The management of cybersecurity risk and its effect on an organization's people and assets.
The strategy used to protect an organization through the implementation of policies, procedures, training and tools that help mitigate cybersecurity threats.
Identifying potential security incidents and improving monitoring capabilities to increase the speed and efficiency of detections.
Making sure that the proper procedures are use to contain, neutralize and analyze security incidents, and implement improvements to the security process.
The process of returning affected systems back to normal operations.
This function emphasizes the importance of strong cybersecurity governance across all levels of the organization. It's about establishing and maintaining the structures and processes needed to effectively manage cybersecurity risk. This includes things like setting clear cybersecurity objectives, ensuring leadership commitment, developing and implementing a comprehensive risk management strategy, and continuously improving cybersecurity performance.
An incident is an occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.
Event:
An event is an observable occurence on a network, system, or device.