Module 1 Flashcards
what are the NIST CSF (cybersecurity framework) tiers?
tier 1 -Partial
Tier 2 - risk informed
tier 3 - Repeatable
tier 4 - Adaptable
list the 2 NIST profiles and describe them
current profile - “as is “ state of system cybersecurity
Target profile - the desired outcome “to be” state of cybersecurity
what could you gain by comparing current profile with target profile
gaps in your cybersecurity that need to be addressed
NIST cybersecurity framework Tier 3 explain
Repeatable -
- – risk management practices are formally approved and expressed as policy
- – cybersecurity practices are regularly updated based on risk management processes and changing threat landscape
- – organization-wide approach to manage cybersecurity
- – risk informed policies, processes, and procedures are defined implemented as intended and reviewed.
- –senior executives ensure consideration of cybersecurity through all lines of operation
- – the organization understands its role, dependencies, and dependents in the larger ecosystem.
NIST cybersecurity framework tier 4, explain
Adaptive -
- – Risk Management process
- – org adapts its cyvbersecrui9ty practices based on previous and current cybersecurity activities, including lessons learned and predictive indicators
- – organization actively adapts to a changing threat and technology landscape and response in a timely and effective manner.
- – integrated risk management -
- – organization wide approach to managing cybersecurity risk that uses risk-informed policies, processes, and procedures to address potential cybersecurity events.
what are the 4 NIST framework core elements
Functions
Categories
subcategories
Informative References
explain the role of functions within the NIST framework
Functions - organize basic cyber security activities at their highest level
explain the role of categories within the NIST framework
categories - are the subdivisions of a function into groups of cybersecurity outcomes closely tied to programmatic needs and particular activities
what is: further divide a category into specific outcomes of technical and/or management activities
- function
- category
- sub-category
- informative references
subcategories
explain the role of informational references within the NIST framework
informative references - are specific sections of standards, guidelines, and practices common among critical infrastructure associated with each subcategory
what are the 5 functions in the NIST cybersecurity framework
- Identify
- protect
- detect - in a timely manner… 72hrs or less per GDPR
- respond
- recover
what NIST Cybersecurity framework function would this describe:
develop an organizational understanding to manage cybersecurity risk to system, people, assets, data and capabilities
- Identify
what NIST cybersecurity framework function would be: develop and implement appropriate safeguards to ensure deliver of critical infrastructure services
- Protect
what NIST Cybersecurity Framework function would be defined as:
Develop and implement appropriate activities to identify the occurrence of a cybersecurity event
- Detect
what cybersecurity framework function would be: develop and implement appropriate activities to take action regarding a detected cybersecurity incident
- Respond
what NIST CSF function would be: develop and implement appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to the cybersecurity incident
- Recovery
list the 4 NIST framework core features
1, functions
- categories
- subcategories
- informative references
what function would these categories belong to? asset management business environment governance risk assessment risk management strategy supply chain risk management
Identity
what function would these categories belong to?
identify management and access control
awareness training
data security
information protection processes and procedures
maintenance
protective technology
Protect