.1, 12.3.3 ID.AM-2: Software platforms and applications within the organization are inventoried.
• COBIT 5 BAI09.01, BAI09.02, BAI09.05
Removed
p. 4
• PCI DSS v3.2.1 2.4, 12.3.7 2 https://www.nist.gov/cyberframework/framework 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 5
• NIST SP 800-53 Rev. 4 AC-4, CA-3, CA-9, PL-8, A.13.2.2
• PCI DSS v3.2.1 1.1.2, 1.1.3 ID.AM-4: External information systems are catalogued.
• COBIT 5 APO02.02, APO10.04, DSS01.02
• NIST SP 800-53 Rev. 4 AC-20, SA-9
• PCI DSS v3.2.1 1.1.1, 1.1.2, 1.1.3, 2.4 ID.AM-5: Resources (e.g., hardware, devices, data, time, and software) are prioritized based on their classification, criticality, and business value.
• COBIT 5 APO03.03, APO03.04, AP012.01, BA104.02, BAI09.02
• NIST SP 800-53 Rev. 4 CP-2, RA-2, SA-14, SC-6
• PCI DSS v3.2.1 9.6.1, 12.2 ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established.
• COBIT 5 APO01.02, APO07.06, APO13.01, DSS06.03
• PCI DSS v3.2.1 1.1.2, 1.1.3 ID.AM-4: External information systems are catalogued.
• COBIT 5 APO02.02, APO10.04, DSS01.02
• NIST SP 800-53 Rev. 4 AC-20, SA-9
• PCI DSS v3.2.1 1.1.1, 1.1.2, 1.1.3, 2.4 ID.AM-5: Resources (e.g., hardware, devices, data, time, and software) are prioritized based on their classification, criticality, and business value.
• COBIT 5 APO03.03, APO03.04, AP012.01, BA104.02, BAI09.02
• NIST SP 800-53 Rev. 4 CP-2, RA-2, SA-14, SC-6
• PCI DSS v3.2.1 9.6.1, 12.2 ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established.
• COBIT 5 APO01.02, APO07.06, APO13.01, DSS06.03
Removed
p. 5
• NIST SP 800-53 Rev. 4 CP-2, PS-7, PM-11
• PCI DSS v3.2.1 12.4, 12.5, 12.8, 12.9 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• PCI DSS v3.2.1 12.4, 12.5, 12.8, 12.9 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 6
ID.BE-1: The organization’s role in the supply chain is identified and communicated.
• COBIT 5 APO08.01, AP008.04, APO08.05, APO10.03, APO10.04,
• ISO/IEC 27001:2013 A.15.1.1, A.15.1.12, A-15.1.3, A.15.2.1, A.15.2.2
• NIST SP 800-53 Rev. 4 CP-2, SA-12 ID.BE-2: The organization’s place in critical infrastructure and its industry sector is identified and communicated.
• COBIT 5 APO02.06, APO03.01
• COBIT 5 APO08.01, AP008.04, APO08.05, APO10.03, APO10.04,
• ISO/IEC 27001:2013 A.15.1.1, A.15.1.12, A-15.1.3, A.15.2.1, A.15.2.2
• NIST SP 800-53 Rev. 4 CP-2, SA-12 ID.BE-2: The organization’s place in critical infrastructure and its industry sector is identified and communicated.
• COBIT 5 APO02.06, APO03.01
Removed
p. 6
• NIST SP 800-53 Rev. 4 PM-8 ID.BE-3: Priorities for organizational mission, objectives, and activities are established and communicated.
• COBIT 5 APO02.01, APO02.06, APO03.01
• ISA 62443-2-1:2009 4.2.2.1, 4.2.3.6
• NIST SP 800-53 Rev. 4 PM-11, SA-14 ID.BE-4: Dependencies and critical functions for delivery of critical services are established.
• COBIT 5 APO10.01, BAI04.02, BAI09.02
• NIST SP 800-53 Rev. 4 CP-8, PE-9, PE-11, PM-8, SA-14 ID.BE-5: Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations).
• OBIT 5 BAI03.02, DSS04.02
• COBIT 5 APO02.01, APO02.06, APO03.01
• ISA 62443-2-1:2009 4.2.2.1, 4.2.3.6
• NIST SP 800-53 Rev. 4 PM-11, SA-14 ID.BE-4: Dependencies and critical functions for delivery of critical services are established.
• COBIT 5 APO10.01, BAI04.02, BAI09.02
• NIST SP 800-53 Rev. 4 CP-8, PE-9, PE-11, PM-8, SA-14 ID.BE-5: Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations).
• OBIT 5 BAI03.02, DSS04.02
Removed
p. 6
• NIST SP 800-53 Rev. 4 CP-2, CP-11, SA-13, SA-14 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 7
ID.GV-1: Organizational cybersecurity policy is established and communicated.
• COBIT 5 APO01.03, APO13.01, EDM01.01, EDM01.02
• NIST SP 800-53 Rev. 4 -1 controls from all families
• PCI DSS v3.2.1 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6, 12.1 ID.GV-2: Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners.
• COBIT 5 APO01.02, APO10.03, APO13.02, DSS05.04
• NIST SP 800-53 Rev. 4 PM-1, PM-2, PS-7
• PCI DSS v3.2.1 12.4, 12.5, 12.8, 12.9 ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed.
• COBIT 5 BJI02.01, MEA03.01, MEA03.04
• COBIT 5 APO01.03, APO13.01, EDM01.01, EDM01.02
• NIST SP 800-53 Rev. 4 -1 controls from all families
• PCI DSS v3.2.1 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6, 12.1 ID.GV-2: Cybersecurity roles and responsibilities are coordinated and aligned with internal roles and external partners.
• COBIT 5 APO01.02, APO10.03, APO13.02, DSS05.04
• NIST SP 800-53 Rev. 4 PM-1, PM-2, PS-7
• PCI DSS v3.2.1 12.4, 12.5, 12.8, 12.9 ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed.
• COBIT 5 BJI02.01, MEA03.01, MEA03.04
Removed
p. 7
• NIST SP 800-53 Rev. 4 -1 controls from all security control families
• PCI DSS v3.2.1 3.1, 12.10 ID.GV-4: Governance and risk management processes address cybersecurity risks.
• COBIT 5 EDM03.02, APO12.02, APO12.05, DSS04.02
• ISA 62443-2-1:2009 4.2.3.1, 4.2.3.3, 4.2.3.8, 4.2.3.9, 4.2.3.11, 4.3.2.4.3,
• ISO/IEC 27001:2013 Clause 6
• NIST SP 800-53 Rev. 4 SA-2, PM-3, PM-7, PM-9, PM-10, PM-11
• PCI DSS v3.2.1 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6, 12.1, 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• PCI DSS v3.2.1 3.1, 12.10 ID.GV-4: Governance and risk management processes address cybersecurity risks.
• COBIT 5 EDM03.02, APO12.02, APO12.05, DSS04.02
• ISA 62443-2-1:2009 4.2.3.1, 4.2.3.3, 4.2.3.8, 4.2.3.9, 4.2.3.11, 4.3.2.4.3,
• ISO/IEC 27001:2013 Clause 6
• NIST SP 800-53 Rev. 4 SA-2, PM-3, PM-7, PM-9, PM-10, PM-11
• PCI DSS v3.2.1 1.5, 2.5, 3.7, 4.3, 5.4, 6.7, 7.3, 8.8, 9.10, 10.8, 11.6, 12.1, 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 8
ID.RA-1: Asset vulnerabilities are identified and documented.
• COBIT 5 APO12.01, APO12.02, APO12.03, APO12.04, DSS05.01,
• ISA 62443-2-1:2009 4.2.3, 4.2.3.7, 4.2.3.9, 4.2.3.12
• NIST SP 800-53 Rev. 4 CA-2, CA-7, CA-8, RA-3, RA-5, SA-5, SA-11, SI-2, SI-4, SI-5
• PCI DSS v3.2.1 6.1, 11.2, 11.3, 12.2 ID.RA-2: Cyber threat intelligence and vulnerability information is received from information sharing forums and sources.
• COBIT 5 APO12.01, APO12.02, APO12.03, APO12.04, DSS05.01,
• ISA 62443-2-1:2009 4.2.3, 4.2.3.7, 4.2.3.9, 4.2.3.12
• NIST SP 800-53 Rev. 4 CA-2, CA-7, CA-8, RA-3, RA-5, SA-5, SA-11, SI-2, SI-4, SI-5
• PCI DSS v3.2.1 6.1, 11.2, 11.3, 12.2 ID.RA-2: Cyber threat intelligence and vulnerability information is received from information sharing forums and sources.
Removed
p. 8
• NIST SP 800-53 Rev. 4 PM-15, PM-16, SI-5
• PCI DSS v3.2.1 6.1 ID.RA-3: Threats, both internal and external, are identified and documented.
• COBIT 5 APO12.01, APO12.02, APO12.03, APO12.04
• ISO/IEC 27001:2013 Clause 6.1.2
• NIST SP 800-53 Rev. 4 RA-3, SI-5, PM-12, PM-16
• PCI DSS v3.2.1 12.2 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• ISO/IEC 27001:2013 Clause 6.1.3
• PCI DSS v3.2.1 6.1 ID.RA-3: Threats, both internal and external, are identified and documented.
• COBIT 5 APO12.01, APO12.02, APO12.03, APO12.04
• ISO/IEC 27001:2013 Clause 6.1.2
• NIST SP 800-53 Rev. 4 RA-3, SI-5, PM-12, PM-16
• PCI DSS v3.2.1 12.2 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• ISO/IEC 27001:2013 Clause 6.1.3
Removed
p. 9
• ISO/IEC 27001:2013 A.16.1.6, Clause 6.1.2
• NIST SP 800-53 Rev. 4 RA-2, RA-3, PM-9, PM-11, SA-14
• PCI DSS v3.2.1 6.1 ID.RA-5: Threats, vulnerabilities, likelihoods, and impacts are used to determine risk.
• NIST SP 800-53 Rev. 4 RA-2, RA-3, PM-16
• PCI DSS v3.2.1 12.2 ID.RA-6: Risk responses are identified and prioritized.
• COBIT 5 APO12.05, APO13.02
• NIST SP 800-53 Rev. 4 PM-4, PM-9
• NIST SP 800-53 Rev. 4 RA-2, RA-3, PM-9, PM-11, SA-14
• PCI DSS v3.2.1 6.1 ID.RA-5: Threats, vulnerabilities, likelihoods, and impacts are used to determine risk.
• NIST SP 800-53 Rev. 4 RA-2, RA-3, PM-16
• PCI DSS v3.2.1 12.2 ID.RA-6: Risk responses are identified and prioritized.
• COBIT 5 APO12.05, APO13.02
• NIST SP 800-53 Rev. 4 PM-4, PM-9
Removed
p. 10
• PCI DSS v3.2.1 12.2 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 10
ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders
• COBIT 5 APO12.04, APO12.05, APO13.02, BAI02.03, BAI04.02
• ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3, Clause 9.3
• NIST SP 800-53 Rev. 4 PM-9
• NIST SP 800-53 Rev. 4 PM-9
• PCI DSS v3.2.1 12.2 ID.RM-2: Organizational risk tolerance is determined and clearly expressed
• ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3
• ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3
• PCI DSS v3.2.1 12.2 ID.RM-3: The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
• NIST SP 800-53 Rev. 4 PM-8, PM-9, PM-11, SA-14
• COBIT 5 APO12.04, APO12.05, APO13.02, BAI02.03, BAI04.02
• ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3, Clause 9.3
• NIST SP 800-53 Rev. 4 PM-9
• NIST SP 800-53 Rev. 4 PM-9
• PCI DSS v3.2.1 12.2 ID.RM-2: Organizational risk tolerance is determined and clearly expressed
• ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3
• ISO/IEC 27001:2013 Clause 6.1.3, Clause 8.3
• PCI DSS v3.2.1 12.2 ID.RM-3: The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis
• NIST SP 800-53 Rev. 4 PM-8, PM-9, PM-11, SA-14
Removed
p. 11
ID.SC-1: Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders
• COBIT 5: APO10.01, APO10.04, APO12.04, APO12.05, APO13.02, BAI01.03, BAI02.03, BAI04.02
• ISA 62443-2-1:2009: 4.3.4.2
• ISO/IEC 27001:2013: A.15.1.1, A.15.1.2, A.15.1.3, A.15.2.1, A.15.2.2
SA-9, SA-12, PM-9
• PCI DSS v3.2.1 12.2, 12.8, 12.9 ID.SC-2: Suppliers and third-party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process
• COBIT 5: APO10.01, APO10.02, APO10.04, APO10.05, APO12.01, APO12.02, APO12.03, APO12.04, APO12.05, APO12.06, APO13.02, BAI02.03
• ISA 62443-2-1:2009: 4.2.3.1, 4.2.3.2, 4.2.3.3, 4.2.3.4, 4.2.3.6, 4.2.3.8, 4.2.3.9, 4.2.3.10, 4.2.3.12, 4.2.3.13, 4.2.3.14
• COBIT 5: APO10.01, APO10.04, APO12.04, APO12.05, APO13.02, BAI01.03, BAI02.03, BAI04.02
• ISA 62443-2-1:2009: 4.3.4.2
• ISO/IEC 27001:2013: A.15.1.1, A.15.1.2, A.15.1.3, A.15.2.1, A.15.2.2
SA-9, SA-12, PM-9
• PCI DSS v3.2.1 12.2, 12.8, 12.9 ID.SC-2: Suppliers and third-party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment process
• COBIT 5: APO10.01, APO10.02, APO10.04, APO10.05, APO12.01, APO12.02, APO12.03, APO12.04, APO12.05, APO12.06, APO13.02, BAI02.03
• ISA 62443-2-1:2009: 4.2.3.1, 4.2.3.2, 4.2.3.3, 4.2.3.4, 4.2.3.6, 4.2.3.8, 4.2.3.9, 4.2.3.10, 4.2.3.12, 4.2.3.13, 4.2.3.14
Removed
p. 11
• NIST SP 800-53: RA-2, RA-3, SA-12, SA-14, SA-15, PM-9
• PCI DSS v3.2.1 12.2, 12.8 ID.SC-3: Contracts with suppliers and third- party partners are used to implement appropriate measures designed to meet the objectives of an organization's cybersecurity and Cyber Supply Chain Risk Management Plan.
• COBIT 5: APO10.01, APO10.02, APO10.03, APO10.04, APO10.05
• ISA 62443-2-1:2009: 4.3.2.6.4, 4.3.2.6.7
• ISO/IEC 27001:2013: A.15.1.1, A.15.1.2, A.15.1.3
• NIST SP 800-53: SA-9, SA-11, SA-12, PM-9
• PCI DSS v3.2.1 12.2, 12.8 ID.SC-3: Contracts with suppliers and third- party partners are used to implement appropriate measures designed to meet the objectives of an organization's cybersecurity and Cyber Supply Chain Risk Management Plan.
• COBIT 5: APO10.01, APO10.02, APO10.03, APO10.04, APO10.05
• ISA 62443-2-1:2009: 4.3.2.6.4, 4.3.2.6.7
• ISO/IEC 27001:2013: A.15.1.1, A.15.1.2, A.15.1.3
• NIST SP 800-53: SA-9, SA-11, SA-12, PM-9
Removed
p. 12
• ISA 62443-2-1:2009: 4.3.2.5.7, 4.3.4.5.11
Removed
p. 12
• COBIT 5: APO10.01, APO10.03, APO10.04, APO10.05, MEA01.01, MEA01.02, MEA01.03, MEA01.04, MEA01.05
Removed
p. 12
• ISA 62443-3-3:2013: SR 6.1
• NIST SP 800-53: AU-2, AU-6, AU-12, AU-16, PS-7, SA-9, SA-12
• PCI DSS v3.2.1 12.8 ID.SC-5: Response and recovery planning and testing are conducted with suppliers and third-party providers.
• ISA 62443-3-3:2013: SR 2.8, SR 3.3, SR.6.1, SR 7.3, SR 7.4
• NIST SP 800-53: CP-2, CP-4, IR-3, IR-4, IR-6, IR-8, IR-9
• PCI DSS v3.2.1 12.10 FUNCTION: PROTECT (PR) Identity Management, Authentication and Access Control (PR.AC): Access to physical and logical assets and associated facilities is limited to authorized users, processes, and devices, and is managed consistent with the assessed risk of unauthorized access to authorized activities and transactions.
PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users, and processes.
• CIS CSC 1.5, 15, 16
• COBIT 5 DSS05.04, DSS06.03
• ISA 62443-3-3:2013 SR 1.1, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9
• ISO/IEC 27001:2013 A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, …
• NIST SP 800-53: AU-2, AU-6, AU-12, AU-16, PS-7, SA-9, SA-12
• PCI DSS v3.2.1 12.8 ID.SC-5: Response and recovery planning and testing are conducted with suppliers and third-party providers.
• ISA 62443-3-3:2013: SR 2.8, SR 3.3, SR.6.1, SR 7.3, SR 7.4
• NIST SP 800-53: CP-2, CP-4, IR-3, IR-4, IR-6, IR-8, IR-9
• PCI DSS v3.2.1 12.10 FUNCTION: PROTECT (PR) Identity Management, Authentication and Access Control (PR.AC): Access to physical and logical assets and associated facilities is limited to authorized users, processes, and devices, and is managed consistent with the assessed risk of unauthorized access to authorized activities and transactions.
PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users, and processes.
• CIS CSC 1.5, 15, 16
• COBIT 5 DSS05.04, DSS06.03
• ISA 62443-3-3:2013 SR 1.1, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9
• ISO/IEC 27001:2013 A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, …
Removed
p. 13
• ISO/IEC 27001:2013 A.11.1.1, A.11.1.2, A.11.1.3, A.11.1.4, A.11.1.5, A.11.1.6, A.11.2.3 1, A.11.2.3, A.11.2.5, A.11.2.6, A.11.2.7, A.11.2.8
• NIST SP 800-53 Rev. 4 PE-2, PE-3, PE-4, PE-5, PE-6, PE-8
• PCI DSS v3.2.1 9.1, 9.2, 9.3, 9.4, 9.5, 9.6, 9.7, 9.9, 9.10 PR.AC-3: Remote access is managed.
• COBIT 5 APO13.01, DSS01.04, DSS05.03
• NIST SP 800-53 Rev. 4 PE-2, PE-3, PE-4, PE-5, PE-6, PE-8
• PCI DSS v3.2.1 9.1, 9.2, 9.3, 9.4, 9.5, 9.6, 9.7, 9.9, 9.10 PR.AC-3: Remote access is managed.
• COBIT 5 APO13.01, DSS01.04, DSS05.03
Removed
p. 13
• NIST SP 800-53 Rev. 4 AC-1, AC-17, AC-19, AC-20
• PCI DSS v3.2.1 2.3, 8.1.5, 8.3, 8.5.1, 12.3.8, 12.3.9, 12.3.10 PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.
• PCI DSS v3.2.1 2.3, 8.1.5, 8.3, 8.5.1, 12.3.8, 12.3.9, 12.3.10 PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties.
Removed
p. 13
• ISO/IEC 27001:2013 A.6.1.2, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5
• NIST SP 800-53 Rev. 4 AC-1, AC-2, AC-3, AC-5, AC-6, AC-14, AC-16, AC-24
• PCI DSS v3.2.1 6.4.2, 7.1, 7.2, 8.7, 9.3 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• NIST SP 800-53 Rev. 4 AC-1, AC-2, AC-3, AC-5, AC-6, AC-14, AC-16, AC-24
• PCI DSS v3.2.1 6.4.2, 7.1, 7.2, 8.7, 9.3 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 14
• NIST SP 800-53 Rev. 4 AC-4, AC-10, SC-7
• PCI DSS v3.2.1 1.1, 1.2, 1.3, 2.2, 6.2, 10.8, 11.3 PR.AC-6: Identities are proofed and bound to credentials and asserted in interactions.
DSS05.04, DSS05.05, DSS05.07, DSS06.03
• ISA 62443-2-1:2009: 4.3.3.2.2, 4.3.3.5.2, 4.3.3.7.2, 4.3.3.7.4
• ISA 62443-3-3:2013: SR 1.1, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.9, SR
• NIST SP 800-53: Rev 4 AC-1, AC-2, AC-3, AC-16, AC-19, AC-24, IA-2, IA- 4, IA-5, IA-8, PE-2, PS-3
• PCI DSS v3.2.1 7.1.4, 8.1, 8.2.2 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative …
• PCI DSS v3.2.1 1.1, 1.2, 1.3, 2.2, 6.2, 10.8, 11.3 PR.AC-6: Identities are proofed and bound to credentials and asserted in interactions.
DSS05.04, DSS05.05, DSS05.07, DSS06.03
• ISA 62443-2-1:2009: 4.3.3.2.2, 4.3.3.5.2, 4.3.3.7.2, 4.3.3.7.4
• ISA 62443-3-3:2013: SR 1.1, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.9, SR
• NIST SP 800-53: Rev 4 AC-1, AC-2, AC-3, AC-16, AC-19, AC-24, IA-2, IA- 4, IA-5, IA-8, PE-2, PS-3
• PCI DSS v3.2.1 7.1.4, 8.1, 8.2.2 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative …
Removed
p. 15
• COBIT 5: DSS05.04, DSS05.10, DSS06.10
• ISA 62443-2-1:2009: 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9
• ISA 62443-3-3:2013: SR 1.1, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 1.10 ISO/IEC 27001:2013 A.9.2.1,
• ISO/IEC 27001:2013: A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, A.18.1.4
• NIST SP 800-53: Rev. 4 AC-7, AC-8, AC-9, AC-11, AC-12, AC-14, IA-1, IA-2, IA-3, IA-4, IA-5, IA-8, IA-9, IA-10, IA-11
• PCI DSS v3.2.1 8.2, 8.3 Awareness and Training (PR.AT): The organization’s personnel and partners are provided cybersecurity awareness education and are trained to perform their cybersecurity-related duties and responsibilities consistent with related policies, procedures, and agreements.
PR.AT-1: All users are informed and trained.
• COBIT 5 APO07.03, BAI05.07
• ISA 62443-2-1:2009: 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9
• ISA 62443-3-3:2013: SR 1.1, SR 1.2, SR 1.5, SR 1.7, SR 1.8, SR 1.9, SR 1.10 ISO/IEC 27001:2013 A.9.2.1,
• ISO/IEC 27001:2013: A.9.2.1, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3, A.18.1.4
• NIST SP 800-53: Rev. 4 AC-7, AC-8, AC-9, AC-11, AC-12, AC-14, IA-1, IA-2, IA-3, IA-4, IA-5, IA-8, IA-9, IA-10, IA-11
• PCI DSS v3.2.1 8.2, 8.3 Awareness and Training (PR.AT): The organization’s personnel and partners are provided cybersecurity awareness education and are trained to perform their cybersecurity-related duties and responsibilities consistent with related policies, procedures, and agreements.
PR.AT-1: All users are informed and trained.
• COBIT 5 APO07.03, BAI05.07
Removed
p. 15
• PCI DSS v3.2.1 6.7, 7.3, 8.4, 9.9.3, 12.4, 12.6 PR.AT-2: Privileged users understand their roles and responsibilities.
• COBIT 5 APO07.02, DSS05.04, DSS06.03
• PCI DSS v3.2.1 1.1.5, 7.1, 7.2, 7.3, 12.4, 12.6 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• COBIT 5 APO07.02, DSS05.04, DSS06.03
• PCI DSS v3.2.1 1.1.5, 7.1, 7.2, 7.3, 12.4, 12.6 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 16
• COBIT 5 APO07.03, APO07.06, APO10.04, APO10.05
• NIST SP 800-53 Rev. 4 PS-7, SA-9, SA-16
• PCI DSS v3.2.1 12.8.2, 12.9 PR.AT-4: Senior executives understand their roles and responsibilities.
• COBIT 5 EDM01.01, APO01.02, APO07.03
• ISO/IEC 27001:2013 A.6.1.1, A.7.2.2,
• ISO/IEC 27001:2013 A.6.1.1, A.7.2.2,
• PCI DSS v3.2.1 12.4, 12.5 PR.AT-5: Physical cybersecurity security personnel understand their roles and responsibilities.
• NIST SP 800-53 Rev. 4 AT-3, IR-2, PM-13
• ISO/IEC 27001:2013 A.8.2.3, A.8.3.1, A.8.3.2, A.8.3.3, A.11.2.5, A.11.2.7
• NIST SP 800-53 Rev. 4 PS-7, SA-9, SA-16
• PCI DSS v3.2.1 12.8.2, 12.9 PR.AT-4: Senior executives understand their roles and responsibilities.
• COBIT 5 EDM01.01, APO01.02, APO07.03
• ISO/IEC 27001:2013 A.6.1.1, A.7.2.2,
• ISO/IEC 27001:2013 A.6.1.1, A.7.2.2,
• PCI DSS v3.2.1 12.4, 12.5 PR.AT-5: Physical cybersecurity security personnel understand their roles and responsibilities.
• NIST SP 800-53 Rev. 4 AT-3, IR-2, PM-13
• ISO/IEC 27001:2013 A.8.2.3, A.8.3.1, A.8.3.2, A.8.3.3, A.11.2.5, A.11.2.7
Removed
p. 17
PR.DS-1: Data-at-rest is protected.
• COBIT 5 APO01.06, BAI02.01, BAI06.01, DSS04.07, DSS05.03,DSS06.06
• NIST SP 800-53 Rev. 4 MP-8, SC-12, SC-28
• PCI DSS v3.2.1 3 (all), 8.2.1 PR.DS-2: Data-in-transit is protected.
• COBIT 5 APO01.06, DSS05.02, DSS06.06
• ISA 62443-3-3:2013 SR 3.1, SR 3.8, SR 4.1, SR 4.2
• ISO/IEC 27001:2013 A.8.2.3, A.13.1.1, A.13.2.1, A.13.2.3, A.14.1.2,
• NIST SP 800-53 Rev. 4 SC-8, SC-11, SC-12
• PCI DSS v3.2.1 4 (all), 8.2.1 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition.
• NIST SP 800-53 Rev. 4 CM-8, MP-6, PE-16
• PCI DSS v3.2.1 2.4, 9.5, 9.6, 9.7, 9.8, 9.9 PR.DS-4: Adequate capacity to ensure availability is maintained.
• COBIT 5 APO13.01, BAI04.04
• NIST SP 800-53 Rev. 4 AU-4, CP-2, SC-5 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table …
• COBIT 5 APO01.06, BAI02.01, BAI06.01, DSS04.07, DSS05.03,DSS06.06
• NIST SP 800-53 Rev. 4 MP-8, SC-12, SC-28
• PCI DSS v3.2.1 3 (all), 8.2.1 PR.DS-2: Data-in-transit is protected.
• COBIT 5 APO01.06, DSS05.02, DSS06.06
• ISA 62443-3-3:2013 SR 3.1, SR 3.8, SR 4.1, SR 4.2
• ISO/IEC 27001:2013 A.8.2.3, A.13.1.1, A.13.2.1, A.13.2.3, A.14.1.2,
• NIST SP 800-53 Rev. 4 SC-8, SC-11, SC-12
• PCI DSS v3.2.1 4 (all), 8.2.1 PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition.
• NIST SP 800-53 Rev. 4 CM-8, MP-6, PE-16
• PCI DSS v3.2.1 2.4, 9.5, 9.6, 9.7, 9.8, 9.9 PR.DS-4: Adequate capacity to ensure availability is maintained.
• COBIT 5 APO13.01, BAI04.04
• NIST SP 800-53 Rev. 4 AU-4, CP-2, SC-5 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table …
Removed
p. 18
• COBIT 5 APO01.06, DSS05.04, DSS05.07, DSS06.02
• ISO/IEC 27001:2013 A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3
• NIST SP 800-53 Rev. 4 AC-4, AC-5, AC-6, PE-19, PS-3, PS-6, SC-7, SC- 8, SC-13, SC-31, SI-4
• PCI DSS v3.2.1 10.6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity.
• COBIT 5 APO01.06, BAI06.01, DSS06.02
• NIST SP 800-53 Rev. 4 SC-16, SI-7
• PCI DSS v3.2.1 11.5 PR.DS-7: The development and testing environment(s) are separate from the production environment.
• COBIT 5 BAI03.08, BAI07.04
• NIST SP 800-53 Rev. 4 CM-2
• PCI DSS v3.2.1 6.4.1, 6.4.2 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly …
• ISO/IEC 27001:2013 A.6.1.2, A.7.1.1, A.7.1.2, A.7.3.1, A.8.2.2, A.8.2.3, A.9.1.1, A.9.1.2, A.9.2.3, A.9.4.1, A.9.4.4, A.9.4.5, A.10.1.1, A.11.1.4, A.11.1.5, A.11.2.1, A.13.1.1, A.13.1.3, A.13.2.1, A.13.2.3, A.13.2.4, A.14.1.2, A.14.1.3
• NIST SP 800-53 Rev. 4 AC-4, AC-5, AC-6, PE-19, PS-3, PS-6, SC-7, SC- 8, SC-13, SC-31, SI-4
• PCI DSS v3.2.1 10.6 PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity.
• COBIT 5 APO01.06, BAI06.01, DSS06.02
• NIST SP 800-53 Rev. 4 SC-16, SI-7
• PCI DSS v3.2.1 11.5 PR.DS-7: The development and testing environment(s) are separate from the production environment.
• COBIT 5 BAI03.08, BAI07.04
• NIST SP 800-53 Rev. 4 CM-2
• PCI DSS v3.2.1 6.4.1, 6.4.2 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly …
Removed
p. 19
• ISO/IEC 27001:2013: A.11.2.4
• NIST SP 800-53: SA-10, SI-7
• PCI DSS v3.2.1 9.9.2 Information Protection Processes and Procedures (PR.IP): Security policies (that address purpose, scope, roles, responsibilities, management commitment, and coordination among organizational entities), processes, and procedures are maintained and used to manage protection of information systems and assets.
PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g., concept of least functionality).
• COBIT 5 BAI10.01, BAI10.02, BAI10.03, BAI10.05
• ISO/IEC 27001:2013 A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4
• NIST SP 800-53 Rev. 4 CM-2, CM-3, CM-4, CM-5, CM-6, CM-7, CM-9, SA-10
• PCI DSS v3.2.1 1.2, 2.2 PR.IP-2: A System Development Life Cycle to manage systems is implemented.
• COBIT 5 APO13.01, BAI03.01, BAI03.02, BAI03.03
• NIST SP 800-53 Rev. 4 PL-8, SA-3, SA-4, SA-8, SA-10, SA-11, SA-12, SA-15, SA-17, SI-12, SI-13, SI-14, SI-16, SI-17
• PCI DSS v3.2.1 6.3, 6.4, 6.5, 6.6, 6.7 3 Blue text in this …
• NIST SP 800-53: SA-10, SI-7
• PCI DSS v3.2.1 9.9.2 Information Protection Processes and Procedures (PR.IP): Security policies (that address purpose, scope, roles, responsibilities, management commitment, and coordination among organizational entities), processes, and procedures are maintained and used to manage protection of information systems and assets.
PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g., concept of least functionality).
• COBIT 5 BAI10.01, BAI10.02, BAI10.03, BAI10.05
• ISO/IEC 27001:2013 A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4
• NIST SP 800-53 Rev. 4 CM-2, CM-3, CM-4, CM-5, CM-6, CM-7, CM-9, SA-10
• PCI DSS v3.2.1 1.2, 2.2 PR.IP-2: A System Development Life Cycle to manage systems is implemented.
• COBIT 5 APO13.01, BAI03.01, BAI03.02, BAI03.03
• NIST SP 800-53 Rev. 4 PL-8, SA-3, SA-4, SA-8, SA-10, SA-11, SA-12, SA-15, SA-17, SI-12, SI-13, SI-14, SI-16, SI-17
• PCI DSS v3.2.1 6.3, 6.4, 6.5, 6.6, 6.7 3 Blue text in this …
Removed
p. 20
• COBIT 5 BAI01.06, BAI06.01,
• NIST SP 800-53 Rev. 4 CM-3, CM-4, SA-10
• PCI DSS v3.2.1 6.4 PR.IP-4: Backups of information are conducted, maintained, and tested periodically.
• COBIT 5 APO13.01, DSS01.01, DSS04.07
• NIST SP 800-53 Rev. 4 CP-4, CP-6, CP-9
• PCI DSS v3.2.1 9.5.1, 12.10.1, 12.10.2 PR.IP-5: Policy and regulations regarding the physical operating environment for organizational assets are met.
• ISA 62443-2-1:2009 4.3.3.3.1 4.3.3.3.2, 4.3.3.3.3, 4.3.3.3.5, 4.3.3.3.6
• PCI DSS v3.2.1 9 (all) 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• NIST SP 800-53 Rev. 4 CM-3, CM-4, SA-10
• PCI DSS v3.2.1 6.4 PR.IP-4: Backups of information are conducted, maintained, and tested periodically.
• COBIT 5 APO13.01, DSS01.01, DSS04.07
• NIST SP 800-53 Rev. 4 CP-4, CP-6, CP-9
• PCI DSS v3.2.1 9.5.1, 12.10.1, 12.10.2 PR.IP-5: Policy and regulations regarding the physical operating environment for organizational assets are met.
• ISA 62443-2-1:2009 4.3.3.3.1 4.3.3.3.2, 4.3.3.3.3, 4.3.3.3.5, 4.3.3.3.6
• PCI DSS v3.2.1 9 (all) 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 21
• COBIT 5 BAI09.03, DSS05.06
• NIST SP 800-53 Rev. 4 MP-6
• PCI DSS v3.2.1 3.1, 9.8 PR.IP-7: Protection processes are improved.
• COBIT 5 APO11.06, APO12.06, DSS04.05
• ISA 62443-2-1:2009 4.4.3.1, 4.4.3.2, 4.4.3.3, 4.4.3.4, 4.4.3.5, 4.4.3.6, 4.4.3.7, 4.4.3.8
• ISO/IEC 27001:2013 A.16.1.6, Clause 9, Clause 10
• NIST SP 800-53 Rev. 4 CA-2, CA-7, CP-2, IR-8, PL-2, PM-6
• PCI DSS v3.2.1 10.8, 12.10.6, 12.11 PR.IP-8: Effectiveness of protection technologies is shared with appropriate parties.
• COBIT 5 BAI08.04, DSS03.04
• NIST SP 800-53 Rev. 4 AC-21, CA-7, SI-4 PR.IP-9: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed.
• COBIT 5 APO12.06, DSS04.03
• NIST SP 800-53 Rev. 4 CP-2, CP-7, CP-12, CP-13, IR-7, IR-8, IR-9, PE- 17
• PCI DSS v3.2.1 11.1.2, 12.5.3, 12.10 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity …
• NIST SP 800-53 Rev. 4 MP-6
• PCI DSS v3.2.1 3.1, 9.8 PR.IP-7: Protection processes are improved.
• COBIT 5 APO11.06, APO12.06, DSS04.05
• ISA 62443-2-1:2009 4.4.3.1, 4.4.3.2, 4.4.3.3, 4.4.3.4, 4.4.3.5, 4.4.3.6, 4.4.3.7, 4.4.3.8
• ISO/IEC 27001:2013 A.16.1.6, Clause 9, Clause 10
• NIST SP 800-53 Rev. 4 CA-2, CA-7, CP-2, IR-8, PL-2, PM-6
• PCI DSS v3.2.1 10.8, 12.10.6, 12.11 PR.IP-8: Effectiveness of protection technologies is shared with appropriate parties.
• COBIT 5 BAI08.04, DSS03.04
• NIST SP 800-53 Rev. 4 AC-21, CA-7, SI-4 PR.IP-9: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed.
• COBIT 5 APO12.06, DSS04.03
• NIST SP 800-53 Rev. 4 CP-2, CP-7, CP-12, CP-13, IR-7, IR-8, IR-9, PE- 17
• PCI DSS v3.2.1 11.1.2, 12.5.3, 12.10 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity …
Removed
p. 22
• NIST SP 800-53 Rev. 4 CP-4, IR-3, PM-14
• PCI DSS v3.2.1 12.10.2 PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening).
• COBIT 5 APO07.01, APO07.02, APO07.03, APO07.04, APO07.05
• PCI DSS v3.2.1 12.10.2 PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening).
• COBIT 5 APO07.01, APO07.02, APO07.03, APO07.04, APO07.05
Removed
p. 22
• ISO/IEC 27001:2013 A.7.1.1, A.7.1.2, A.7.2.1, A.7.2.2, A.7.2.3, A.7.3.1, A.7.3.1, A.8.1.4
• NIST SP 800-53 Rev. 4 PS-1, PS-2, PS-3, PS-4, PS-5, PS-6, PS-7, PS-8, SA-21
• PCI DSS v3.2.1 8.1.3, 9.3, 12.7 PR.IP-12: A vulnerability management plan is developed and implemented.
• COBIT 5 BAI03.10, DSS05.01, DSS05.02
• NIST SP 800-53 Rev. 4 RA-3, RA-5, SI-2
• NIST SP 800-53 Rev. 4 PS-1, PS-2, PS-3, PS-4, PS-5, PS-6, PS-7, PS-8, SA-21
• PCI DSS v3.2.1 8.1.3, 9.3, 12.7 PR.IP-12: A vulnerability management plan is developed and implemented.
• COBIT 5 BAI03.10, DSS05.01, DSS05.02
• NIST SP 800-53 Rev. 4 RA-3, RA-5, SI-2
Removed
p. 23
PR.MA-1: Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools.
• COBIT 5 BAI03.10, BAI09.02, BAI09.0, DSS01.05
• NIST SP 800-53 Rev. 4 MA-2, MA-3, MA-5, MA-6
• PCI DSS v3.2.1 6.2, 9.9.3 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access.
• ISA 62443-2-1:2009 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8
• NIST SP 800-53 Rev. 4 MA-4
• PCI DSS v3.2.1 8.1.5, 8.3, 8.5.1, 12.3.8, 12.3.9 Protective Technology (PR.PT): Technical security solutions are managed to ensure the security and resilience of systems and assets, consistent with related policies, procedures, and agreements.
PR.PT-1: Audit/log records are determined, documented, implemented, and reviewed in accordance with policy.
• COBIT 5 APO11.04, BAI03.05, DSS05.04, DSS05.07, MEA02.01
• ISA 62443-2-1:2009 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4
• ISA 62443-3-3:2013 SR 2.8, SR 2.9, SR 2.10, SR 2.11, SR 2.12
• NIST SP 800-53 Rev. 4 AU Family
• PCI DSS v3.2.1 10.1, 10.2, …
• COBIT 5 BAI03.10, BAI09.02, BAI09.0, DSS01.05
• NIST SP 800-53 Rev. 4 MA-2, MA-3, MA-5, MA-6
• PCI DSS v3.2.1 6.2, 9.9.3 PR.MA-2: Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access.
• ISA 62443-2-1:2009 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8
• NIST SP 800-53 Rev. 4 MA-4
• PCI DSS v3.2.1 8.1.5, 8.3, 8.5.1, 12.3.8, 12.3.9 Protective Technology (PR.PT): Technical security solutions are managed to ensure the security and resilience of systems and assets, consistent with related policies, procedures, and agreements.
PR.PT-1: Audit/log records are determined, documented, implemented, and reviewed in accordance with policy.
• COBIT 5 APO11.04, BAI03.05, DSS05.04, DSS05.07, MEA02.01
• ISA 62443-2-1:2009 4.3.3.3.9, 4.3.3.5.8, 4.3.4.4.7, 4.4.2.1, 4.4.2.2, 4.4.2.4
• ISA 62443-3-3:2013 SR 2.8, SR 2.9, SR 2.10, SR 2.11, SR 2.12
• NIST SP 800-53 Rev. 4 AU Family
• PCI DSS v3.2.1 10.1, 10.2, …
Removed
p. 24
• COBIT 5 DSS05.02, DSS05.05, DSS06.06
• ISA 62443-2-1:2009 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4
• ISA 62443-3-3:2013 SR 1.1, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7
• NIST SP 800-53 Rev. 4 AC-3, CM-7
• PCI DSS v3.2.1 2.2, 7.1, 7.2, 9.3 PR.PT-4: Communications and control networks are protected.
• COBIT 5 DSS05.02, APO13.01
• ISA 62443-3-3:2013 SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6
• NIST SP 800-53 Rev. 4 AC-4, AC-17, AC-18, CP-8, SC-7, SC-19, SC-20, SC-21, SC-22, SC-23, SC-24, SC-25, SC-29, SC-32, SC-36, SC-37, SC- 38, SC-39, SC-40, SC-41, SC-43
• PCI DSS v3.2.1 1 (all), …
• ISA 62443-2-1:2009 4.3.3.5.1, 4.3.3.5.2, 4.3.3.5.3, 4.3.3.5.4, 4.3.3.5.5, 4.3.3.5.6, 4.3.3.5.7, 4.3.3.5.8, 4.3.3.6.1, 4.3.3.6.2, 4.3.3.6.3, 4.3.3.6.4, 4.3.3.6.5, 4.3.3.6.6, 4.3.3.6.7, 4.3.3.6.8, 4.3.3.6.9, 4.3.3.7.1, 4.3.3.7.2, 4.3.3.7.3, 4.3.3.7.4
• ISA 62443-3-3:2013 SR 1.1, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 1.10, SR 1.11, SR 1.12, SR 1.13, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR 2.5, SR 2.6, SR 2.7
• NIST SP 800-53 Rev. 4 AC-3, CM-7
• PCI DSS v3.2.1 2.2, 7.1, 7.2, 9.3 PR.PT-4: Communications and control networks are protected.
• COBIT 5 DSS05.02, APO13.01
• ISA 62443-3-3:2013 SR 3.1, SR 3.5, SR 3.8, SR 4.1, SR 4.3, SR 5.1, SR 5.2, SR 5.3, SR 7.1, SR 7.6
• NIST SP 800-53 Rev. 4 AC-4, AC-17, AC-18, CP-8, SC-7, SC-19, SC-20, SC-21, SC-22, SC-23, SC-24, SC-25, SC-29, SC-32, SC-36, SC-37, SC- 38, SC-39, SC-40, SC-41, SC-43
• PCI DSS v3.2.1 1 (all), …
Removed
p. 25
DE.AE-1: A baseline of network operations and expected data flows for users and systems is established and managed.
• ISO/IEC 27001:2013: A.12.1.1, A.12.1.2, A.13.1.1, A.13.1.2
• NIST SP 800-53 Rev. 4 AC-4, CA-3, CM-2, SI-4
• PCI DSS v3.2.1 1.1.1, 1.1.2, 1.1.3 DE.AE-2: Detected events are analyzed to understand attack targets and methods.
• ISA 62443-3-3:2013 SR 2.8, SR 2.9, SR 2.10, SR 2.11, SR 2.12, SR 3.9, SR 6.1, SR 6.2
• NIST SP 800-53 Rev. 4 AU-6, CA-7, IR-4, SI-4
• PCI DSS v3.2.1 10.6 (all), 12.5.2 DE.AE-3: Event data are collected and correlated from multiple sources and sensors.
• CIS CSC 1, 3, 4, 5, 6, 7, 8, 11, 12, 13, 14, 15, 16
• NIST SP 800-53 Rev. 4 AU-6, CA-7, IR-4, IR-5, IR-8, SI-4
• PCI DSS v3.2.1 10.1, 12.10.5, 10.6 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity …
• ISO/IEC 27001:2013: A.12.1.1, A.12.1.2, A.13.1.1, A.13.1.2
• NIST SP 800-53 Rev. 4 AC-4, CA-3, CM-2, SI-4
• PCI DSS v3.2.1 1.1.1, 1.1.2, 1.1.3 DE.AE-2: Detected events are analyzed to understand attack targets and methods.
• ISA 62443-3-3:2013 SR 2.8, SR 2.9, SR 2.10, SR 2.11, SR 2.12, SR 3.9, SR 6.1, SR 6.2
• NIST SP 800-53 Rev. 4 AU-6, CA-7, IR-4, SI-4
• PCI DSS v3.2.1 10.6 (all), 12.5.2 DE.AE-3: Event data are collected and correlated from multiple sources and sensors.
• CIS CSC 1, 3, 4, 5, 6, 7, 8, 11, 12, 13, 14, 15, 16
• NIST SP 800-53 Rev. 4 AU-6, CA-7, IR-4, IR-5, IR-8, SI-4
• PCI DSS v3.2.1 10.1, 12.10.5, 10.6 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity …
Removed
p. 26
• COBIT 5 APO12.06, DSS03.01
• COBIT 5 APO12.06, DSS03.01
• NIST SP 800-53 Rev. 4 CP-2, IR-4, RA-3, SI -4
• PCI DSS v3.2.1 10.6.3, 12.5.2 DE.AE-5: Incident alert thresholds are established.
• NIST SP 800-53 Rev. 4 IR-4, IR-5, IR-8
• PCI DSS v3.2.1 12.5.2 Security Continuous Monitoring (DE.CM): The information system and assets are monitored to identify cybersecurity events and verify the effectiveness of protective measures.
DE.CM-1: The network is monitored to detect potential cybersecurity events.
• CIS CSC 7, 8, 12, 13, 15, 16
• COBIT 5 DSS01.03, DSS03.05, DSS05.07
• NIST SP 800-53 Rev. 4 AC-2, AU-12, CA-7, CM-3, SC-5, SC-7, SI-4
• PCI DSS v3.2.1 10.6.1, 10.6.2, 11.4 DE.CM-2: The physical environment is monitored to detect potential cybersecurity events.
• COBIT 5 DSS01.04, DSS01.05
• NIST SP 800-53 Rev. 4 CA-7, PE-3, PE-6, PE-20
• COBIT 5 APO12.06, DSS03.01
• NIST SP 800-53 Rev. 4 CP-2, IR-4, RA-3, SI -4
• PCI DSS v3.2.1 10.6.3, 12.5.2 DE.AE-5: Incident alert thresholds are established.
• NIST SP 800-53 Rev. 4 IR-4, IR-5, IR-8
• PCI DSS v3.2.1 12.5.2 Security Continuous Monitoring (DE.CM): The information system and assets are monitored to identify cybersecurity events and verify the effectiveness of protective measures.
DE.CM-1: The network is monitored to detect potential cybersecurity events.
• CIS CSC 7, 8, 12, 13, 15, 16
• COBIT 5 DSS01.03, DSS03.05, DSS05.07
• NIST SP 800-53 Rev. 4 AC-2, AU-12, CA-7, CM-3, SC-5, SC-7, SI-4
• PCI DSS v3.2.1 10.6.1, 10.6.2, 11.4 DE.CM-2: The physical environment is monitored to detect potential cybersecurity events.
• COBIT 5 DSS01.04, DSS01.05
• NIST SP 800-53 Rev. 4 CA-7, PE-3, PE-6, PE-20
Removed
p. 27
• NIST SP 800-53 Rev. 4 AC-2, AU-12, AU-13, CA-7, CM-10, CM-11
• PCI DSS v3.2.1 9.1.1 DE.CM-4: Malicious code is detected.
• NIST SP 800-53 Rev. 4 SI-3, SI-8
• PCI DSS v3.2.1 5 (all) DE.CM-5: Unauthorized mobile code is detected.
• ISO/IEC 27001:2013 A.12.5.1, A-12.6.2
• NIST SP 800-53 Rev. 4 SC-18, SI-4. SC-44
• PCI DSS v3.2.1 5 (all) DE.CM-6: External service provider activity is monitored to detect potential cybersecurity events.
• COBIT 5 APO07.06, APO10.05
• NIST SP 800-53 Rev. 4 CA-7, PS-7, SA-4, SA-9, SI-4
• PCI DSS v3.2.1 8.1.5, 10.6 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the …
• PCI DSS v3.2.1 9.1.1 DE.CM-4: Malicious code is detected.
• NIST SP 800-53 Rev. 4 SI-3, SI-8
• PCI DSS v3.2.1 5 (all) DE.CM-5: Unauthorized mobile code is detected.
• ISO/IEC 27001:2013 A.12.5.1, A-12.6.2
• NIST SP 800-53 Rev. 4 SC-18, SI-4. SC-44
• PCI DSS v3.2.1 5 (all) DE.CM-6: External service provider activity is monitored to detect potential cybersecurity events.
• COBIT 5 APO07.06, APO10.05
• NIST SP 800-53 Rev. 4 CA-7, PS-7, SA-4, SA-9, SI-4
• PCI DSS v3.2.1 8.1.5, 10.6 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the …
Removed
p. 28
• CIS CSC 1, 2, 3, 5, 9, 12, 13, 15, 16
• COBIT 5 DSS05.02, DSS05.05
• NIST SP 800-53 Rev. 4 AU-12, CA-7, CM-3, CM-8, PE-3, PE-6, PE-20, SI-4
• PCI DSS v3.2.1 10.1, 10.6.1, 11.1, 11.4, 11.5, 12.10.5 DE.CM-8: Vulnerability scans are performed.
• COBIT 5 BAI03.10, DSS05.01
• NIST SP 800-53 Rev. 4 RA-5
• PCI DSS v3.2.1 11.2 Detection Processes (DE.DP): Detection processes and procedures are maintained and tested to ensure awareness of anomalous events.
DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountability.
• NIST SP 800-53 Rev. 4 CA-2, CA-7, PM-14
• PCI DSS v3.2.1 9.9.3, 12.5.2, 12.10 DE.DP-2: Detection activities comply with all applicable requirements.
• COBIT 5 DSS06.01, MEA03.03, MEA03.04
• ISO/IEC 27001:2013 A.18.1.4, A.18.2.2, A-18.2.3
• NIST SP 800-53 Rev. 4 AC-25, CA-2, CA-7, PM-14, SA-18, SI-4
• PCI DSS v3.2.1 10.9, 11.2, 11.3, 11.4, 12.10.1 3 Blue text in this table has been added by PCI SSC and denotes …
• COBIT 5 DSS05.02, DSS05.05
• NIST SP 800-53 Rev. 4 AU-12, CA-7, CM-3, CM-8, PE-3, PE-6, PE-20, SI-4
• PCI DSS v3.2.1 10.1, 10.6.1, 11.1, 11.4, 11.5, 12.10.5 DE.CM-8: Vulnerability scans are performed.
• COBIT 5 BAI03.10, DSS05.01
• NIST SP 800-53 Rev. 4 RA-5
• PCI DSS v3.2.1 11.2 Detection Processes (DE.DP): Detection processes and procedures are maintained and tested to ensure awareness of anomalous events.
DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountability.
• NIST SP 800-53 Rev. 4 CA-2, CA-7, PM-14
• PCI DSS v3.2.1 9.9.3, 12.5.2, 12.10 DE.DP-2: Detection activities comply with all applicable requirements.
• COBIT 5 DSS06.01, MEA03.03, MEA03.04
• ISO/IEC 27001:2013 A.18.1.4, A.18.2.2, A-18.2.3
• NIST SP 800-53 Rev. 4 AC-25, CA-2, CA-7, PM-14, SA-18, SI-4
• PCI DSS v3.2.1 10.9, 11.2, 11.3, 11.4, 12.10.1 3 Blue text in this table has been added by PCI SSC and denotes …
Removed
p. 29
• COBIT 5 APO13.02, DSS05.02
• NIST SP 800-53 Rev. 4 CA-2, CA-7, PE-3, PM-14, SI-3, SI-4
• PCI DSS v3.2.1 10.6.1, 10.9, 11.2, 11.3, 12.10 DE.DP-4: Event detection information is communicated.
• COBIT 5 APO08.04, APO12.06, DSS02.05
• NIST SP 800-53 Rev. 4 AU-6, CA-2, CA-7, RA-5, SI-4
• PCI DSS v3.2.1 12.10 DE.DP-5: Detection processes are continuously improved.
• NIST SP 800-53 Rev. 4, CA-2, CA-7, PL-2, RA-5, SI-4, PM-14
• NIST SP 800-53 Rev. 4 CA-2, CA-7, PE-3, PM-14, SI-3, SI-4
• PCI DSS v3.2.1 10.6.1, 10.9, 11.2, 11.3, 12.10 DE.DP-4: Event detection information is communicated.
• COBIT 5 APO08.04, APO12.06, DSS02.05
• NIST SP 800-53 Rev. 4 AU-6, CA-2, CA-7, RA-5, SI-4
• PCI DSS v3.2.1 12.10 DE.DP-5: Detection processes are continuously improved.
• NIST SP 800-53 Rev. 4, CA-2, CA-7, PL-2, RA-5, SI-4, PM-14
Removed
p. 30
• COBIT 5 APO12.06, BAI01.10
• NIST SP 800-53 Rev. 4 CP-2, CP-10, IR-4, IR-8
• NIST SP 800-53 Rev. 4 CP-2, CP-3, IR-3, IR-8
• PCI DSS v3.2.1 12.10 Communications (RS.CO): Response activities are coordinated with internal and external stakeholders (e.g. external support from law enforcement agencies) RS.CO-1: Personnel know their roles and order of operations when a response is needed.
• COBIT 5 EDM03.02, APO01.02, APO12.03
• PCI DSS v3.2 12.10 RS.CO-2: Incidents are reported consistent with established criteria.
• NIST SP 800-53 Rev. 4 AU-6, IR-6, IR-8
• PCI DSS v3.2.1 10.8, 12.10 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy …
• NIST SP 800-53 Rev. 4 CP-2, CP-10, IR-4, IR-8
• NIST SP 800-53 Rev. 4 CP-2, CP-3, IR-3, IR-8
• PCI DSS v3.2.1 12.10 Communications (RS.CO): Response activities are coordinated with internal and external stakeholders (e.g. external support from law enforcement agencies) RS.CO-1: Personnel know their roles and order of operations when a response is needed.
• COBIT 5 EDM03.02, APO01.02, APO12.03
• PCI DSS v3.2 12.10 RS.CO-2: Incidents are reported consistent with established criteria.
• NIST SP 800-53 Rev. 4 AU-6, IR-6, IR-8
• PCI DSS v3.2.1 10.8, 12.10 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy …
Removed
p. 31
• ISO/IEC 27001:2013 A.16.1.2, Clause 7.4, Clause 16.1.2
• NIST SP 800-53 Rev. 4 CA-2, CA-7, CP-2, IR-4, IR-8, PE-6, RA-5, SI-4
• PCI DSS v3.2.1 12.10 RS.CO-4: Coordination with stakeholders occurs consistent with response plans.
• NIST SP 800-53 Rev. 4 CA-2, CA-7, CP-2, IR-4, IR-8, PE-6, RA-5, SI-4
• PCI DSS v3.2.1 12.10 RS.CO-4: Coordination with stakeholders occurs consistent with response plans.
Removed
p. 31
• PCI DSS v3.2.1 12.10.1 RS.CO-5: Voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness.
• NIST SP 800-53 Rev. 4 PM-15, SI-5 Analysis (RS.AN): Analysis is conducted to ensure effective response and support recovery activities.
RS.AN-1: Notifications from detection systems are investigated.
• COBIT 5 DSS02.04, DSS02.07
• NIST SP 800-53 Rev. 4 AU-6, CA-7, IR-4, IR-5, PE-6, SI-4
• PCI DSS v3.2.1 10.6.3, 11.5.1, 12.5.2, 12.10.5 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
• NIST SP 800-53 Rev. 4 PM-15, SI-5 Analysis (RS.AN): Analysis is conducted to ensure effective response and support recovery activities.
RS.AN-1: Notifications from detection systems are investigated.
• COBIT 5 DSS02.04, DSS02.07
• NIST SP 800-53 Rev. 4 AU-6, CA-7, IR-4, IR-5, PE-6, SI-4
• PCI DSS v3.2.1 10.6.3, 11.5.1, 12.5.2, 12.10.5 3 Blue text in this table has been added by PCI SSC and denotes PCI DSS v3.2.1 requirements that relate to NIST Cybersecurity Framework outcomes. Only the blue text has been added. All other content in this table is copied directly from the NIST Cybersecurity "Framework V1.1 Core (Excel)" at this URL: https://www.nist.gov/cyberframework/framework. PCI SSC is not responsible for the accuracy of the information from the NIST Framework, including the Informative References therefrom.
Removed
p. 32
• NIST SP 800-53 Rev. 4 CP-2, IR-4
• PCI DSS v3.2.1 10.6.3, 11.5.1, 12.5.2 RS.AN-3: Forensics are performed.
• COBIT 5 APO12.06, DSS03.02, DSS05.07
• ISA 62443-3-3:2013 SR 2.8, SR 2.9, SR 2.10, SR 2.11, SR 2.12, SR 3.9,
• NIST SP 800-53 Rev. 4 AU-7, IR-4
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.AN-4: Incidents are categorized consistent with response plans.
• NIST SP 800-53 Rev. 4 CP-2, IR-4, IR-5, IR-8
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.AN-5: Processes are established to receive, analyze, and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g., internal testing, security bulletins, or security researchers).
• COBIT 5 EDM03.02, DSS05.07
• NIST 800-53 Rev 4 SI-5, PM-15
• PCI DSS v3.2.1 10.6.3, 11.5.1, 12.5.2 RS.AN-3: Forensics are performed.
• COBIT 5 APO12.06, DSS03.02, DSS05.07
• ISA 62443-3-3:2013 SR 2.8, SR 2.9, SR 2.10, SR 2.11, SR 2.12, SR 3.9,
• NIST SP 800-53 Rev. 4 AU-7, IR-4
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.AN-4: Incidents are categorized consistent with response plans.
• NIST SP 800-53 Rev. 4 CP-2, IR-4, IR-5, IR-8
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.AN-5: Processes are established to receive, analyze, and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g., internal testing, security bulletins, or security researchers).
• COBIT 5 EDM03.02, DSS05.07
• NIST 800-53 Rev 4 SI-5, PM-15
Removed
p. 33
RS.MI-1: Incidents are contained.
• ISA 62443-3-3:2013 SR 5.1, SR 5.2, SR 5.4
• NIST SP 800-53 Rev. 4 IR-4
• NIST SP 800-53 Rev. 4 IR-4
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.MI-2: Incidents are mitigated.
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks.
• NIST SP 800-53 Rev. 4 CA-7, RA-3, RA-5
• PCI DSS v3.2.1 6.1, 6.2, 10.6.3, 11.2, 11.5.1, 12.5.2, 12.10 Improvements (RS.IM): Organizational response activities are improved by incorporating lessons learned from current and RS.IM-1: Response plans incorporate lessons learned.
• ISA 62443-2-1:2009 4.3.4.5.10, 4.4.3.4
• ISA 62443-3-3:2013 SR 5.1, SR 5.2, SR 5.4
• NIST SP 800-53 Rev. 4 IR-4
• NIST SP 800-53 Rev. 4 IR-4
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.MI-2: Incidents are mitigated.
• PCI DSS v3.2.1 11.5.1, 12.5.2 RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks.
• NIST SP 800-53 Rev. 4 CA-7, RA-3, RA-5
• PCI DSS v3.2.1 6.1, 6.2, 10.6.3, 11.2, 11.5.1, 12.5.2, 12.10 Improvements (RS.IM): Organizational response activities are improved by incorporating lessons learned from current and RS.IM-1: Response plans incorporate lessons learned.
• ISA 62443-2-1:2009 4.3.4.5.10, 4.4.3.4
Removed
p. 34
• COBIT 5 BAI01.13, DSS04.08
• PCI DSS v3.2.112.10.6 FUNCTION: RECOVER (RC) Recovery Planning (RC.RP): Recovery processes and procedures are executed and maintained to ensure timely restoration of systems or assets affected by cybersecurity incidents.
RC.RP-1: Recovery plan is executed during or after a cybersecurity incident.
• COBIT 5 APO12.06, DSS02.05, DSS03.04
• PCI DSS v3.2.1 12.10.6 Improvements (RC.IM): Recovery planning and processes are improved by incorporating lessons learned into future activities.
RC.IM-1: Recovery plans incorporate lessons learned.
• COBIT 5 APO12.06, BAI05.07, DSS04.08
• PCI DSS v3.2.1 12.10.6 RC.IM-2: Recovery strategies are updated.
• COBIT 5 APO12.06, BAI07.08
• NIST SP 800-53 Rev. 4 CP-2, IR-4
• PCI DSS v3.2.112.10.6 FUNCTION: RECOVER (RC) Recovery Planning (RC.RP): Recovery processes and procedures are executed and maintained to ensure timely restoration of systems or assets affected by cybersecurity incidents.
RC.RP-1: Recovery plan is executed during or after a cybersecurity incident.
• COBIT 5 APO12.06, DSS02.05, DSS03.04
• PCI DSS v3.2.1 12.10.6 Improvements (RC.IM): Recovery planning and processes are improved by incorporating lessons learned into future activities.
RC.IM-1: Recovery plans incorporate lessons learned.
• COBIT 5 APO12.06, BAI05.07, DSS04.08
• PCI DSS v3.2.1 12.10.6 RC.IM-2: Recovery strategies are updated.
• COBIT 5 APO12.06, BAI07.08
• NIST SP 800-53 Rev. 4 CP-2, IR-4
Removed
p. 35
RC.CO-1: Public relations are managed.
• ISO/IEC 27001:2013 A.6.1.4, Clause 7.4 RC.CO-2: Reputation is repaired after an incident.
• ISO/IEC 27001:2013 Clause 7.4 RC.CO-3: Recovery activities are communicated to internal and external stakeholders as well as executive and management teams.
• ISO/IEC 27001:2013 A.6.1.4, Clause 7.4 RC.CO-2: Reputation is repaired after an incident.
• ISO/IEC 27001:2013 Clause 7.4 RC.CO-3: Recovery activities are communicated to internal and external stakeholders as well as executive and management teams.