Identify – Develop an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. The activities in the Identify Function are foundational for effective use of the Framework. Understanding the business context, the resources that support critical functions, and the related cybersecurity risks enables an organization to focus and prioritize its efforts, consistent with its risk management strategy and business needs. Examples of outcome Categories within this Function include Asset Management; Business Environment; Governance; Risk Assessment; and Risk Management Strategy.
Protect – Develop and implement appropriate safeguards to ensure delivery of critical services. The Protect Function supports the ability to limit or contain the impact of a potential cybersecurity event. Examples of outcome Categories within this Function include Identity Management and Access Control; Awareness and Training; Data Security; Information Protection Processes and Procedures; Maintenance; and Protective Technology.
Detect – Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. The Detect Function enables the timely discovery of cybersecurity events. Examples of outcome Categories within this Function include Anomalies and Events; Security Continuous Monitoring; and Detection Processes.
Respond – Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. The Respond Function supports the ability to contain the impact of a potential cybersecurity incident. Examples of outcome Categories within this Function include Response Planning; Communications; Analysis; Mitigation; and Improvements.
Recover – Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. The Recover Function supports timely recovery to normal operations to reduce the impact of a cybersecurity incident. Examples of outcome Categories within this Function include Recovery Planning; Improvements; and Communications.
CYBERSECURITY RISK MANAGEMENT PROGRAM OBJECTIVES (CYBERSECURITY OBJECTIVES)
DC4: The process for establishing, maintaining, and approving cybersecurity objectives to support the achievement of the entity's objectives
The process for establishing cybersecurity objectives based on the entity's business and strategic objectives established by the board of directors and management
The process for obtaining board of director or executive management approval of the entity's cybersecurity objectives
The use of security management and control frameworks in establishing the entity's cybersecurity objectives and developing and maintaining controls within the entity's cybersecurity risk management program, including disclosure of the particular framework(s) used (for example, NIST Cybersecurity Framework, ISO 27001/2 and related frameworks, or internally- developed frameworks based on a combination of sources)
FACTORS THAT HAVE A SIGNIFICANT EFFECT ON INHERENT CYBERSECURITY RISKS
DC5: Factors that have a significant effect on the entity's inherent cybersecurity risks, including the (1) characteristics of technologies, connection types, use of service providers, and delivery channels used by the entity, (2) organizational and user characteristics, and (3) environmental, technological, organizational and other changes during the period covered by the description at the entity and in its environment.
Changes to the entity's principal products, services, or distribution methods
Significant changes to entity processes, IT architecture and applications, and the processes and systems used by outsourced service providers
Acquisitions and other business units that have not been fully integrated into the cybersecurity risk management program including the integration or segmentation strategy used for the acquiree's IT systems, and the current state of those activities
Changes to legal and regulatory requirements
Divestures and other cessation of operations, particularly those that have ongoing service support obligations for systems related to those operations (if any), and the current status of those activities
DC6: For security incidents that (1) were identified during the 12-month period preceding the period end date of management's description and (2) resulted in a significant impairment of the entity's achievement of its cybersecurity objectives, disclosure of the following (a) nature of the incident; (b) timing surrounding the incident; and (c) extent (or effect) of those incidents and their disposition
Was considered sufficiently significant based on law or regulation to require public disclosure
Had a material effect on the financial position or results of operations and required disclosure in financial statement filings
Resulted in sanctions by any legal or regulatory agency
Resulted in withdrawal from material markets or cancellation of material contracts
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics you need to know. (The Perils of Mount Must Read™ Confessions of a Cliff Note Junky) These resources go onto the "Mountain of Must Read". If you don't recognize the standard reference, you've missed critical understanding. As of 2022, this is the minimum NIST alphabet. All of these documents are found at https://csrc.nist.gov/publications/ Be very careful about static content. Look at links before you launch them. Never use alternate sites for the Computer Security Resource Center. Get the full list here <NIST Reading Extended>