<-- Back
function category code description column4
Govern Organizational Context GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
Govern Risk Management Strategy GV.RM-01 Risk management objectives are established and agreed tby organizational stakeholders
Govern Risk Management Strategy GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Govern Risk Management Strategy GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
Govern Oversight GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
Govern Oversight GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
Govern Oversight GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
Govern Cybersecurity Supply Chain Risk Management GV.SC-04 Suppliers are known and prioritized by criticality
Govern Cybersecurity Supply Chain Risk Management GV.SC-06 Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
Govern Cybersecurity Supply Chain Risk Management GV.SC-10 Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement
Identify ID The organization's current cybersecurity risks are understood
Identify Asset Management ID.AM-01 Inventories of hardware managed by the organization are maintained
Identify Asset Management ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained
Identify Asset Management ID.AM-04 Inventories of services provided by suppliers are maintained
Identify Asset Management ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
Identify Risk Assessment ID.RA-02 Cyber threat intelligence is received from information sharing forums and sources
Identify Risk Assessment ID.RA-03 Internal and external threats to the organization are identified and recorded
Identify Risk Assessment ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Identify Risk Assessment ID.RA-09 The authenticity and integrity of hardware and software are assessed prior to acquisition and use
Identify Risk Assessment ID.RA-10 Critical suppliers are assessed prior to acquisition
Identify Improvement ID.IM-02: Improvements are identified from security tests and exercises including those done in coordination with suppliers and relevant third parties
Protect PR Safeguards to manage the organization's cybersecurity risks are used
Protect Identity Management; Authentication; and Access Control PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
Protect Awareness and Training PR.AT The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
Protect Awareness and Training PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
Protect Awareness and Training PR.AT-02 Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind
Protect Platform Security PR.PS-01 Configuration management practices are established and applied
Protect Platform Security PR.PS-04 Log records are generated and made available for continuous monitoring
Protect Platform Security PR.PS-05 Installation and execution of unauthorized software are prevented
Protect Technology Infrastructure Resilience PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
Protect Technology Infrastructure Resilience PR.IR-02 The organization's technology assets are protected from environmental threats
Protect Technology Infrastructure Resilience PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Protect Technology Infrastructure Resilience PR.IR-04 Adequate resource capacity to ensure availability is maintained
Detect DE Possible cybersecurity attacks and compromises are found and analyzed
Detect Continuous Monitoring DE.CM-01 Networks and network services are monitored to find potentially adverse events
Detect Continuous Monitoring DE.CM-02 The physical environment is monitored to find potentially adverse events
Detect Continuous Monitoring DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
Detect Continuous Monitoring DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
Detect Adverse Event Analysis DE.AE-02 Potentially adverse events are analyzed to better understand associated activities
Detect Adverse Event Analysis DE.AE-03 Information is correlated from multiple sources
Detect Adverse Event Analysis DE.AE-04 The estimated impact and scope of adverse events are understood
Detect Adverse Event Analysis DE.AE-06 Information on adverse events is provided to authorized staff and tools
Detect Adverse Event Analysis DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
Detect Adverse Event Analysis DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
Respond RS Actions regarding a detected cybersecurity incident are taken
Respond Incident Management RS.MA Responses to detected cybersecurity incidents are managed
Respond Incident Management RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared
Respond Incident Management RS.MA-02 Incident reports are triaged and validated
Respond Incident Management RS.MA-03 Incidents are categorized and prioritized
Respond Incident Management RS.MA-04 Incidents are escalated or elevated as needed
Respond Incident Management RS.MA-05 The criteria for initiating incident recovery are applied
Respond Incident Analysis RS.AN Investigations are conducted to ensure effective response and support forensics and recovery activities
Respond Incident Analysis RS.AN-03 Analysis is performed to establish what has taken place during an incident and the root cause of the incident
Respond Incident Analysis RS.AN-06 Actions performed during an investigation are recorded and the records' integrity and provenance are preserved
Respond Incident Analysis RS.AN-07 Incident data and metadata are collected and their integrity and provenance are preserved
Respond Incident Analysis RS.AN-08 An incident's magnitude is estimated and validated
Respond Incident Response Reporting and Communication RS.CO Response activities are coordinated with internal and external stakeholders as required by laws; regulations or policies
Respond Incident Response Reporting and Communication RS.CO-02 Internal and external stakeholders are notified of incidents
Respond Incident Response Reporting and Communication RS.CO-03 Information is shared with designated internal and external stakeholders
Respond Incident Mitigation RS.MI Activities are performed to prevent expansion of an event and mitigate its effects
Respond Incident Mitigation RS.MI-01 Incidents are contained
Respond Incident Mitigation RS.MI-02 Incidents are eradicated
Recover RC Assets and operations affected by a cybersecurity incident are restored
Recover Incident Recovery Plan Execution RC.RP Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents
Recover Incident Recovery Plan Execution RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
Recover Incident Recovery Plan Execution RC.RP-02 Recovery actions are selected; scoped; prioritized and performed
Recover Incident Recovery Plan Execution RC.RP-03 The integrity of backups and other restoration assets is verified before using them for restoration
Recover Incident Recovery Plan Execution RC.RP-04 Critical mission functions and cybersecurity risk management are considered t0 establish post-incident operational norms
Recover Incident Recovery Plan Execution RC.RP-05 The integrity of restored assets is verified; systems and services are restored and normal operating status is confirmed
Recover Incident Recovery Plan Execution RC.RP-06 The end of incident recovery is declared based on criteria; and incident related documentation is completed
Recover Incident Recovery Communication RC.CO Restoration activities are coordinated with internal and external parties
Recover Incident Recovery Communication RC.CO-03 Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders