NIST CSF 2.0 · derived mapping target
ID.IM-02Improvements from tests and exercises
Use the results of security tests and exercises, including ones run with suppliers and partners, to find and make improvements.
Mapping at a glance
ID.IM-02Improvements from tests and exercisesNIST CSF 2.0
ID.IM-02 is covered by 9 Sekit CSF controls. +4 more in the table below. Open in the full graph →
Mapped from the Sekit CSF
The Sekit controls that cover this requirement, lens by lens.
RCF-0019Metrics & reporting · PolicyRCF-0020Metrics & reporting · ProcessRCF-0021Metrics & reporting · TechnicalRCF-0031Control testing program · PolicyRCF-0032Control testing program · ProcessRCF-0033Control testing program · TechnicalRCF-0220Vulnerability remediation SLAs · PolicyRCF-0221Vulnerability remediation SLAs · ProcessRCF-0222Vulnerability remediation SLAs · Technical
ISO/IEC 27001:2022 counterparts
Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.
ISO/IEC 42001:2023 — Annex A counterparts
Cyber Essentials counterparts
Evidence that proves this control
What an auditor, or Sekit's evidence engine, asks for.
Incident playbooks, exercises and forensics readiness
The step-by-step guides for the most likely incidents, the tabletop exercises, the post-incident review reports, and how evidence is preserved so an incident can be investigated.
Phishing simulation results
The proof that phishing simulations are run to test employees and the follow-up training given to those who fall for them.
From the Sekit evidence catalog
Related controls
Via the shared Sekit CSF topic, not the framework's own index.
Ask Sekura: “What evidence proves ID.IM-02?”
Also via MCP, free with account