Identify – Develop an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. The activities in the Identify Function are foundational for effective use of the Framework. Understanding the business context, the resources that support critical functions, and the related cybersecurity risks enables an organization to focus and prioritize its efforts, consistent with its risk management strategy and business needs. Examples of outcome Categories within this Function include Asset Management; Business Environment; Governance; Risk Assessment; and Risk Management Strategy.
Protect – Develop and implement appropriate safeguards to ensure delivery of critical services. The Protect Function supports the ability to limit or contain the impact of a potential cybersecurity event. Examples of outcome Categories within this Function include Identity Management and Access Control; Awareness and Training; Data Security; Information Protection Processes and Procedures; Maintenance; and Protective Technology.
Detect – Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. The Detect Function enables the timely discovery of cybersecurity events. Examples of outcome Categories within this Function include Anomalies and Events; Security Continuous Monitoring; and Detection Processes.
Respond – Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. The Respond Function supports the ability to contain the impact of a potential cybersecurity incident. Examples of outcome Categories within this Function include Response Planning; Communications; Analysis; Mitigation; and Improvements.
Recover – Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. The Recover Function supports timely recovery to normal operations to reduce the impact of a cybersecurity incident. Examples of outcome Categories within this Function include Recovery Planning; Improvements; and Communications.
DC11: The process for (1) identifying cybersecurity risks and environmental, technological, organizational and other changes that could have a significant effect on the entity's cybersecurity risk management program and (2) assessing the related risks to the achievement of the entity's cybersecurity objectives
The use of new technologies
Changes to the regulatory, economic, and physical environment in which the entity operates
New business lines
Changes to the composition of existing business lines
Changes in available resources
Acquired or divested business operations
Rapid growth
Changing operational presence in foreign countries
Changing political climates
DC12: The process for identifying, assessing, and managing the risks associated with vendors and business partners
Establishing specific requirements for a vendor and other business partner engagement that includes scope of services and product specifications, roles and responsibilities, compliance requirements, and service levels
Assessing, on a periodic basis, the risks that the vendors and business partners represent to the achievement of the entity's objectives, including risks that arise from those entities' relevant vendors and business partners (often referred to as fourth party risk)
Assigning responsibility and accountability for the management of associated risks
Establishing communication and resolution protocols for service and product issues, including reporting of identified threats
Establishing exception-handling procedures
Periodically assessing the performance of vendors and business partners and those entities' relevant vendors and business partners
Implementing procedures for addressing associated risks
CYBERSECURITY COMMUNICATIONS AND QUALITY OF CYBERSECURITY INFORMATION
DC13: The process for internally communicating relevant cybersecurity information necessary to support the functioning of the entity's cybersecurity risk management program, including (1) objectives and responsibilities for cybersecurity and (2) thresholds for communicating identified security events that are monitored, investigated, and determined to be security incidents requiring a response, remediation, or both
Awareness programs, including training about detecting and avoiding social engineering threats and security breach reporting and response
Job descriptions
Acknowledgement of code of conduct and policies,
Employee signed confidentiality agreements, and
Policy and procedures manuals)
DC14: The process for communicating with external parties regarding matters affecting the functioning of the entity's cybersecurity risk management program
The existence and use of open communication channels that allow input from customers, consumers, vendors, business partners, external auditors, regulators, financial analysts, and others to provide management and the board of directors with relevant information
The process for creating and updating communications regarding cybersecurity, including considerations of timing, audience, and nature of information when selecting the communication method to be used
The use of various communication channels, such as whistle-blower hotlines, to enable anonymous or confidential communication when normal channels are inoperative or ineffective
The process by which legal, regulatory, and fiduciary requirements, including required communication of data breaches and incidents, are considered when making communications
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics you need to know. (The Perils of Mount Must Read™ Confessions of a Cliff Note Junky) These resources go onto the "Mountain of Must Read". If you don't recognize the standard reference, you've missed critical understanding. As of 2022, this is the minimum NIST alphabet. All of these documents are found at https://csrc.nist.gov/publications/ Be very careful about static content. Look at links before you launch them. Never use alternate sites for the Computer Security Resource Center. Get the full list here <NIST Reading Extended>