NIST Cybersecurity Framework Functions
Controls are mapped to the six functions of the NIST Cybersecurity Framework (CSF) 2.0. The functions organize cybersecurity outcomes at the highest level.
Govern (GV)
Establish and monitor the organization’s cybersecurity risk management strategy, expectations, and policy. Govern provides context for all other functions.
| Control | Title | Owner |
|---|---|---|
| SID-ARCH-02 | Operator-Scope Compliance Obligations | operator |
| SID-ORG-01 | Information Security Policy | operator |
| SID-ORG-02 | Roles, Responsibilities, and Segregation of Duties | operator |
| SID-ORG-04 | Supplier and Third-Party Security | operator |
| SID-ORG-05 | Legal, Regulatory, and Contractual Compliance | operator |
| SID-ORG-06 | Wallet Service Practice Statement | operator |
| SID-ORG-07 | Terms of Service and Privacy Policy | operator |
| SID-OPS-05 | Secure Configuration Management | platform |
Identify (ID)
Understand the organization’s assets, suppliers, and related cybersecurity risks. Prioritize efforts consistent with risk management strategy and business needs.
| Control | Title | Owner |
|---|---|---|
| SID-ARCH-01 | Platform Architecture Non-Applicability Register | platform |
| SID-ORG-03 | Risk Management Framework | operator |
| SID-ORG-08 | Information Classification and Labelling | operator |
| SID-HARD-06 | Wallet Attestation and Environment Integrity | platform |
| SID-OPS-09 | Platform Security Documentation | platform |
| SID-OPS-13 | Operator Security Documentation | operator |
| SID-TRUST-01 | AuthZEN PDP Trust Evaluation Service | platform |
| SID-TRUST-02 | Multi-Registry Trust Framework Support | platform |
Protect (PR)
Implement safeguards to ensure delivery of critical services and reduce the likelihood and impact of cybersecurity events.
| Control | Title | Owner |
|---|---|---|
| SID-ACCESS-01 | Multi-Tenant Isolation | platform |
| SID-ACCESS-02 | Rate Limiting and Brute-Force Protection | platform |
| SID-ACCESS-03 | User Consent Before Credential Disclosure | platform |
| SID-ACCESS-04 | SPOCP Policy-Based Query Authorization | platform |
| SID-AUTH-01 | FIDO2/WebAuthn Passwordless Authentication | platform |
| SID-AUTH-02 | JWT Bearer Token Session Management | platform |
| SID-AUTH-03 | OIDC Gate for External Identity Providers | platform |
| SID-AUTH-04 | WebSocket JWT Handshake Authentication | platform |
| SID-AUTH-05 | Wallet Unlock, Lockout, and PIN Security | platform |
| SID-AUTH-06 | Wallet Lifecycle Management | platform |
| SID-CRYPTO-01 | PKCS#11 HSM Key Protection | platform |
| SID-CRYPTO-02 | PRF Extension Key Derivation | platform |
| SID-CRYPTO-03 | AES-256-GCM Encrypted Keystore | platform |
| SID-CRYPTO-04 | COSE Sign1 and mDOC Cryptography | platform |
| SID-CRYPTO-05 | Secure Random Number Generation | platform |
| SID-DATA-01 | SD-JWT Selective Disclosure | platform |
| SID-DATA-02 | mDOC Element-Level Selective Disclosure | platform |
| SID-DATA-03 | Credential Revocation via Token Status List | platform |
| SID-DATA-04 | VCTM Schema Validation | platform |
| SID-DATA-06 | PII Field Encryption for User Records | platform |
| SID-DATA-07 | Credential Re-issuance and Lifecycle Management | platform |
| SID-DATA-08 | Server-Side Data Cache Protection | platform |
| SID-DATA-09 | Runtime Memory Protection | platform |
| SID-DATA-10 | Wallet Backup Security | platform |
| SID-HARD-01 | Error Message Sanitization | platform |
| SID-HARD-02 | Input Validation and Injection Prevention | platform |
| SID-HARD-03 | Network Segmentation (Separate Server Ports) | platform |
| SID-HARD-04 | Secure Registration Enforcement | platform |
| SID-HARD-05 | Browser Security Controls | platform |
| SID-HARD-07 | Resource Upload Constraints | platform |
| SID-HARD-08 | Sensitive Data UI Protection | platform |
| SID-HARD-09 | Application Resilience and Anti-Tampering | platform |
| SID-KEY-01 | WSCA WebSocket Key Signing Delegation | platform |
| SID-KEY-02 | IACA Certificate Management | platform |
| SID-KEY-03 | WSCD Client Library with rawSign API | platform |
| SID-KEY-04 | R2PS Remote WSCD SCAL2 Compliance | platform |
| SID-OPS-08 | Secure Development Lifecycle | platform |
| SID-OPS-12 | Deployment Environment Separation | operator |
| SID-OPS-10 | Encryption-at-Rest and Secrets Management | operator |
| SID-OPS-11 | Data Leakage Prevention — Infrastructure Controls | operator |
| SID-PPL-01 | Personnel Screening and Onboarding | operator |
| SID-PPL-02 | Security Awareness, Education, and Training | operator |
| SID-PPL-03 | Confidentiality and Non-Disclosure Agreements | operator |
| SID-PHY-01 | Data Center Physical Security | operator |
| SID-PHY-02 | Equipment and Media Security | operator |
| SID-PRIV-01 | Minimal Disclosure Enforcement | platform |
| SID-PRIV-02 | VP Nonce Binding (Anti-Replay) | platform |
| SID-PRIV-03 | Right-to-Erasure Bulk Deletion API | platform |
| SID-PRIV-04 | Pseudonymous Authentication | platform |
| SID-TRANS-01 | TLS 1.2+ Minimum with Configurable Version | platform |
| SID-TRANS-02 | OpenID4VCI Credential Issuance Protocol | platform |
| SID-TRANS-03 | OpenID4VP Credential Presentation Protocol | platform |
| SID-TRANS-04 | SSRF-Protected HTTP Client | platform |
| SID-TRANS-05 | Operator TLS Deployment Enforcement | operator |
| SID-TRUST-03 | Issuer and Verifier Trust Gating | platform |
| SID-TRUST-04 | Trust Decision Caching with Circuit Breaker | platform |
| SID-TRUST-05 | Relying Party Registration and Over-Request Detection | platform |
Detect (DE)
Develop and implement activities to identify the occurrence of a cybersecurity event in a timely manner.
| Control | Title | Owner |
|---|---|---|
| SID-AUDIT-01 | Structured Security Event Logging | platform |
| SID-AUDIT-02 | Privacy-Preserving Audit Event Taxonomy | platform |
| SID-OPS-04 | Vulnerability Management | platform |
| SID-OPS-06 | Monitoring and Alerting | operator |
| SID-OPS-07 | Fraud Management | operator |
| SID-PPL-04 | Information Security Event Reporting | operator |
Respond (RS)
Take action regarding a detected cybersecurity incident to contain its impact.
| Control | Title | Owner |
|---|---|---|
| SID-OPS-01 | Incident Response and Management | operator |
Recover (RC)
Maintain plans for resilience and restore capabilities or services impaired by a cybersecurity incident.
| Control | Title | Owner |
|---|---|---|
| SID-OPS-02 | Business Continuity and ICT Readiness | operator |
| SID-OPS-03 | Backup and Recovery | operator |