| Govern |
Organizational Context |
GV.OC-01 |
The organizational mission is understood and informs cybersecurity risk management |
|
| Govern |
Risk Management Strategy |
GV.RM-01 |
Risk management objectives are established and agreed tby organizational stakeholders |
|
| Govern |
Risk Management Strategy |
GV.RM-03 |
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes |
|
| Govern |
Risk Management Strategy |
GV.RM-04 |
Strategic direction that describes appropriate risk response options is established and communicated |
|
| Govern |
Oversight |
GV.OV-01 |
Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction |
|
| Govern |
Oversight |
GV.OV-02 |
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks |
|
| Govern |
Oversight |
GV.OV-03 |
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed |
|
| Govern |
Cybersecurity Supply Chain Risk Management |
GV.SC-04 |
Suppliers are known and prioritized by criticality |
|
| Govern |
Cybersecurity Supply Chain Risk Management |
GV.SC-06 |
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships |
|
| Govern |
Cybersecurity Supply Chain Risk Management |
GV.SC-10 |
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement |
|
| Identify |
|
ID |
The organization's current cybersecurity risks are understood |
|
| Identify |
Asset Management |
ID.AM-01 |
Inventories of hardware managed by the organization are maintained |
|
| Identify |
Asset Management |
ID.AM-03 |
Representations of the organization's authorized network communication and internal and external network data flows are maintained |
|
| Identify |
Asset Management |
ID.AM-04 |
Inventories of services provided by suppliers are maintained |
|
| Identify |
Asset Management |
ID.AM-07 |
Inventories of data and corresponding metadata for designated data types are maintained |
|
| Identify |
Risk Assessment |
ID.RA-02 |
Cyber threat intelligence is received from information sharing forums and sources |
|
| Identify |
Risk Assessment |
ID.RA-03 |
Internal and external threats to the organization are identified and recorded |
|
| Identify |
Risk Assessment |
ID.RA-04 |
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded |
|
| Identify |
Risk Assessment |
ID.RA-09 |
The authenticity and integrity of hardware and software are assessed prior to acquisition and use |
|
| Identify |
Risk Assessment |
ID.RA-10 |
Critical suppliers are assessed prior to acquisition |
|
| Identify |
Improvement |
ID.IM-02: Improvements are identified from security tests and exercises |
including those done in coordination with suppliers and relevant third parties |
|
| Protect |
|
PR |
Safeguards to manage the organization's cybersecurity risks are used |
|
| Protect |
Identity Management; Authentication; and Access Control |
PR.AA-02 |
Identities are proofed and bound to credentials based on the context of interactions |
|
| Protect |
Awareness and Training |
PR.AT |
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks |
|
| Protect |
Awareness and Training |
PR.AT-01 |
Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind |
|
| Protect |
Awareness and Training |
PR.AT-02 |
Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind |
|
| Protect |
Platform Security |
PR.PS-01 |
Configuration management practices are established and applied |
|
| Protect |
Platform Security |
PR.PS-04 |
Log records are generated and made available for continuous monitoring |
|
| Protect |
Platform Security |
PR.PS-05 |
Installation and execution of unauthorized software are prevented |
|
| Protect |
Technology Infrastructure Resilience |
PR.IR-01 |
Networks and environments are protected from unauthorized logical access and usage |
|
| Protect |
Technology Infrastructure Resilience |
PR.IR-02 |
The organization's technology assets are protected from environmental threats |
|
| Protect |
Technology Infrastructure Resilience |
PR.IR-03 |
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations |
|
| Protect |
Technology Infrastructure Resilience |
PR.IR-04 |
Adequate resource capacity to ensure availability is maintained |
|
| Detect |
|
DE |
Possible cybersecurity attacks and compromises are found and analyzed |
|
| Detect |
Continuous Monitoring |
DE.CM-01 |
Networks and network services are monitored to find potentially adverse events |
|
| Detect |
Continuous Monitoring |
DE.CM-02 |
The physical environment is monitored to find potentially adverse events |
|
| Detect |
Continuous Monitoring |
DE.CM-03 |
Personnel activity and technology usage are monitored to find potentially adverse events |
|
| Detect |
Continuous Monitoring |
DE.CM-06 |
External service provider activities and services are monitored to find potentially adverse events |
|
| Detect |
Adverse Event Analysis |
DE.AE-02 |
Potentially adverse events are analyzed to better understand associated activities |
|
| Detect |
Adverse Event Analysis |
DE.AE-03 |
Information is correlated from multiple sources |
|
| Detect |
Adverse Event Analysis |
DE.AE-04 |
The estimated impact and scope of adverse events are understood |
|
| Detect |
Adverse Event Analysis |
DE.AE-06 |
Information on adverse events is provided to authorized staff and tools |
|
| Detect |
Adverse Event Analysis |
DE.AE-07 |
Cyber threat intelligence and other contextual information are integrated into the analysis |
|
| Detect |
Adverse Event Analysis |
DE.AE-08 |
Incidents are declared when adverse events meet the defined incident criteria |
|
| Respond |
|
RS |
Actions regarding a detected cybersecurity incident are taken |
|
| Respond |
Incident Management |
RS.MA |
Responses to detected cybersecurity incidents are managed |
|
| Respond |
Incident Management |
RS.MA-01 |
The incident response plan is executed in coordination with relevant third parties once an incident is declared |
|
| Respond |
Incident Management |
RS.MA-02 |
Incident reports are triaged and validated |
|
| Respond |
Incident Management |
RS.MA-03 |
Incidents are categorized and prioritized |
|
| Respond |
Incident Management |
RS.MA-04 |
Incidents are escalated or elevated as needed |
|
| Respond |
Incident Management |
RS.MA-05 |
The criteria for initiating incident recovery are applied |
|
| Respond |
Incident Analysis |
RS.AN |
Investigations are conducted to ensure effective response and support forensics and recovery activities |
|
| Respond |
Incident Analysis |
RS.AN-03 |
Analysis is performed to establish what has taken place during an incident and the root cause of the incident |
|
| Respond |
Incident Analysis |
RS.AN-06 |
Actions performed during an investigation are recorded and the records' integrity and provenance are preserved |
|
| Respond |
Incident Analysis |
RS.AN-07 |
Incident data and metadata are collected and their integrity and provenance are preserved |
|
| Respond |
Incident Analysis |
RS.AN-08 |
An incident's magnitude is estimated and validated |
|
| Respond |
Incident Response Reporting and Communication |
RS.CO |
Response activities are coordinated with internal and external stakeholders as required by laws; regulations or policies |
|
| Respond |
Incident Response Reporting and Communication |
RS.CO-02 |
Internal and external stakeholders are notified of incidents |
|
| Respond |
Incident Response Reporting and Communication |
RS.CO-03 |
Information is shared with designated internal and external stakeholders |
|
| Respond |
Incident Mitigation |
RS.MI |
Activities are performed to prevent expansion of an event and mitigate its effects |
|
| Respond |
Incident Mitigation |
RS.MI-01 |
Incidents are contained |
|
| Respond |
Incident Mitigation |
RS.MI-02 |
Incidents are eradicated |
|
| Recover |
|
RC |
Assets and operations affected by a cybersecurity incident are restored |
|
| Recover |
Incident Recovery Plan Execution |
RC.RP |
Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents |
|
| Recover |
Incident Recovery Plan Execution |
RC.RP-01 |
The recovery portion of the incident response plan is executed once initiated from the incident response process |
|
| Recover |
Incident Recovery Plan Execution |
RC.RP-02 |
Recovery actions are selected; scoped; prioritized and performed |
|
| Recover |
Incident Recovery Plan Execution |
RC.RP-03 |
The integrity of backups and other restoration assets is verified before using them for restoration |
|
| Recover |
Incident Recovery Plan Execution |
RC.RP-04 |
Critical mission functions and cybersecurity risk management are considered t0 establish post-incident operational norms |
|
| Recover |
Incident Recovery Plan Execution |
RC.RP-05 |
The integrity of restored assets is verified; systems and services are restored and normal operating status is confirmed |
|
| Recover |
Incident Recovery Plan Execution |
RC.RP-06 |
The end of incident recovery is declared based on criteria; and incident related documentation is completed |
|
| Recover |
Incident Recovery Communication |
RC.CO |
Restoration activities are coordinated with internal and external parties |
|
| Recover |
Incident Recovery Communication |
RC.CO-03 |
Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders |
|