NIST Cybersecurity Framework 2.0 Crosswalk
Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.
Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.
Purpose
How each practice relates to NIST Cybersecurity Framework 2.0 outcome identifiers — useful for reporting campaign progress against a framework most boards already recognize.
How to use it
Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.
How these mappings were made
Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.
Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.
| Term | Meaning |
|---|---|
| Direct | The practice addresses the substance of the requirement head-on. |
| Supporting | The practice materially helps satisfy the requirement but does not cover it alone. |
| Enabling | The practice is a prerequisite that makes the requirement achievable. |
| Contextual | The practice informs or constrains how the requirement is met. |
| High confidence | Reviewed against the primary source text; the relationship is explicit. |
| Moderate confidence | Reviewed against the primary source; the relationship is a reasoned interpretation. |
| Low confidence | Directional only. Treat as a starting point for your own analysis. |
This is independent educational material. It supports planning and evidence collection; it does not establish compliance with NIST SP 800-171, DFARS 252.204-7012, CMMC, export-control obligations, or any contract requirement, and it is not an assessment. Tailor every item to your own technical, operational, contractual, regulatory, and safety requirements.
IT Top 10
| Practice | Short title | Identifier | Relationship | Confidence | Caveat |
|---|---|---|---|---|---|
| IT-02 | Asset inventory | ID.AM-01 / ID.AM-02 | Direct | High | The CSF describes outcomes, not testable controls. It is a planning aid here, not a measure of completion. |
| IT-03 | Technical debt reduction | ID.AM-08 | Supporting | Moderate | The CSF describes outcomes, not testable controls. |
| IT-04 | Flexible technology stack | PR.PS-01 | Supporting | Moderate | The CSF describes outcomes, not testable controls. |
| IT-09 | Backup and disaster recovery | PR.DS-11 / RC.RP-01 | Direct | Moderate | The CSF describes outcomes, not testable controls. |
OT Top 10
| Practice | Short title | Identifier | Relationship | Confidence | Caveat |
|---|---|---|---|---|---|
| OT-01 | OT identity and access control | PR.AA-01 / PR.AA-05 | Direct | Moderate | The CSF describes outcomes, not testable controls. |
| OT-02 | Validated OT asset inventory | ID.AM-01 / ID.AM-02 | Direct | High | The CSF describes outcomes, not testable controls. |
| OT-03 | OT network segmentation | PR.IR-01 | Direct | Moderate | The CSF describes outcomes, not testable controls. |
| OT-04 | OT incident response and recovery | RS.MA-01 / RC.RP-01 | Direct | Moderate | The CSF describes outcomes, not testable controls. |
| OT-05 | OT vulnerability management | ID.RA-01 / PR.PS-02 | Supporting | Moderate | The CSF describes outcomes, not testable controls. |
| OT-06 | OT remote access pathways | PR.AA-05 | Supporting | Moderate | The CSF describes outcomes, not testable controls. |
| OT-07 | OT continuous monitoring | DE.CM-01 / DE.AE-02 | Direct | Moderate | The CSF describes outcomes, not testable controls. |
| OT-08 | OT system resiliency | RC.RP-01 / PR.DS-11 | Direct | Moderate | The CSF describes outcomes, not testable controls. |
| OT-09 | OT supply chain security | GV.SC-01 / GV.SC-05 | Direct | Moderate | The CSF describes outcomes, not testable controls. |
| OT-10 | OT change review | PR.PS-01 | Supporting | Moderate | The CSF describes outcomes, not testable controls. |
Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-nist-csf-2-0-crosswalk to keep filenames consistent across your team.