S1, M1-M5 Flashcards
(175 cards)
What does NIST stand for?
National Institute of Standards and Technology
When was NIST established?
1901
Why was NIST initially established?
to promote US research
When did NIST branch out into cybersecurity?
1995
What are the three most important NIST frameworks?
- Cybersecurity Framework
- Privacy Framework
- SP 800-53 Security and Privacy Controls for Information Systems and Organizations
Is NIST CSF a voluntary or required framework?
voluntary
What are the three primary components of the NIST CSF?
- Core
- Tiers
- Organizational Profiles
What is the focus of the CSF Core (NIST)?
provides ways to reduce cybersecurity risk by enhancing cybersecurity protection
What does the NIST CSF Core consist of?
six functions
What are the six functions of the NIST CSF Core?
Govern, Identify, Protect, Detect, Respond, Recover
Which of the six NIST CSF functions touches all other functions?
govern (because you need oversight over all of it)
T/F: NIST CSF Core functions represent ordered steps.
False, they should all be done concurrently (simultaneously).
What is the focus of Identify (NIST)?
understand assets, risks, and improvement opportunities (AIR)
What is the focus of Protect (NIST)?
secure assets to prevent or reduce the likelihood and impact of adverse cybersecurity events
What is the focus of Detect (NIST)?
discover cybersecurity attacks and incidents quickly (timely)
What is the focus of Respond (NIST)?
contain the effects of cybersecurity incidents
What is the focus of Recover (NIST)?
restoration of company’s normal operations
What is the key difference between Respond and Recover for NIST?
Respond deals with how you contain an attack and respond in real time to deal with it.
Recover deals with how you return to normal business operations after the attack has been contained.
Is a locked door on a house a preventative or detective measure?
preventative (it stops an attacker from getting in)
Is a security camera on a house a preventative or detective measure?
It is more traditionally a detective measure, but it can also be preventative in that it deters the attacker from wanting to rob that house.
T/F: NIST CSF Tiers are a means to implement the six functions.
False, they are just a categorization mechanism.
What do the NIST CSF Tiers do?
measure the sophistication of an organization’s information security infrastructure
How many CSF Tiers are there?
4
What are the four CSF Tiers?
Partial
Risk-Informed
Repeatable
Adaptive