NATURE OF BUSINESS AND OPERATIONS

DC1: The nature of the entity's business and operations, including the principal products or services
  • The entity's principal markets, including the geographic locations of those markets, and changes to those markets
  • If the entity operates more than one business, the relative importance of the entity's operations in each business and the basis for management's determination (for example, revenues or asset values)

NATURE OF INFORMATION AT RISK

DC2: The principal types of sensitive information created, collected, transmitted, used, or stored by the entity

  • Information regarding individuals that warrants protection based on law, commitment, or reasonable expectation of confidentiality (for example, personally identifiable information, protected health information, and payment card data)
  • Third-party entity information (for example, information subject to confidentiality requirements in contracts) that warrants protection based on law, commitment, or reasonable expectation of confidentiality, availability, and integrity
  • Entity information (for example, trade secrets, corporate strategy, and financial and operational data) whose confidentiality, availability and integrity is necessary to the achievement of the entity's business objectives
DC3: The entity's principal cybersecurity risk management program objectives (cybersecurity objectives) related to availability, confidentiality, integrity of data, and integrity of processing
  • The accuracy, completeness, and reliability of information, goods, and services produced
  • The safeguarding of entity assets
  • Safeguarding of life and health
Main Menu