Identify – Develop an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. The activities in the Identify Function are foundational for effective use of the Framework. Understanding the business context, the resources that support critical functions, and the related cybersecurity risks enables an organization to focus and prioritize its efforts, consistent with its risk management strategy and business needs. Examples of outcome Categories within this Function include Asset Management; Business Environment; Governance; Risk Assessment; and Risk Management Strategy.
Protect – Develop and implement appropriate safeguards to ensure delivery of critical services. The Protect Function supports the ability to limit or contain the impact of a potential cybersecurity event. Examples of outcome Categories within this Function include Identity Management and Access Control; Awareness and Training; Data Security; Information Protection Processes and Procedures; Maintenance; and Protective Technology.
Detect – Develop and implement appropriate activities to identify the occurrence of a cybersecurity event. The Detect Function enables the timely discovery of cybersecurity events. Examples of outcome Categories within this Function include Anomalies and Events; Security Continuous Monitoring; and Detection Processes.
Respond – Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. The Respond Function supports the ability to contain the impact of a potential cybersecurity incident. Examples of outcome Categories within this Function include Response Planning; Communications; Analysis; Mitigation; and Improvements.
Recover – Develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity incident. The Recover Function supports timely recovery to normal operations to reduce the impact of a cybersecurity incident. Examples of outcome Categories within this Function include Recovery Planning; Improvements; and Communications.
MONITORING OF THE CYBERSECURITY RISK MANAGEMENT PROGRAM
DC15: The process for conducting ongoing and periodic evaluations of the operating effectiveness of key control activities and other components of internal control related to cybersecurity
The variety of different types of ongoing and separate evaluations used, which may include a combination of periodic and continuous internal audit assessments, penetration testing, and independent certifications made against established security and other specifications (for example, ISO 27001 and HITRUST)
The process for considering the rate of change in business and business processes when selecting and developing such evaluations
The process for performing the ongoing and periodic evaluations, including whether (a) the design and current state of the entity's cybersecurity risk management program, including the controls, are used to establish a baseline; (b) evaluators have sufficient knowledge to understand what is being evaluated; and (c) the scope and frequency of the evaluations is commensurate with the risk
DC16: The process used to evaluate and communicate, in a timely manner, identified security threats, vulnerabilities, and control deficiencies to parties responsible for taking corrective actions, including management and the board of directors, as appropriate
The process by which management and the board of directors, as appropriate, assess results of ongoing and periodic evaluations, including whether the process considers the remediation of identified security threats, vulnerabilities, and control deficiencies
The process for communicating identified security threats, vulnerabilities, and control deficiencies to parties responsible for taking corrective action and to senior management and the board of directors, as appropriate
The process for monitoring remediation of identified deficiencies
DC17: The process for developing a response to assessed risks, including the design and implementation of control processes
The process to align controls with risk responses needed to protect information assets and to detect, respond to, mitigate and recover from security events based on the assessed risks
The consideration of the environment in which the entity operates, the complexity of the environment, the nature and scope of the entity's operations, and its specific characteristics when selecting and developing control processes
The process for including a range and variety of controls (for example, manual and automated controls and preventive and detective controls) in risk mitigation activities to achieve a balanced approach to the mitigation of identified cybersecurity risks
The use of risk transfer strategies, including the purchase of insurance, to address risks that are not addressed by controls
DC18: A summary of the entity's IT infrastructure and its network architectural characteristics
The use of segmentation, where appropriate, and baseline configurations of both physical and virtual endpoints, devices, firewalls, routers, switches, operating systems, databases, and applications
The use of infrastructure and network elements provided by outsourced service providers
DC19: The key security policies and processes implemented and operated to address the entity's cybersecurity risks, including those addressing the following:
The process for establishing retention periods for types of confidential information and identifying the information when received or created and associating the information to a specific retention period
The process for identifying information classified as confidential
The process for preventing the destruction of identified information during its specified retention period
The process for identifying information that has reached the end of its retention period and information that is an exception to the retention policies
The process for destroying information identified for destruction
We hope you are adequately preparing for the new AICPA Assessment criteria. We advise that everyone begins at the end, with DC19. Comparatively, by the size of the implementation guidance, it's a whopper.
As a sample of the size of the last control area in this guidance, here's the text for section DC-19
DC19: The key security policies and processes implemented and operated to address the entity's cybersecurity risks, including those addressing the following:
The process for establishing retention periods for types of confidential information and identifying the information when received or created and associating the information to a specific retention period
The process for identifying information classified as confidential
The process for preventing the destruction of identified information during its specified retention period
The process for identifying information that has reached the end of its retention period and information that is an exception to the retention policies
The process for destroying information identified for destruction
Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics you need to know. (The Perils of Mount Must Read™ Confessions of a Cliff Note Junky) These resources go onto the "Mountain of Must Read". If you don't recognize the standard reference, you've missed critical understanding. As of 2022, this is the minimum NIST alphabet. All of these documents are found at https://csrc.nist.gov/publications/ Be very careful about static content. Look at links before you launch them. Never use alternate sites for the Computer Security Resource Center. Get the full list here <NIST Reading Extended>