Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
CROSSWALK · IT / OTv1.0 · REVIEWED 2026-07-28

NIST Cybersecurity Framework 2.0 Crosswalk

Brilliant at the Basics Resource Center · brilliantatthebasics.us · published by inDirectIT, Inc.

Independent educational material. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Does not establish compliance, certification, or contractual standing.

Purpose

How each practice relates to NIST Cybersecurity Framework 2.0 outcome identifiers — useful for reporting campaign progress against a framework most boards already recognize.

How to use it

Use the identifier column to find the requirement in its own source document, then read the caveat before drawing any conclusion. Where a row is marked Supporting or Contextual, the practice is one contribution among several — it is not the whole requirement.

How these mappings were made

Each mapping was read against the primary source text and then classified by relationship type and confidence. No automated mapping tool was used, and no row asserts equivalence.

Relationship type and confidence are editorial judgements, not authoritative equivalence. Read the caveat column before using any row in a compliance conversation.

TermMeaning
DirectThe practice addresses the substance of the requirement head-on.
SupportingThe practice materially helps satisfy the requirement but does not cover it alone.
EnablingThe practice is a prerequisite that makes the requirement achievable.
ContextualThe practice informs or constrains how the requirement is met.
High confidenceReviewed against the primary source text; the relationship is explicit.
Moderate confidenceReviewed against the primary source; the relationship is a reasoned interpretation.
Low confidenceDirectional only. Treat as a starting point for your own analysis.

IT Top 10

PracticeShort titleIdentifierRelationshipConfidenceCaveat
IT-02Asset inventoryID.AM-01 / ID.AM-02DirectHighThe CSF describes outcomes, not testable controls. It is a planning aid here, not a measure of completion.
IT-03Technical debt reductionID.AM-08SupportingModerateThe CSF describes outcomes, not testable controls.
IT-04Flexible technology stackPR.PS-01SupportingModerateThe CSF describes outcomes, not testable controls.
IT-09Backup and disaster recoveryPR.DS-11 / RC.RP-01DirectModerateThe CSF describes outcomes, not testable controls.

OT Top 10

PracticeShort titleIdentifierRelationshipConfidenceCaveat
OT-01OT identity and access controlPR.AA-01 / PR.AA-05DirectModerateThe CSF describes outcomes, not testable controls.
OT-02Validated OT asset inventoryID.AM-01 / ID.AM-02DirectHighThe CSF describes outcomes, not testable controls.
OT-03OT network segmentationPR.IR-01DirectModerateThe CSF describes outcomes, not testable controls.
OT-04OT incident response and recoveryRS.MA-01 / RC.RP-01DirectModerateThe CSF describes outcomes, not testable controls.
OT-05OT vulnerability managementID.RA-01 / PR.PS-02SupportingModerateThe CSF describes outcomes, not testable controls.
OT-06OT remote access pathwaysPR.AA-05SupportingModerateThe CSF describes outcomes, not testable controls.
OT-07OT continuous monitoringDE.CM-01 / DE.AE-02DirectModerateThe CSF describes outcomes, not testable controls.
OT-08OT system resiliencyRC.RP-01 / PR.DS-11DirectModerateThe CSF describes outcomes, not testable controls.
OT-09OT supply chain securityGV.SC-01 / GV.SC-05DirectModerateThe CSF describes outcomes, not testable controls.
OT-10OT change reviewPR.PS-01SupportingModerateThe CSF describes outcomes, not testable controls.

NIST Cybersecurity Framework 2.0 Crosswalk · version 1.0 · reviewed 2026-07-28 · file name batb-nist-csf-2-0-crosswalk

Generated from Framework crosswalk at brilliantatthebasics.us. The live pages carry the current version of this guidance.

Independent educational material published by inDirectIT, Inc. Not affiliated with, sponsored by, approved by, or endorsed by the U.S. Department of War. Cybersecurity practices must be tailored to each organization’s technical, operational, contractual, regulatory, and safety requirements.

All downloads

Printing produces a paginated document. Choose “Save as PDF” in the print dialog and name it batb-nist-csf-2-0-crosswalk to keep filenames consistent across your team.