Security & cloud
NIST Cybersecurity Framework
C-009 · CertiBOB catalogue reference, not an official standard or control number.
Prepare a scoped security & cloud record for NIST Cybersecurity Framework. Catalogue context: United States; cross-sector.
- Type
- Framework
- Recorded edition
- 2.0
- Jurisdiction
- United States
- Sector context
- Cross-sector
Catalogue metadata is not a claim of current applicability or full coverage. Verify editions, amendments, licensing and jurisdiction before use.
Edition currency: review needed.
Preparation classification and price under review. Add to your preparation selection →
Publisher / source for NIST Cybersecurity Framework ↗What is available for preparation?
12 original preparation prompts
Original CertiBOB guidance is available; it is not the complete official framework or authoritative requirements.
These are catalogue records, not a claim that an edition is current or that its requirements are fully implemented.
Start with the scope and the record.
Define the systems and services in scope, identify control owners and gather records showing how controls operate.
In your private workspace, select the applicable edition and permitted requirement content. Describe operating controls, link evidence, and record a human review of its coverage and period. Findings remain separate from remediation progress.
Original preparation prompts
These 12 prompts are CertiBOB preparation guidance, not official requirement text or a complete control library.
- GV.OC · Understand organizational context
- Record relevant stakeholders, obligations and the systems within scope.
- GV.RR · Assign accountable roles
- Name security decision owners and communicate their responsibilities.
- ID.AM · Maintain an asset inventory
- Record information, systems and external services supporting the assessment scope.
- ID.RA · Evaluate security risks
- Document risks, owners, priorities and treatment decisions.
- PR.AA · Manage identity and access
- Demonstrate approval, authentication and periodic review of access.
- PR.DS · Protect information
- Record safeguards for information in storage, transfer and use.
- DE.CM · Monitor important systems
- Define monitored events, escalation owners and retained monitoring evidence.
- DE.AE · Investigate unusual events
- Record how observations are assessed and escalated.
- RS.MA · Manage incident response
- Maintain response responsibilities and evidence of exercises or incident handling.
- RS.CO · Coordinate incident communications
- Identify communications owners and record appropriate notifications.
- RC.RP · Exercise recovery plans
- Record recovery procedures, test outcomes and follow-up work.
- RC.CO · Communicate recovery progress
- Define who communicates recovery status and validates restoration.
Reuse proof. Keep the judgement distinct.
A file can support multiple controls or requirements only through valid, reviewed mappings. Each framework and edition retains its own applicability, provenance and readiness evaluation. Human verification and independent auditor judgement remain necessary.
Prepared is not certified.
CertiBOB supports preparation and coordination. It does not issue an independent assessment opinion, certify your organization or guarantee an outcome.
Build your readiness record →