NIST CSF PR.PS - Platform Security
Manage platform security through configuration management, software and hardware lifecycle management, logging, unauthorized software prevention, and secure software development practices
Where this comes from
Provision: PR.PS - Platform Security
Instrument: NIST Cybersecurity Framework 2.0 (February 2024)
Citation: NIST Cybersecurity Framework 2.0, February 26, 2024, Section PR.PS (Platform Security), Sub-categories PR.PS-01 through PR.PS-06
Text version: CSF 2.0
Who it applies to
It applies when all of these are true:
- Service type — any answer
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Personal data is encrypted in transit and at rest
- Access to personal data is role-restricted and access is logged
- A documented incident-response / breach-notification procedure exists and is tested
- Third-party processors are bound by equivalent security obligations
- Unauthorized role cannot read personal-data endpoints (403)
Questions people ask
- Does NIST CSF PR.PS - Platform Security apply to my service?
- It applies when Service type — any answer.
- From when does this apply?
- NIST CSF PR.PS - Platform Security applies from 26 February 2024. Its current status is: in force.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.