NIST CSF Flashcards
(48 cards)
What are the different Tiers?
- ) Partial
- ) Risk Informed
- ) Repeatable
- ) Adaptive
What are the three cybersecurity management practice areas being measured under the different Tiers?
- ) Risk Management Process
- ) Integrated Risk Management Program
- ) External Participation
What does Risk Management Process mean?
The functionality and repeatability of the cybersecurity risk management
- How much is the organization involved in the risk management process?
What does Integrated Risk Management Program mean?
The extent to which cybersecurity is considered in broader risk management decisions
- How well is cybersecurity risk integrated into the overall business risk of the organization? How much is cybersecurity considered in overall risk management?
What does External Participation mean?
The degree to which the organization: 1. monitors and manages supply chain risk, and 2. benefits by sharing or receiving information from external parties
- How well does the organization coordinates, collaborates, and shares information back and forth with other organizations?
What is a Profile?
A particular customization of the CSF Core for an organization or sector based on their unique requirements
What are the three main inputs that determine a CSF Profile?
- ) Business Objectives
- ) Security Requirements
- ) Technical Environment
If the CSF is an overall cybersecurity management model, then what is the RMF?
It falls under CSF for Risk Management, which has “tasks” that link back to CSF functions
What are some of the most comparable frameworks to the CSF?
- CIS (Center for Internet Security) CSC
- COBIT 5
- ISA
- ISO/IEC
- NIST SP 800-53
What are the 5 CSF Functions?
- ) Identify (ID)
- ) Protect (PR)
- ) Detect (DE)
- ) Respond (RS)
- ) Recover (RE)
For ID, the organization must identify what?
- Systems and data
- Critical business processes that depend on those systems and data
- The weaknesses and strengths associated with those systems
- All resources (people, technology, money, equipment, facilities)
- Vulnerabilities, threats, likelihood, impact, and frequency and overall risk
- Governance (laws, regulations, etc.)
What are the categories under the Identify (ID) Function?
- ) Asset Management (ID.AM)
- ) Business Environment (ID.BE)
- ) Governance (ID.GV)
- ) Risk Assessment (ID.RA)
- ) Risk Management Strategy (ID.RM)
- ) Supply Chain Risk Management (ID.SC)
How many subcategories support the 6 categories within the Identify Function?
29
What does the Protect (PR) Function focus on?
- Ensuring strong authentication and access control
- Protecting data
- Secure maintenance of assets
- Securing people (security clearances, user authorization, etc.)
- Sound policies and procedures
- Ensuring the right administrative, technical, and physical controls are in place
What are the categories under the Protect (PR) Function?
- ) Identity Management, Authentication, Access Control (PR.AC)
- ) Awareness and Training (PR.AT)
- ) Data Security (PR.DS)
- ) Information Protection Processes and Procedures (PR.IP)
- ) Maintenance (PR.MA)
- ) Protective Technology (PR.PT)
How many subcategories support the 6 categories within the Protect Function?
39
What is the purpose of the “Informative References” portion of the CSF?
Maps the subcategory to other frameworks and controls that tell you how to actually do the subcategory (action)
What does the Detect (DE) Function focus on?
- Focuses on detection processes and technologies
- Looks for anomalies and unusual events
- Ensures continuous security and risk monitoring
What are the categories under the Detect (DE) Function?
- ) Anomalies and Events (DE.AE)
- ) Security Continuous Monitoring (DE.CM)
- ) Detection Processes (DE.DP)
How many subcategories support the 3 categories within the Detect Function?
18
What does the Respond (RS) Function focus on?
- Planning for incident and contingency response
- Ensuring the robustness of incident communications
- Analyzing the root causes of incidents
- Mitigating damage to systems, data, equipment, facilities, and people
- Improving the overall contingency planning and response processes
What are the categories under the Respond (RS) Function?
- ) Response Planning (RS.RP)
- ) Communications (RS.CO)
- ) Analysis (RS.AN)
- ) Mitigation (RS.MI)
- ) Improvements (RS.IM)
How many subcategories support the 5 categories within the Respond Function?
16
What does the Recover (RC) Function focus on?
- Business continuity, incident recovery, and disaster recovery planning
- Maintaining communications during the recovery process
- Improving the recovery effort