edit

NIST Cybersecurity Framework

Identify

The management of cybersecurity risk and its effect on an organization's people and assets.

Protect

The strategy used to protect an organization through the implementation of policies, procedures, training and tools that help mitigate cybersecurity threats.

Detect

Identifying potential security incidents and improving monitoring capabilities to increase the speed and efficiency of detections.

Respond

Making sure that the proper procedures are use to contain, neutralize and analyze security incidents, and implement improvements to the security process.

Recover

The process of returning affected systems back to normal operations.

Govern

This function emphasizes the importance of strong cybersecurity governance across all levels of the organization. It's about establishing and maintaining the structures and processes needed to effectively manage cybersecurity risk. This includes things like setting clear cybersecurity objectives, ensuring leadership commitment, developing and implementing a comprehensive risk management strategy, and continuously improving cybersecurity performance.


Definitions

Incident:

An incident is an occurrence that actually or imminently jeopardizes, without lawful authority, the confidentiality, integrity or availability of information or an information system; or constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

Event:

An event is an observable occurence on a network, system, or device.


The five w's of an incident.
  1. Who triggered the incident
  2. What happened
  3. When the incident took place
  4. Where the incident took place
  5. Why the incident occured