Foreword xvii Acknowledgements xix 1 Overview of Risk Management and the NIST Cybersecurity Framework 1 1.1 Brief Overview of Risk Management Principles 1 1.1.1 The Core Journey of Risk Management 2 1.1.1.1 Identify Risks 2 1.1.
1.2 Analyze and Evaluate Risks 2 1.1.1.3 Control and Mitigate Risks 2 1.1.1.4 Monitor and Review Risks 2 1.
1.2 Cultivating a Resilient Organization 3 1.2 Background on the NIST Cybersecurity Framework 3 1.2.1 Six Basic Functions 4 1.2.1.1 Identify (ID) 4 1.
2.1.2 Protect (PR) 5 1.2.1.3 Detect (DE) 5 1.2.1.
4 Respond (RS) 5 1.2.1.5 Recover (RC) 6 1.2.1.6 Govern (GV) 6 1.2.
2 Overview of Additional CSF Core Elements 6 1.2.2.1 Categories 6 1.2.2.2 Subcategories 6 1.2.
2.3 Implementation Examples 7 1.2.2.4 Informative References 7 1.2.3 Other Vital Elements of the CSF 8 1.2.
3.1 Framework Profiles 8 1.2.3.2 Implementation Tiers 8 1.2.4 How the NIST Framework Jives with the Parkerian Hexad 9 2 NIST Function Identify 11 2.1 IDENTIFY (ID): The Organization''s Current Cybersecurity Risks Are Understood 12 2.
1.1 Asset Management (ID.AM): Assets (e.g., Data, Hardware, Software, Systems, Facilities, Services, People) That Enable the Organization to Achieve Business Purposes Are Identified and Managed Consistently with Their Relative Importance to Organizational Objectives and the Organization''s Risk Strategy 12 2.1.1.1 ID.
AM-01: Inventories of Hardware Managed by the Organization Are Maintained 13 2.1.1.2 ID.AM-02: Inventories of Software, Services, and Systems Managed by the Organization Are Maintained 14 2.1.1.3 ID.
AM-03: Representations of the Organization''s Authorized Network Communication and Internal and External Network Data Flows Are Maintained 15 2.1.1.4 ID.AM-04: Inventories of Services Provided by Suppliers Are Maintained 16 2.1.1.5 ID.
AM-05: Assets Are Prioritized Based on Classification, Criticality, Resources, and Impact on the Mission 17 2.1.1.6 ID.AM-07: Inventories of Data and Corresponding Metadata for Designated Data Types Are Maintained (Note ID.AM-06 Is Now Incorporated into GV.RR-02, GV.SC-02) 18 2.
1.1.7 ID.AM-08: Systems, Hardware, Software, Services, and Data Are Managed Throughout Their Life Cycles 19 2.1.2 Risk Assessment (ID.RA): The Cybersecurity Risk to the Organization, Assets, and Individuals Is Understood by the Organization 21 2.1.
2.1 ID.RA-01: Vulnerabilities in Assets Are Identified, Validated, and Recorded 22 2.1.2.2 ID.RA-02: Cyber Threat Intelligence Is Received from Information-sharing Forums and Sources 23 2.1.
2.3 ID.RA-03: Internal and External Threats to the Organization Are Identified and Recorded 24 2.1.2.4 ID.RA-04: Potential Impacts and Likelihoods of Threats Exploiting Vulnerabilities Are Identified and Recorded 25 2.1.
2.5 ID.RA-05: Threats, Vulnerabilities, Likelihoods, and Impacts Are Used to Understand Inherent Risk and Inform Risk Response Prioritization 26 2.1.2.6 ID.RA-06: Risk Responses Are Chosen, Prioritized, Planned, Tracked, and Communicated 27 2.1.
2.7 ID.RA-07: Changes and Exceptions Are Managed, Assessed for Risk Impact, Recorded, and Tracked 29 2.1.2.8 ID.RA-08: Processes for Receiving, Analyzing, and Responding to Vulnerability Disclosures Are Established 30 2.1.
2.9 ID.RA-09: The Authenticity and Integrity of Hardware and Software Are Assessed Before Acquisition and Use 31 2.1.2.10 ID.RA-10: Critical Suppliers Are Assessed Before Acquisition 32 2.1.
3 Improvement (ID.IM): Improvements to Organizational Cybersecurity Risk Management Processes, Procedures, and Activities Are Identified Across All CSF Functions 33 2.1.3.1 ID.IM-01: Improvements Are Identified from Evaluations 34 2.1.3.
2 ID.IM-02: Improvements Are Identified from Security Tests and Exercises, Including Those Done in Coordination with Suppliers and Relevant Third Parties 36 2.1.3.3 ID.IM-03: Improvements Are Identified from the Execution of Operational Processes, Procedures, and Activities 38 2.1.3.
4 ID.IM-04: Incident Response Plans and Other Cybersecurity Plans That Affect Operations Are Established, Communicated, Maintained, and Improved 40 Chapter Summary 41 Chapter Quiz 41 Bibliography 42 3 NIST Function Protect 43 3.1 Protect: Safeguards to Manage the Organization''s Cybersecurity Risks Are Used 44 3.1.1 Identity Management, Authentication, and Access Control (PR.AA)--Access to Physical and Logical Assets Is Limited to Authorized Users, Services, and Hardware and Managed Commensurate with the Assessed Risk of Unauthorized Access 44 3.1.1.
1 PR.AA-01: Identities and Credentials for Authorized Users, Services, and Hardware Are Managed 45 3.1.1.2 PR.AA-02: Identities Are Proofed and Bound to Credentials Based on the Context of Interactions 46 3.1.1.
3 PR.AA-03: Users, Services, and Hardware Are Authenticated 47 3.1.1.4 PR.AA-04: Identity Assertions Are Protected, Conveyed, and Verified 49 3.1.1.
5 PR.AA-05: Access Permissions, Entitlements, and Authorizations Are Defined in a Policy, Managed, Enforced, and Reviewed, and Incorporate the Principles of Least Privilege and Separation of Duties 50 3.1.1.6 PR.AA-06: Physical Access to Assets Is Managed, Monitored, and Enforced Commensurate with Risk 52 3.1.2 Awareness and Training (PR.
AT): The Organization''s Personnel Are Provided with Cybersecurity Awareness and Training So That They Can Perform Their Cybersecurity-related Tasks 54 3.1.2.1 PR.AT-01: Personnel Are Provided with Awareness and Training So That They Possess the Knowledge and Skills to Perform General Tasks with Cybersecurity Risks in Mind 54 3.1.2.2 PR.
AT-02: Individuals in Specialized Roles Are Provided with Awareness and Training So That They Possess the Knowledge and Skills to Perform Relevant Tasks with Cybersecurity Risks in Mind 56 3.1.3 Data Security (PR.DS): Data Are Managed Consistently with the Organization''s Risk Strategy to Protect the Confidentiality, Integrity, and Availability of Information 57 3.1.3.1 PR.DS-01: The Confidentiality, Integrity, and Availability of Data-at-rest Are Protected 58 3.
1.3.2 PR.DS-02: The Confidentiality, Integrity, and Availability of Data-in-transit Are Protected 60 3.1.3.3 PR.DS-10: The Confidentiality, Integrity, and Availability of Data-in-use Are Protected.
(PR.DS-03: [Withdrawn: Incorporated into ID.AM-08, PR.PS-03], PR.DS-04: [Withdrawn: Moved to PR.IR-04], PR.DS-05: [Withdrawn: Incorporated into PR.DS-01, PR.
DS-02, PR.DS-10], PR.DS-06: [Withdrawn: Incorporated into PR.DS-01, DE.CM-09], PR.DS-07: [Withdrawn: Incorporated into PR.IR-01], PR.DS-08: [Withdrawn: Incorporated into ID.
RA-09, DE.CM-09]) 62 3.1.3.4 PR.DS-11: Backups of Data Are Created, Protected, Maintained, and Tested 63 3.1.4 Platform Security (PR.
PS): The Hardware, Software (e.g., Firmware, Operating Systems, Applications), and Services of Physical and Virtual Platforms Are Managed Consistent with the Organization''s Risk Strategy to Protect Their Confidentiality, Integrity, and Availability 65 3.1.4.1 PR.PS-01: Configuration Management Practices Are Established and Applied 65 3.1.
4.2 PR.PS-02: Software Is Maintained, Replaced, and Removed Commensurate with Risk 67 3.1.4.3 PR.PS-03: Hardware Is Maintained, Replaced, and Removed Commensurate with Risk 68 3.1.
4.4 PR.PS-04: Log Records Are Generated and Made Available for Continuous Monitoring 70 3.1.4.5 PR.PS-05: Installation and Execution of Unauthorized Software Are Prevented 71 3.1.
4.6 PR.PS-06: Secure Software Development Practices Are Integrated, and Their Performance Is Monitored Throughout the Software Development Life Cycle 72 3.1.5 Technology Infrastructure Resilience (PR.IR): Security Architectures Are Managed with the Organization''s Risk Strategy to Protect Asset Confidentiality, Integrity, and Availability, and Organizational Resilience 74 3.1.5.
1 PR.IR-01: Networks and Environments Are Protected from Unauthorized Logical Access and Usage 75 3.1.5.2 PR.IR-02: The Organization''s Technology Assets Are Protected from Environmental Threats 76 3.1.5.
3 PR.IR-03: Mechanisms Are Implemented to Achieve Resilience Requirements in Normal and Adverse Situations 77 3.1.5.4 PR.IR-04: Adequate Resource Capacity to Ensure Availability Is Maintained 79 Chapter Summary 80 Chapter Quiz 80 Bibliography 80 4 NIST Function Detect 81 4.1 DETECT: Possible Cybersecurity Attacks and Compromises Are Found and Analyzed 82 4.1.
1 Continuous Monitoring (DE.CM): Assets Are Monitored to Find Anomalies, Indicators of Compromise, and Other Potentially Adverse Events 83 4.1.1.1 DE.CM-01: Networks and Network Services Are Monitored to Find Potentially Adverse Events 83 4.1.1.
2 DE.CM-02: The Physical Environment Is Monitored to Find Potentially Adverse Events 84 4.1.1.3 DE.CM-03: Personnel Activity and Technology Usage Are Monitored to Find Potentially Adverse Events 85 4.1.1.
4 DE.CM-06: External Service Provider Activities and Services Are Monitored to Find Potentially Adverse Events (Note: DE.CM-04: [Withdrawn: Incorporated into DE.CM-01, DE.CM-09] and DE.CM-05: [Withdrawn: Incorporated into DE.CM-01, De.cm-09]) 86 4.
1.1.5 DE.CM-09: Computing Hardware and Software, Runtime Environments, and Their Data Are Monitored to Find Potentially Adverse Events (Note: DE.CM-07: [Withdrawn: Incorporated into DE.CM-01, DE.CM-03, DE.CM-06, DE.
CM-09], DE.CM-08: [Withdrawn: Incorporated into ID.RA-01]) 87 4.1.2 Adverse Event Analysis (DE.AE): Anomalies, Ind.