Identify – Develop an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. The activities in the Identify Function are foundational for effective use of the Framework. Understanding the business context, the resources that support critical functions, and the related cybersecurity risks enables an organization to focus and prioritize its efforts, consistent with its risk management strategy and business needs. Examples of outcome Categories within this Function include Asset Management; Business Environment; Governance; Risk Assessment; and Risk Management Strategy.
Protect – Develop and implement appropriate safeguards to ensure delivery of critical services. The Protect Function supports the ability to limit or contain the impact of a potential cybersecurity event. Examples of outcome Categories within this Function include Identity Management and Access Control; Awareness and Training; Data Security; Information Protection Processes and Procedures; Maintenance; and Protective Technology.
Detect – Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. The Detect Function enables the timely discovery of cybersecurity events. Examples of outcome Categories within this Function include Anomalies and Events; Security Continuous Monitoring; and Detection Processes.
Respond – Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. The Respond Function supports the ability to contain the impact of a potential cybersecurity incident. Examples of outcome Categories within this Function include Response Planning; Communications; Analysis; Mitigation; and Improvements.
Recover – Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. The Recover Function supports timely recovery to normal operations to reduce the impact of a cybersecurity incident. Examples of outcome Categories within this Function include Recovery Planning; Improvements; and Communications.
DC7: The process for establishing, maintaining, and communicating integrity and ethical values to support the functioning of the cybersecurity risk management program
How management sets the tone at the top
The establishment and enforcement of standards of conduct for entity personnel
The process used to identify and remedy deviations from established standards
Consideration of contractors and vendors in process for establishing standards of conduct, evaluating adherence to those standards, and addressing deviations in a timely manner
DC8: The process for board oversight of the entity's cybersecurity risk management program
The extent of the board of directors' cybersecurity and IT expertise or access to external cybersecurity and IT expertise, or both
Identification of the board committee designated with oversight of the entity's cybersecurity risk management program, if any
The frequency and detail with which the board or committee reviews or provides input into cybersecurity-related matters, including board oversight of security incidents
DC9: Established cybersecurity accountability and reporting lines
The responsibility for the review and oversight of the cybersecurity risk management program by senior management
The identification of the designated cybersecurity leader (for example, chief information security officer), and the reporting of that individual to executive management and board of directors
The roles and responsibilities of entity personnel who perform cybersecurity controls and activities
The process for addressing the oversight and management of external parties (for example, vendors) when establishing structures, reporting lines, authorities, and responsibilities
DC10: The process used to hire and develop competent individuals and contractors and to hold those individuals accountable for their cybersecurity responsibilities
The process for considering the competence of qualified personnel with cybersecurity responsibilities, including the performance of background checks, assessment of educational levels and certifications, requirements for ongoing training, hiring contractors, and the use of offshore recruiting
The program for providing cybersecurity awareness and training to employees and contractors based on their cybersecurity responsibilities and access to information and information systems
The process for making sure that employees and contractors have the resources necessary to carry out their cybersecurity responsibilities
The process for identifying the types and levels of cybersecurity professionals needed
The processes used to communicate performance expectations and hold individuals accountable for the performance of their responsibilities
The processes to update communication and accountability mechanisms and monitor employee compliance with their responsibilities and entity policies
The process used to reward individuals for performance and the process used to align the measures used to the achievement of the entity's objectives
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics you need to know. (The Perils of Mount Must Read™ Confessions of a Cliff Note Junky) These resources go onto the "Mountain of Must Read". If you don't recognize the standard reference, you've missed critical understanding. As of 2022, this is the minimum NIST alphabet. All of these documents are found at https://csrc.nist.gov/publications/ Be very careful about static content. Look at links before you launch them. Never use alternate sites for the Computer Security Resource Center. Get the full list here <NIST Reading Extended>