NIST Cybersecurity Framework 2.0
Every virtue against NIST Cybersecurity Framework 2.0. Control identifiers link to the NIST reference; strengths are stated as words.
| Virtue | Control | Control title | Strength | Why it maps |
|---|---|---|---|---|
| 義 01 Gi | PR.DS-01 | Confidentiality, integrity, and availability of data at rest | direct | Integrity protection for data at rest is what lets a system stand behind its own recorded actions. |
| GV.PO-01 | Policy for managing cybersecurity risk | partial | Policy sets the expectation of provable, non-repudiable conduct but does not itself produce the evidence. | |
| 勇 02 Yū | DE.CM-01 | Networks and network services monitored | direct | Continuous monitoring is the platform courage builds on, though the framework stops short of mandating the hunt. |
| DE.AE-02 | Potentially adverse events analysed | direct | Analysing adverse events is the disciplined core of threat hunting that both frameworks do require. | |
| RS.MA-01 | Incident response plan executed | direct | Executing the response plan is acting decisively on what the hunt turns up. | |
| 仁 03 Jin | PR.AT-01 | Personnel awareness and training | partial | Awareness training touches the human side of security but not whether the controls themselves are usable. |
| GV.RR-04 | Cybersecurity is included in human resources practices | partial | HR practices bring security into the employee lifecycle without addressing the friction that drives workarounds. | |
| 礼 04 Rei | PR.AA-05 | Access permissions incorporate least privilege | direct | Least privilege in access permissions is Rei stated almost word for word. |
| PR.AA-01 | Identities managed for authorised users and services | direct | Managing identities for authorised users and services is the precondition for granting only what duty demands. | |
| 誠 05 Makoto | PR.DS-01 | Confidentiality, integrity, and availability of data at rest | direct | Integrity checks on data at rest are machine truth — the system reporting its own state honestly. |
| RS.CO-02 | Incidents reported to internal and external stakeholders | direct | Notifying stakeholders of an incident is human truth: reporting what is, not what is comfortable. | |
| 名誉 06 Meiyo | GV.RR-02 | Roles, responsibilities, and authorities established | direct | Named roles and authorities are what make accountability locatable. |
| GV.OV-01 | Risk management strategy outcomes reviewed | direct | Reviewing risk-management outcomes is honour as self-scrutiny — checking your own work before an auditor does. | |
| 忠義 07 Chūgi | PR.AT-02 | Personnel with specialised roles trained | direct | Training people in specialised roles builds the shared competence a security culture runs on. |
| GV.RR-04 | Cybersecurity is included in human resources practices | direct | Integrating security into HR practices is how loyalty is built into the employment relationship rather than demanded of it. | |
| 自制 08 Jisei | PR.PS-01 | Configuration management practices established | direct | Configuration management practice is self-control expressed as infrastructure — deliberate, recorded change. |
| ID.IM-03 | Improvements from operational processes | partial | Improvements drawn from operations feed the discipline but are a step removed from the change act itself. |