What does NIST Cybersecurity Framework mean on the CPA exam?
NIST Cybersecurity Framework. A voluntary framework of cybersecurity outcomes organized into functions. Version 2.0, released February 2024, has SIX: Govern, Identify, Protect, Detect, Respond and Recover. Govern was added in 2.0, so a source listing five functions is describing version 1.1 or earlier.
Defined against NIST CSWP 29 (CSF 2.0).
Which CPA exam sections use NIST Cybersecurity Framework?
NIST Cybersecurity Framework appears in the ISC section of the CPA exam.
Related terms
- applicable financial reporting framework: The framework management adopts for the statements, such as GAAP or a special purpose framework.
- COSO Internal Control - Integrated Framework: The reference model for internal control: five components and seventeen principles, all of which must be present and functioning for control to be effective.
- control environment: The governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's system of internal control.