S1 M1 Flashcards
3 components to manage cybersecurity risk
Framework core
Implementation tiers
Framework profile
Purpose of NIST CSF?
To identify, assess, and manage cybersecurity risks in a cost effective and repeatable manner
5 CSF Core components
Identify
Protect
Detect
Respond
Recover
CSF Implementation Tiers
Tier 1 - partial (not integrated; ad hoc and situational risk management)
Tier 2 - risk informed (some are aware of risks, but not yet integrated; no action taken)
Tier 3 - repeatable (formal, documented policies, cybersecurity is implemented into planning)
Tier 4 - adaptive (Fully integrated and cybersecurity is prioritized)
CSF Profiles
Current profile - current level of risk management
Target profile - Where you would like your risk management to be
Gap analysis - difference between current and target
Privacy framework core
Identify
Protect
Detect
Respond
Recover
Control
Communicate
Govern
Difference between NIST security and privacy controls and NIST CSF and privacy framework
CSF and privacy framework are designed to manage cybersecurity risks in a cost effective manner, security and privacy controls are designed to protect against sophisticated threats. Must more detailed and stricter.
Three NIST SP control implementation approaches
Common - implementation at the organizational level
System-specific - Implementation at the information system level
Hybrid - combination based on appropriateness