You are on page 1of 7

CYBERSECURITY

FRAMEWORK
A collection of finest practices that an
organization must follow to manage its
cybersecurity risk.
Goal of the framework:
• Reduce company’s exposure to cyberattacks
• Identify areas at higher risk for data breaches
•Monitor the compromising activities of cyber
criminals
TYPES OF
SECURITY
FRAMEWORK
Control
Framewo
rk

Program
Framewo
rk

Risk
Framewo
Function Category

Identify Asset
Management
Business
Environment
Governance
FRAMEW Risk Assessment
Risk Management
ORK Strategy Supply Chain
Risk Management

CATEGORIES Protect Identify management,


Authentication and
Access Control
Awareness
Training Data
Security
Information
Protection
Processes and
REFERENCE
S
How to Make Sense of Cybeísecuíity Fíamewoíks (RSA Confeíence2019)’
https://www.nist.gov/cybeífíamewoík https://reciprocity.com/resources/what-is-
a-cybersecurity-framework/
DEEP DIVE INTO: NIST
CYBERSECURITY
FRAMEWORK
Identify  Composed of three parts:
• Core
Protect • Implementation Tiers
• Profiles
Detect Defines a common language
for managing risk
Respond • Core has five functions that
provide a high-level,
Recover strategic view of security
lifecycle
Function Category

Detect Anomalies and


events Security
continuous
monitoring
Detection
FRAMEW Processes

ORK Respond Response


Planning
Communications
CATEGORIES Analysis
Mitigation
Improvements

Recover Recover
Planning
Improvements
Communications
Thank
You

You might also like