Skip to content
Digital Bushido

NIST Cybersecurity Framework 2.0

Every virtue against NIST Cybersecurity Framework 2.0. Control identifiers link to the NIST reference; strengths are stated as words.

NIST Cybersecurity Framework 2.0Table scrolls horizontally.
VirtueControlControl titleStrengthWhy it maps
01 GiPR.DS-01Confidentiality, integrity, and availability of data at restdirectIntegrity protection for data at rest is what lets a system stand behind its own recorded actions.
GV.PO-01Policy for managing cybersecurity riskpartialPolicy sets the expectation of provable, non-repudiable conduct but does not itself produce the evidence.
02 DE.CM-01Networks and network services monitoreddirectContinuous monitoring is the platform courage builds on, though the framework stops short of mandating the hunt.
DE.AE-02Potentially adverse events analyseddirectAnalysing adverse events is the disciplined core of threat hunting that both frameworks do require.
RS.MA-01Incident response plan executeddirectExecuting the response plan is acting decisively on what the hunt turns up.
03 JinPR.AT-01Personnel awareness and trainingpartialAwareness training touches the human side of security but not whether the controls themselves are usable.
GV.RR-04Cybersecurity is included in human resources practicespartialHR practices bring security into the employee lifecycle without addressing the friction that drives workarounds.
04 ReiPR.AA-05Access permissions incorporate least privilegedirectLeast privilege in access permissions is Rei stated almost word for word.
PR.AA-01Identities managed for authorised users and servicesdirectManaging identities for authorised users and services is the precondition for granting only what duty demands.
05 MakotoPR.DS-01Confidentiality, integrity, and availability of data at restdirectIntegrity checks on data at rest are machine truth — the system reporting its own state honestly.
RS.CO-02Incidents reported to internal and external stakeholdersdirectNotifying stakeholders of an incident is human truth: reporting what is, not what is comfortable.
名誉 06 MeiyoGV.RR-02Roles, responsibilities, and authorities establisheddirectNamed roles and authorities are what make accountability locatable.
GV.OV-01Risk management strategy outcomes revieweddirectReviewing risk-management outcomes is honour as self-scrutiny — checking your own work before an auditor does.
忠義 07 ChūgiPR.AT-02Personnel with specialised roles traineddirectTraining people in specialised roles builds the shared competence a security culture runs on.
GV.RR-04Cybersecurity is included in human resources practicesdirectIntegrating security into HR practices is how loyalty is built into the employment relationship rather than demanded of it.
自制 08 JiseiPR.PS-01Configuration management practices establisheddirectConfiguration management practice is self-control expressed as infrastructure — deliberate, recorded change.
ID.IM-03Improvements from operational processespartialImprovements drawn from operations feed the discipline but are a step removed from the change act itself.