Directive NIS2 European Union
Kybermittari

Kybermittari — Cybermeter

NIS2 says what you must achieve, never how you demonstrate it. Finland answers with Kybermittari. If you operate there, this is what your regulator reads.

Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

Kybermittari is a self-assessment instrument published by the authority, not a certification scheme and not a legal requirement. A completed assessment evidences that you have measured yourself against a recognised model — it does not certify anything, and it does not by itself demonstrate NIS2 compliance.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the certifiable route in Finland; Kybermittari is commonly used alongside it to direct effort rather than to replace it.

What it is built on

Kybermittari does not invent its own taxonomy. It sits on The US Department of Energy Cybersecurity Capability Maturity Model (C2M2) and the NIST Cybersecurity Framework.

Kybermittari is a capability maturity assessment rather than a control checklist: an organisation scores its own practices by domain and by maturity indicator level, then works the gaps. It was built for critical infrastructure operators but the authority presents it as suitable for any size and sector.

Mapping

How it covers the ten NIS2 measures


Article 21(2) is the article of NIS2 — Directive (EU) 2022/2555 — that lists the ten risk-management measures every entity in scope owes, lettered (a) to (j). Those ten letters are the first column of each table on this page, and the keys every mapping we publish hangs off. The ten measures, one by one.

Basis

Kybermittari follows the domains of the DoE Cybersecurity Capability Maturity Model, each assessed across maturity indicator levels MIL 0 to MIL 3. Traficom carries eleven domains rather than the ten of C2M2: it adds CRITICAL, the protection of services critical to society, and it names the supply chain domain DEPENDENCIES.

Limit of this mapping

Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target. CRITICAL is not placed against a measure here: it is Traficom's own addition, and putting it under a letter would be our invention rather than their model.

Mapped at the level of
Kybermittari domain
Units in the framework
11
Units carrying article 21(2)
10
Each of the ten risk-management measures of article 21(2), mapped to the Kybermittari domain units of Kybermittari
NIS2 art. 21(2) Directive (EU) 2022/2555 Measure Kybermittari — Kybermittari domain
(a) Risk analysis and security policies RISK PROGRAM
(b) Incident handling RESPONSE SITUATION
(c) Business continuity RESPONSE ARCHITECTURE
(d) Supply chain security DEPENDENCIES
(e) Security in acquisition, development and maintenance THREAT ARCHITECTURE
(f) Assessing the effectiveness of the measures PROGRAM RISK
(g) Basic cyber hygiene and cybersecurity training WORKFORCE
(h) Cryptography and encryption ARCHITECTURE
(i) Human resources security, access control and asset management ACCESS ASSET WORKFORCE
(j) Multi-factor authentication and secured communications ACCESS ARCHITECTURE
11 Kybermittari domain units, in full
  • ASSET — Asset Management
  • THREAT — Threat and Vulnerability Management
  • RISK — Risk Management
  • ACCESS — Identity and Access Management
  • SITUATION — Situational Awareness
  • RESPONSE — Event and Incident Response, Continuity of Operations
  • DEPENDENCIES — Supply Chain and External Dependencies Management
  • CRITICAL — Protection of services critical to society
  • WORKFORCE — Workforce Management
  • ARCHITECTURE — Cybersecurity Architecture
  • PROGRAM — Cybersecurity Program Management
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. Kybermittari is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to Kybermittari and to the enterprise frameworks an organisation is likely to already operate
NIS2 art. 21(2) Directive (EU) 2022/2555 Kybermittari ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis RISK PROGRAM 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling RESPONSE SITUATION 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity RESPONSE ARCHITECTURE 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain DEPENDENCIES 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development THREAT ARCHITECTURE 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness PROGRAM RISK 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training WORKFORCE 5.37 6.3 8.7 AT SI CM
(h) Cryptography ARCHITECTURE 8.24 SC
(i) HR, access, assets ACCESS ASSET WORKFORCE 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms ACCESS ARCHITECTURE 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Measure catalogue

325 practices, and the level each one enters at


A mapping says which of the ten measures a framework serves. A catalogue says which practice, at which level. Here are all 325, as Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland publishes them.

Practices
325
Domains
11
Objectives
42

Published by Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland, under CC BY 4.0

Traficom / NCSC-FI, Kybermittari assessment tool V1 — CC BY 4.0. Structure and counts here are derived from that publication; identifiers and wording are theirs.

  • Traficom / NCSC-FI, Kybermittari assessment tool V1 (Excel), sheets Data, Languages and NISTMap

Get the official documents from https://www.kyberturvallisuuskeskus.fi/en/our-services/situation-awareness-and-network-management/kybermittari-cybermeter — the framework and everything published with it belong to its owner, and that publication is the version that binds. Kybermittari material is published by Traficom under CC BY 4.0.

  • Practice wording is the English column of the tool itself, published alongside Finnish and Swedish.
  • The NIST CSF column is the crosswalk Traficom publishes in the tool. There is no crosswalk to article 21(2) — the letters on this page are our own thematic mapping, at domain level.
  • The tool carries eleven domains, not the ten of C2M2: Traficom adds CRITICAL, the protection of services critical to society, which is the NIS2 angle exactly.

What each level adds

Depth here is one thing: how many more practices the next level pulls in. Each level contains everything below it, which is checked on every extraction.

Kybermittari levels: practices added, cumulative total
Level Adds Cumulative
MIL 1 — initiated +60 60
MIL 2 — performed +147 207
MIL 3 — managed +118 325

What these levels are, and are not

MIL levels are not assurance tiers you are assigned: you reach MIL 2 in a domain only by performing every MIL 1 practice in it, and you set your own target profile. Nothing in Finnish law assigns you a MIL, and reaching one discharges no obligation.

The catalogue, practice by practice

11 domains, 42 objectives, 325 practices. Each row carries the level at which it becomes due.

ACCESS — Identity and Access Management  · 22 practices

Establish and Maintain Identities (ACCESS-1)

Kybermittari practices in ACCESS-1, Establish and Maintain Identities
Practice Level Title NIST CSF
ACCESS-1a MIL 1 — initiated Identities are provisioned, at least in an ad hoc manner, for personnel and other entities (e.g., services, devices) that require access to assets (note that this does not preclude shared identities) PR.AC-1
ACCESS-1b MIL 1 — initiated Credentials are issued for personnel and other entities that require access to assets (e.g., passwords, smart cards, certificates, keys, lock combinations), at least in an ad hoc manner PR.AC-1
ACCESS-1c MIL 1 — initiated Identities are deprovisioned, at least in an ad hoc manner, when no longer required PR.AC-1
ACCESS-1d MIL 2 — performed Identity repositories are reviewed and updated to ensure accuracy, at an organization-defined frequency PR.AC-1
ACCESS-1e MIL 2 — performed Credentials are periodically reviewed to ensure that they are associated with the correct person or entity PR.AC-1 PR.AC-6
ACCESS-1f MIL 2 — performed Identities are deprovisioned within organization-defined time thresholds when no longer required PR.AC-1
ACCESS-1g MIL 3 — managed Requirements for credentials are based on the organization’s risk criteria (RISK-2b) (e.g., multifactor credentials for higher risk access) and cybersecurity architecture (e.g., credential requirements for accessing security zones (ARCHITECTURE-2b)) PR.AC-1 PR.AC-7

Control Access (ACCESS-2)

Kybermittari practices in ACCESS-2, Control Access
Practice Level Title NIST CSF
ACCESS-2a MIL 1 — initiated Access requirements (e.g., rules for which types of entities are allowed to access an asset, the limits of allowed access, constraints on remote access, and authentication parameters) are determined, at least in an ad hoc manner PR.AC-2 PR.AC-3 PR.AC-7 PR.MA-2 PR.PT-2 PR.PT-3
ACCESS-2b MIL 1 — initiated Access is granted to identities based on the access requirements, at least in an ad hoc manner PR.AC-2 PR.AC-3 PR.PT-2 PR.PT-3
ACCESS-2c MIL 1 — initiated Access is revoked when no longer required, at least in an ad hoc manner PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-2 PR.PT-3
ACCESS-2d MIL 2 — performed Access requirements incorporate least privilege and separation of duties principles PR.AC-2 PR.AC-3 PR.AC-4 PR.MA-2 PR.PT-3
ACCESS-2e MIL 2 — performed Access requests are reviewed and approved by the asset owner PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-3
ACCESS-2f MIL 2 — performed Root privileges, administrative access, emergency access, and shared accounts receive additional scrutiny and monitoring PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-3
ACCESS-2g MIL 3 — managed Access privileges are reviewed and updated to ensure conformance with access requirements, at an organization-defined frequency PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-3
ACCESS-2h MIL 3 — managed Anomalous access attempts are monitored as indicators of cybersecurity events PR.PT-3

Management Activities (ACCESS-3)

Kybermittari practices in ACCESS-3, Management Activities
Practice Level Title NIST CSF
ACCESS-3a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the ACCESS domain
ACCESS-3b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the ACCESS domain
ACCESS-3c MIL 2 — performed Personnel performing activities in the ACCESS domain have the skills and knowledge needed to perform their assigned responsibilities
ACCESS-3d MIL 2 — performed Responsibility and authority for the performance of activities in the ACCESS domain are assigned to personnel
ACCESS-3e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the ACCESS domain PR.PT-2
ACCESS-3f MIL 3 — managed Performance objectives for activities in the ACCESS domain are established and monitored to track achievement (PROGRAM-1b)
ACCESS-3g MIL 3 — managed Documented practices for activities in the ACCESS domain are standardized and improved across the enterprise
ARCHITECTURE — Cybersecurity Architecture  · 32 practices

Establish and Maintain Cybersecurity Architecture Strategy and Program (ARCHITECTURE-1)

Kybermittari practices in ARCHITECTURE-1, Establish and Maintain Cybersecurity Architecture Strategy and Program
Practice Level Title NIST CSF
ARCHITECTURE-1a MIL 1 — initiated The organization has a strategy for cybersecurity architecture, which may be developed and/or managed in an ad hoc manner PR.AC-5
ARCHITECTURE-1b MIL 2 — performed A strategy for cybersecurity architecture is established and maintained to support the organization’s cybersecurity program strategy (PROGRAM-1b) and enterprise architecture PR.AC-5
ARCHITECTURE-1c MIL 2 — performed A documented cybersecurity architecture is established and maintained that includes IT and OT systems and networks and aligns with system and asset categorization and prioritization PR.AC-5 PR.PT-4
ARCHITECTURE-1d MIL 2 — performed Governance for cybersecurity architecture is established and maintained that includes provisions for periodic architectural reviews and an exceptions process (e.g., an architecture review board)
ARCHITECTURE-1e MIL 2 — performed The cybersecurity architecture incorporates confidentiality, integrity, and availability requirements for the function’s assets PR.AC-5 PR.DS-4
ARCHITECTURE-1f MIL 2 — performed The cybersecurity architecture incorporates cybersecurity principles (e.g., least functionality, default deny, least privilege) PR.AC-5 PR.DS-4 PR.DS-5 PR.PT-4 PR.PT-5
ARCHITECTURE-1g MIL 3 — managed The cybersecurity architecture strategy and program are aligned with the organization’s enterprise architecture strategy and program
ARCHITECTURE-1h MIL 3 — managed Conformance of the organization’s systems and networks to the cybersecurity architecture is evaluated according to organization-defined triggers (e.g., time elapsed, changes to systems, networks, or assets) PR.DS-4
ARCHITECTURE-1i MIL 3 — managed The cybersecurity architecture is guided by the information from the organization’s risk taxonomy (RISK-2e) and threat profile (THREAT-1d) to support the implementation of protections against identified threats

Implement Segmentation as an Element of the Cybersecurity Architecture (ARCHITECTURE-2)

Kybermittari practices in ARCHITECTURE-2, Implement Segmentation as an Element of the Cybersecurity Architecture
Practice Level Title NIST CSF
ARCHITECTURE-2a MIL 1 — initiated The organization’s IT systems are separated from OT systems through segmentation, either through physical means (e.g., air gaps) or logical means (e.g., network configuration or appliances), at least in an ad hoc manner PR.AC-5 PR.PT-4 PR.PT-5
ARCHITECTURE-2b MIL 2 — performed Assets that are important to the delivery of the function are segmented into multiple security zones based on criteria defined in the cybersecurity architecture (e.g., risk analysis results, security requirements, remote access, functional requirements) PR.AC-5 PR.PT-4
ARCHITECTURE-2c MIL 3 — managed All assets are segmented into security zones based on criteria defined in the cybersecurity architecture PR.AC-5 PR.PT-4

Implement Application Security as an Element of the Cybersecurity Architecture (ARCHITECTURE-3)

Kybermittari practices in ARCHITECTURE-3, Implement Application Security as an Element of the Cybersecurity Architecture
Practice Level Title NIST CSF
ARCHITECTURE-3a MIL 2 — performed Software developed in-house that is to be deployed on assets that are important to the delivery of the function is developed using secure software development practices DE.CM-4
ARCHITECTURE-3b MIL 2 — performed The selection of procured software (e.g., mobile applications, applications to be hosted on premises, software-as-a-service applications) to be deployed on assets that are important to the delivery of the function includes consideration of the vendor’s secure software development practices (DEPENDENCIES-2e)
ARCHITECTURE-3c MIL 3 — managed The architecture review process evaluates the security of new and revised applications prior to deployment (ARCHITECTURE-1h) PR.DS-6 PR.IP-3
ARCHITECTURE-3d MIL 3 — managed Security testing (e.g., static testing, dynamic testing, fuzz testing, penetration testing) is performed for in-house-developed and in-house-tailored applications based on identified risk according to organization-defined triggers (e.g., time elapsed, changes to applications, changes to threat environment) DE.CM-4 DE.CM-5

Implement Data Security as an Element of the Cybersecurity Architecture (ARCHITECTURE-4)

Kybermittari practices in ARCHITECTURE-4, Implement Data Security as an Element of the Cybersecurity Architecture
Practice Level Title NIST CSF
ARCHITECTURE-4a MIL 1 — initiated Sensitive data (e.g., PII, PCI, PHI, CEII, IP, operations data) is protected at rest (e.g., encrypted, masked, password-protected, subject to access control lists) at least in an ad hoc manner PR.DS-1 PR.DS-5
ARCHITECTURE-4b MIL 1 — initiated Sensitive data (e.g., PII, PCI, PHI, CEII, IP, operations data) is protected in transit (e.g., encrypted, masked, transmitted using protected mechanisms) at least in an ad hoc manner (ASSET-2c) PR.DS-2 PR.DS-5
ARCHITECTURE-4c MIL 2 — performed Key management infrastructure (i.e., key generation, key storage, key destruction, key update, and key revocation) are established and maintained to support the protection of data-at-rest and data-in-transit PR.DS-1 PR.DS-2 PR.DS-5
ARCHITECTURE-4d MIL 2 — performed Cryptographic controls are established and maintained to support the protection of data-at-rest and data-in-transit as required in the cybersecurity architecture PR.DS-1 PR.DS-2 PR.DS-5
ARCHITECTURE-4e MIL 2 — performed The cybersecurity architecture includes controls (e.g., data loss prevention tools, physical data exfiltration controls) to manage the transmission of data within and between systems based on security requirements (ARCHITECTURE-1e) PR.AC-5 PR.PT-4
ARCHITECTURE-4f MIL 3 — managed The cybersecurity architecture includes protections for all data-at-rest (i.e., on-premise and cloud-based file storage and databases) for selected data categories (ASSET-2c) PR.DS-1 PR.DS-5
ARCHITECTURE-4g MIL 3 — managed The cybersecurity architecture includes protections for all data-in-transit (e.g., within internal networks, across network boundaries, and external traffic, including cloud solutions) for selected data categories (ASSET-2c) PR.DS-2 PR.DS-5
ARCHITECTURE-4h MIL 3 — managed Data protections are tested (e.g., controls validation) according to organization-defined triggers (e.g., time elapsed, changes to system architecture, changes to threat environment) PR.IP-7
ARCHITECTURE-4i MIL 3 — managed The cybersecurity architecture includes protections against unauthorized changes to software, firmware, and information (due to errors or malicious activity) PR.DS-6

Management Activities (ARCHITECTURE-5)

Kybermittari practices in ARCHITECTURE-5, Management Activities
Practice Level Title NIST CSF
ARCHITECTURE-5a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the ARCHITECTURE domain
ARCHITECTURE-5b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the ARCHITECTURE domain
ARCHITECTURE-5c MIL 2 — performed Personnel performing activities in the ARCHITECTURE domain have the skills and knowledge needed to perform their assigned responsibilities
ARCHITECTURE-5d MIL 2 — performed Responsibility and authority for the performance of activities in the ARCHITECTURE domain are assigned to personnel
ARCHITECTURE-5e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the ARCHITECTURE domain PR.PT-4
ARCHITECTURE-5f MIL 3 — managed Performance objectives for activities in the ARCHITECTURE domain are established and monitored to track achievement (PROGRAM-1b)
ARCHITECTURE-5g MIL 3 — managed Documented practices for activities in the ARCHITECTURE domain are standardized and improved across the enterprise
ASSET — Asset, Change and Configuration Management  · 31 practices

Manage IT and OT Asset Inventory (ASSET-1)

Kybermittari practices in ASSET-1, Manage IT and OT Asset Inventory
Practice Level Title NIST CSF
ASSET-1a MIL 1 — initiated There is an inventory of IT and OT assets that are important to the delivery of the function; management of the inventory may be ad hoc ID.AM-1 ID.AM-2 ID.AM-5 ID.BE-4
ASSET-1b MIL 2 — performed Inventory attributes include information to support the cybersecurity program strategy (PROGRAM-1a) (e.g., locations, asset owners, applicable cybersecurity requirements, service dependencies, service level agreements, end of life dates, end of support dates, and conformance of assets to relevant industry standards) ID.AM-1 ID.AM-2 ID.AM-5 ID.BE-4
ASSET-1c MIL 2 — performed Inventoried assets for the delivery of the function are prioritized based on formally defined criteria ID.AM-5 ID.BE-4
ASSET-1d MIL 3 — managed All IT and OT assets for the delivery of the function are inventoried ID.AM-1 ID.AM-2 ID.AM-3 ID.BE-4
ASSET-1e MIL 3 — managed The asset inventory is current (as defined by the organization) ID.AM-1 ID.AM-2 ID.BE-4
ASSET-1f MIL 3 — managed The asset inventory is used to identify cybersecurity risks (e.g., asset end of life or end of support, single points of failure) ID.BE-4 ID.RA-5

Manage Information Asset Inventory (ASSET-2)

Kybermittari practices in ASSET-2, Manage Information Asset Inventory
Practice Level Title NIST CSF
ASSET-2a MIL 1 — initiated There is an inventory of information assets that are important to the delivery of the function (e.g., SCADA set points, customer information, financial data, log data); management of the inventory may be ad hoc ID.AM-5 ID.BE-4
ASSET-2b MIL 2 — performed Inventory attributes include information to support the cybersecurity program strategy (PROGRAM-1a) (e.g., storage locations, backup locations and frequencies, asset owners, applicable cybersecurity requirements, service dependencies, service level agreements) ID.AM-3 ID.AM-5 ID.BE-4 PR.IP-4
ASSET-2c MIL 2 — performed Inventoried information assets are categorized based on a defined scheme ID.AM-5 ID.BE-4 PR.IP-4
ASSET-2d MIL 3 — managed There is an inventory for all information assets related to the delivery of the function ID.AM-3 ID.AM-5 ID.BE-4 PR.IP-4
ASSET-2e MIL 3 — managed The asset inventory is current (as defined by the organization) ID.AM-3 ID.BE-4 PR.IP-4
ASSET-2f MIL 3 — managed The asset inventory is used to identify cybersecurity risks (e.g., risk of disclosure, risk of destruction, risk of tampering) ID.BE-4 ID.RA-5

Manage Asset Configuration (ASSET-3)

Kybermittari practices in ASSET-3, Manage Asset Configuration
Practice Level Title NIST CSF
ASSET-3a MIL 1 — initiated Configuration baselines are established, at least in an ad hoc manner, for inventoried assets where it is desirable to ensure that multiple assets are configured similarly PR.DS-8.DISABLED PR.IP-1
ASSET-3b MIL 1 — initiated Configuration baselines are used, at least in an ad hoc manner, to configure assets at deployment and restoration PR.DS-8.DISABLED PR.IP-1
ASSET-3c MIL 2 — performed The design of configuration baselines includes cybersecurity objectives (PROGRAM-1b) PR.IP-1
ASSET-3d MIL 3 — managed Asset configurations are monitored for consistency with baselines throughout the assets’ lifecycles PR.DS-8.DISABLED PR.IP-1
ASSET-3e MIL 3 — managed Configuration baselines are reviewed and updated at an organization-defined frequency PR.IP-1
ASSET-3f MIL 3 — managed Configuration baselines incorporate requirements from the applicable security zone (ARCHITECTURE-2b) (e.g., network appliance configurations are tailored to the traffic restrictions for the zone) PR.IP-1

Manage Changes to Assets (ASSET-4)

Kybermittari practices in ASSET-4, Manage Changes to Assets
Practice Level Title NIST CSF
ASSET-4a MIL 1 — initiated Changes to inventoried assets are evaluated before being implemented, at least in an ad hoc manner PR.DS-3 PR.IP-3
ASSET-4b MIL 1 — initiated Changes to inventoried assets are logged, at least in an ad hoc manner PR.DS-3 PR.IP-3 PR.MA-1
ASSET-4c MIL 2 — performed Changes to assets are tested prior to being deployed, whenever possible PR.DS-3 PR.DS-7 PR.IP-3
ASSET-4d MIL 2 — performed Change management practices address the full life cycle of assets (i.e., acquisition, deployment, operation, retirement) PR.DS-3 PR.IP-2 PR.IP-3 PR.IP-6
ASSET-4e MIL 3 — managed Changes to assets are tested for cybersecurity impact prior to being deployed PR.DS-7 PR.IP-3
ASSET-4f MIL 3 — managed Change logs include information about modifications that impact the cybersecurity requirements of assets (availability, integrity, confidentiality) PR.DS-3 PR.IP-3 PR.MA-1

Management Activities (ASSET-5)

Kybermittari practices in ASSET-5, Management Activities
Practice Level Title NIST CSF
ASSET-5a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the ASSET domain PR.DS-3 PR.IP-3
ASSET-5b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the ASSET domain PR.DS-3 PR.MA-1
ASSET-5c MIL 2 — performed Personnel performing activities in the ASSET domain have the skills and knowledge needed to perform their assigned responsibilities
ASSET-5d MIL 2 — performed Responsibility and authority for the performance of activities in the ASSET domain are assigned to personnel
ASSET-5e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the ASSET domain PR.DS-3 PR.IP-3 PR.IP-5
ASSET-5f MIL 3 — managed Performance objectives for activities in the ASSET domain are established and monitored to track achievement (PROGRAM-1b)
ASSET-5g MIL 3 — managed Documented practices for activities in the ASSET domain are standardized and improved across the enterprise ID.SC-3
CRITICAL — Critical Service Protection  · 27 practices

Identification of Critical Services and their dependencies (CRITICAL-1)

Kybermittari practices in CRITICAL-1, Identification of Critical Services and their dependencies
Practice Level Title NIST CSF
CRITICAL-1a MIL 1 — initiated Organization provided services that are critical to the society (critical services), have been identified and documented.
CRITICAL-1b MIL 1 — initiated The data needed to provide the critical services, has been mapped and documented.
CRITICAL-1c MIL 1 — initiated The processes needed to provide the critical services, have been mapped and documented.
CRITICAL-1d MIL 1 — initiated The systems (IT and OT assets) needed to provide the critical services, have been mapped and documented.
CRITICAL-1e MIL 2 — performed The facilities needed to provide the critical services, have been mapped and documented.
CRITICAL-1f MIL 2 — performed The supply chain needed to provide the critical services, has been mapped and documented.
CRITICAL-1g MIL 2 — performed The period of time how quickly the failure of resources (data, processes, systems, facilities, supply chain) needed by critical services, would have a significant impact on the normal operation of the society, has been determined and documented.
CRITICAL-1h MIL 3 — managed The cascade effects across the society of a degraded or failed critical services have been identified and documented.

Governance of Critical Services (CRITICAL-2)

Kybermittari practices in CRITICAL-2, Governance of Critical Services
Practice Level Title NIST CSF
CRITICAL-2a MIL 1 — initiated All resources (data, processes, systems, facilities, supply chain) that are needed to provide the services critical to the society, are within the scope of the organization's security management policies and processes.
CRITICAL-2b MIL 1 — initiated All resources (data, processes, systems, facilities, supply chain) that are needed to provide the services critical to the society, are within the scope of the organization's risk management policies and processes.
CRITICAL-2c MIL 2 — performed Your organisation's approach and policy relating to the security of networks and information systems supporting the delivery of services critical to the society, are owned and managed at board level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation.
CRITICAL-2d MIL 2 — performed Regular board discussions on the security of network and information systems supporting the delivery of your services critical to the society take place, based on timely and accurate information and informed by expert guidance.
CRITICAL-2e MIL 2 — performed There is a board-level individual who has overall accountability for the security of networks and information systems needed by the critical services and drives regular discussion at board-level.
CRITICAL-2f MIL 2 — performed Direction set at board level is translated into effective organisational practices that direct and control the security of the networks and information systems supporting your critical services.
CRITICAL-2g MIL 2 — performed Senior management have visibility of key risk decisions made throughout the organisation.
CRITICAL-2h MIL 2 — performed Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential service, as set by senior management.
CRITICAL-2i MIL 2 — performed Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools, and authority they need.
CRITICAL-2j MIL 3 — managed Risk management decisions are periodically reviewed to ensure their continued relevance and validity.
CRITICAL-2k MIL 3 — managed The risk management process takes into account the resources (data, processes, systems, facilities, supply chain), critical period of time and cascade effects.

Minimisation of the impact of cyber security incidents on Critical Services (CRITICAL-3)

Kybermittari practices in CRITICAL-3, Minimisation of the impact of cyber security incidents on Critical Services
Practice Level Title NIST CSF
CRITICAL-3a MIL 1 — initiated Your response plan covers all of your critical services.
CRITICAL-3b MIL 1 — initiated Your response plan comprehensively covers scenarios that are focused on likely impacts of known and well-understood attacks only.
CRITICAL-3c MIL 1 — initiated Your response plan is understood by all staff who are involved with your organisation's response function
CRITICAL-3d MIL 1 — initiated Your response plan is documented and shared with all relevant stakeholders
CRITICAL-3e MIL 2 — performed Your incident response plan is based on a clear understanding of the security risks to the networks and information systems supporting your essential service .
CRITICAL-3f MIL 2 — performed Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen.
CRITICAL-3g MIL 3 — managed Your incident response plan is documented and integrated with wider organisational business and supply chain response plans.
CRITICAL-3h MIL 3 — managed Your incident response plan is communicated and understood by the business areas involved with the supply or maintenance of your essential services.
DEPENDENCIES — Supply Chain and External Dependencies Management  · 28 practices

Identify Dependencies (DEPENDENCIES-1)

Kybermittari practices in DEPENDENCIES-1, Identify Dependencies
Practice Level Title NIST CSF
DEPENDENCIES-1a MIL 1 — initiated Important IT and OT supplier dependencies are identified (i.e., internal and external parties on which the delivery of the function depends, including operating partners), at least in an ad hoc manner ID.AM-4 ID.BE-4 ID.SC-2
DEPENDENCIES-1b MIL 1 — initiated Important customer dependencies are identified (i.e., internal and external parties that are dependent on the delivery of the function, including operating partners), at least in an ad hoc manner ID.BE-1 ID.BE-2 ID.SC-2
DEPENDENCIES-1c MIL 2 — performed Supplier dependencies are identified according to established criteria ID.AM-4 ID.BE-4 ID.SC-2
DEPENDENCIES-1d MIL 2 — performed Customer dependencies are identified according to established criteria ID.BE-1 ID.BE-2 ID.SC-2
DEPENDENCIES-1e MIL 2 — performed Single-source and other essential dependencies are identified ID.AM-4 ID.BE-4 ID.SC-2
DEPENDENCIES-1f MIL 2 — performed Dependencies are prioritized ID.BE-1 ID.BE-2 ID.SC-2
DEPENDENCIES-1g MIL 3 — managed Dependency prioritization and identification are based on defined risk criteria (RISK-2b) ID.AM-4 ID.BE-1 ID.BE-2 ID.BE-4 ID.SC-2

Manage Dependency Risk (DEPENDENCIES-2)

Kybermittari practices in DEPENDENCIES-2, Manage Dependency Risk
Practice Level Title NIST CSF
DEPENDENCIES-2a MIL 1 — initiated Significant cybersecurity risks due to suppliers and other dependencies are identified and addressed, at least in an ad hoc manner ID.SC-1 DE.CM-6
DEPENDENCIES-2b MIL 1 — initiated Cybersecurity requirements are considered when establishing relationships with suppliers and other third parties, at least in an ad hoc manner ID.SC-1 ID.SC-3
DEPENDENCIES-2c MIL 2 — performed Identified cybersecurity dependency risks are entered into the risk register (RISK-1d) ID.SC-1
DEPENDENCIES-2d MIL 2 — performed Contracts and agreements with third parties incorporate sharing of cybersecurity threat information ID.SC-3
DEPENDENCIES-2e MIL 2 — performed Cybersecurity requirements are established for suppliers according to a defined practice, including requirements for secure software development practices where appropriate ID.SC-3
DEPENDENCIES-2f MIL 2 — performed Agreements with suppliers and other external entities include cybersecurity requirements ID.SC-3
DEPENDENCIES-2g MIL 2 — performed Evaluation and selection of suppliers and other external entities includes consideration of their ability to meet cybersecurity requirements ID.SC-3
DEPENDENCIES-2h MIL 2 — performed Agreements with suppliers require notification of cybersecurity incidents related to the delivery of the product or service ID.SC-3
DEPENDENCIES-2i MIL 2 — performed Suppliers and other external entities are periodically reviewed for their ability to continually meet the cybersecurity requirements ID.SC-4
DEPENDENCIES-2j MIL 3 — managed Cybersecurity requirements are established for supplier dependencies based on defined risk criteria (RISK-2b) ID.SC-1
DEPENDENCIES-2k MIL 3 — managed Vendor selection criteria include consideration of end-of-life and end-of-support timelines ID.SC-3
DEPENDENCIES-2l MIL 3 — managed Vendor selection criteria include consideration of safeguards against counterfeit or compromised software, hardware, and services ID.SC-2 ID.SC-3 DE.CM-5
DEPENDENCIES-2m MIL 3 — managed Information sources are monitored to identify and avoid supply chain risks (e.g., counterfeit or compromised software, hardware, and services) ID.SC-4 DE.CM-5 DE.CM-6
DEPENDENCIES-2n MIL 3 — managed Acceptance testing of procured assets includes testing for cybersecurity requirements ID.SC-4

Management Activities (DEPENDENCIES-3)

Kybermittari practices in DEPENDENCIES-3, Management Activities
Practice Level Title NIST CSF
DEPENDENCIES-3a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the DEPENDENCIES domain
DEPENDENCIES-3b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the DEPENDENCIES domain
DEPENDENCIES-3c MIL 2 — performed Personnel performing activities in the DEPENDENCIES domain have the skills and knowledge needed to perform their assigned responsibilities
DEPENDENCIES-3d MIL 2 — performed Responsibility and authority for the performance of activities in the DEPENDENCIES domain are assigned to personnel
DEPENDENCIES-3e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the DEPENDENCIES domain
DEPENDENCIES-3f MIL 3 — managed Performance objectives for activities in the DEPENDENCIES domain are established and monitored to track achievement (PROGRAM-1b)
DEPENDENCIES-3g MIL 3 — managed Documented practices for activities in the DEPENDENCIES domain are standardized and improved across the enterprise
PROGRAM — Cybersecurity Program Management  · 40 practices

Establish Cybersecurity Program Strategy (PROGRAM-1)

Kybermittari practices in PROGRAM-1, Establish Cybersecurity Program Strategy
Practice Level Title NIST CSF
PROGRAM-1a MIL 1 — initiated The organization has a cybersecurity program strategy, which may be developed and/or managed in an ad hoc manner
PROGRAM-1b MIL 2 — performed The cybersecurity program strategy defines objectives for the organization’s cybersecurity activities
PROGRAM-1c MIL 2 — performed The cybersecurity program strategy and priorities are documented and aligned with the organization’s strategic objectives and risk to critical infrastructure ID.BE-2
PROGRAM-1d MIL 2 — performed The cybersecurity program strategy defines the organization’s approach to provide program oversight and governance for cybersecurity activities
PROGRAM-1e MIL 2 — performed The cybersecurity program strategy defines the structure and organization of the cybersecurity program
PROGRAM-1f MIL 2 — performed The cybersecurity program strategy identifies standards and/or guidelines intended to be followed by the program
PROGRAM-1g MIL 2 — performed The cybersecurity program strategy identifies any applicable compliance requirements that must be satisfied by the program ID.GV-3
PROGRAM-1h MIL 3 — managed The cybersecurity program strategy is updated to reflect business changes, changes in the operating environment, and changes in the threat profile (THREAT-1d) PR.IP-7

Sponsor Cybersecurity Program (PROGRAM-2)

Kybermittari practices in PROGRAM-2, Sponsor Cybersecurity Program
Practice Level Title NIST CSF
PROGRAM-2a MIL 1 — initiated Resources (people, funding, and tools) are provided, at least in an ad hoc manner, to establish the cybersecurity program
PROGRAM-2b MIL 1 — initiated Senior management, with proper authority, provides support for the cybersecurity program, at least in an ad hoc manner
PROGRAM-2c MIL 2 — performed The cybersecurity program is established according to the cybersecurity program strategy
PROGRAM-2d MIL 2 — performed Adequate resources (people, funding, and tools) are provided to operate a cybersecurity program aligned with the program strategy
PROGRAM-2e MIL 2 — performed Senior management sponsorship for the cybersecurity program is visible and active (e.g., the importance and value of cybersecurity activities is regularly communicated by senior management)
PROGRAM-2f MIL 2 — performed Senior management sponsorship is provided for the development, maintenance, and enforcement of cybersecurity policies ID.GV-1
PROGRAM-2g MIL 2 — performed Responsibility for the cybersecurity program is assigned to a role with requisite authority
PROGRAM-2h MIL 2 — performed Stakeholders for cybersecurity program management activities are identified and involved ID.AM-6
PROGRAM-2i MIL 3 — managed The performance of the cybersecurity program is monitored to ensure it aligns with the cybersecurity program strategy
PROGRAM-2j MIL 3 — managed Cybersecurity activities are independently reviewed (i.e., by reviewers outside the cybersecurity program under direction from the organization's governing body) to ensure conformance with cybersecurity policies and procedures
PROGRAM-2k MIL 3 — managed The cybersecurity program addresses and enables the achievement of regulatory compliance as appropriate ID.GV-3
PROGRAM-2l MIL 3 — managed The organization collaborates with external entities to contribute to the development and implementation of cybersecurity standards, guidelines, leading practices, lessons learned, and emerging technologies

Address Cybersecurity in Continuity of Operations (PROGRAM-3)

Kybermittari practices in PROGRAM-3, Address Cybersecurity in Continuity of Operations
Practice Level Title NIST CSF
PROGRAM-3a MIL 1 — initiated Continuity plans are developed to sustain and restore operation of the function if a cyber event or incident occurs, at least in an ad hoc manner ID.BE-5 PR.IP-9
PROGRAM-3b MIL 1 — initiated Backups of IT, OT, and information assets are available and tested, at least in an ad hoc manner PR.IP-4
PROGRAM-3c MIL 2 — performed An analysis of the impacts from potential cyber events informs the development of continuity plans PR.IP-9
PROGRAM-3d MIL 2 — performed The assets and activities necessary to sustain minimum operations of the function are identified and documented in continuity plans ID.BE-5 PR.IP-4
PROGRAM-3e MIL 2 — performed Continuity plans address IT, OT, and information assets important to the delivery of the function, including the availability of backup data and replacement, redundant, and spare IT and OT assets PR.PT-5 ID.BE-5 PR.IP-4 PR.IP-9
PROGRAM-3f MIL 2 — performed Continuity plans are tested through evaluations and exercises (e.g., walkthroughs, tabletops, dependency testing, testing backups and spares) at an organization-defined frequency ID.SC-5 PR.IP-9 PR.IP-10
PROGRAM-3g MIL 2 — performed Recovery time objectives (RTOs) and recovery point objectives (RPOs) for assets important to the delivery of the function are incorporated into continuity plans ID.BE-5
PROGRAM-3h MIL 2 — performed Cybersecurity incident criteria that trigger the execution of continuity plans are established and communicated to incident response and continuity management functions RC.RP-1 PR.IP-9
PROGRAM-3i MIL 3 — managed Continuity plans are tested through evaluations and exercises at an organization-defined frequency and include current cyber threat scenarios ID.SC-5 PR.IP-9 PR.IP-10
PROGRAM-3j MIL 3 — managed Continuity plans are aligned with the function’s risk taxonomy (RISK-2e) and threat profile (THREAT-1d) to ensure coverage of identified risk categories and threats
PROGRAM-3k MIL 3 — managed The results of continuity plan testing or activation are compared to recovery objectives, and plans are improved accordingly PR.IP-9 PR.IP-10 RC.IM-1
PROGRAM-3l MIL 3 — managed Cybersecurity incident content within continuity plans is periodically reviewed and updated PR.IP-10 RC.IM-1
PROGRAM-3m MIL 3 — managed Continuity plans are periodically reviewed and updated PR.IP-9 PR.IP-10

Management Activities (PROGRAM-4)

Kybermittari practices in PROGRAM-4, Management Activities
Practice Level Title NIST CSF
PROGRAM-4a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the PROGRAM domain
PROGRAM-4b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the PROGRAM domain
PROGRAM-4c MIL 2 — performed Personnel performing activities in the PROGRAM domain have the skills and knowledge needed to perform their assigned responsibilities
PROGRAM-4d MIL 2 — performed Responsibility and authority for the performance of activities in the PROGRAM domain are assigned to personnel
PROGRAM-4e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the PROGRAM domain ID.GV-1
PROGRAM-4f MIL 3 — managed Performance objectives for activities in the PROGRAM domain are established and monitored to track achievement
PROGRAM-4g MIL 3 — managed Documented practices for activities in the PROGRAM domain are standardized and improved across the enterprise
RESPONSE — Event and Incident Response  · 32 practices

Detect Cybersecurity Events (RESPONSE-1)

Kybermittari practices in RESPONSE-1, Detect Cybersecurity Events
Practice Level Title NIST CSF
RESPONSE-1a MIL 1 — initiated Detected cybersecurity events are reported to a specified person or role and logged, at least in an ad hoc manner DE.DP-4 RS.CO-2 PR.MA-2
RESPONSE-1b MIL 2 — performed Criteria are established for cybersecurity event detection (e.g., what constitutes a cybersecurity event, where to look for cybersecurity events) DE.DP-2 RS.AN-4
RESPONSE-1c MIL 2 — performed Cybersecurity events are centrally logged based on the established criteria DE.AE-3 RS.AN-1 RS.AN-4
RESPONSE-1d MIL 3 — managed Event information is correlated to support incident analysis by identifying patterns, trends, and other common features DE.AE-2 DE.AE-3 RS.AN-1
RESPONSE-1e MIL 3 — managed Cybersecurity event detection activities are adjusted based on information from the organization’s risk register (RISK-1d) and threat profile (THREAT-1d) to help monitor for identified risks and detect known threats DE.DP-2
RESPONSE-1f MIL 3 — managed Situational awareness for the function is monitored to support the identification of cybersecurity events (SITUATION-2i)

Analyze Cybersecurity Events and Declare Incidents (RESPONSE-2)

Kybermittari practices in RESPONSE-2, Analyze Cybersecurity Events and Declare Incidents
Practice Level Title NIST CSF
RESPONSE-2a MIL 1 — initiated Criteria for declaring cybersecurity incidents are established, at least in an ad hoc manner DE.AE-5 RS.AN-4
RESPONSE-2b MIL 1 — initiated Cybersecurity events are analyzed to support the declaration of cybersecurity incidents, at least in an ad hoc manner DE.AE-4
RESPONSE-2c MIL 2 — performed Cybersecurity incident declaration criteria are formally established based on the potential impact to the function (RISK-1c) DE.AE-4 DE.AE-5 RS.AN-2
RESPONSE-2d MIL 2 — performed Cybersecurity incident declaration criteria are updated at an organization defined frequency
RESPONSE-2e MIL 2 — performed Events are escalated based on established criteria
RESPONSE-2f MIL 2 — performed There is a repository where escalated cybersecurity events and incidents are logged and tracked to closure
RESPONSE-2g MIL 2 — performed Cybersecurity stakeholders (e.g., government, connected organizations, vendors, sector organizations, regulators, internal entities) are identified and notified of events and incidents based on organization-defined criteria (SITUATION-3d) RS.CO-2 RS.CO-3 RS.CO-4 RC.CO-3
RESPONSE-2h MIL 3 — managed Criteria for cybersecurity incident declaration are aligned with the organization’s risk criteria (RISK-2b) DE.AE-4 DE.AE-5 RS.AN-2
RESPONSE-2i MIL 3 — managed Cybersecurity incidents are correlated to support the discovery of patterns, trends, and other common features DE.AE-2 DE.AE-3

Respond to Cybersecurity Events and Incidents (RESPONSE-3)

Kybermittari practices in RESPONSE-3, Respond to Cybersecurity Events and Incidents
Practice Level Title NIST CSF
RESPONSE-3a MIL 1 — initiated Cybersecurity event and incident response personnel are identified and roles are assigned, at least in an ad hoc manner RS.CO-1
RESPONSE-3b MIL 1 — initiated Responses to cybersecurity events and incidents are executed, at least in an ad hoc manner, to limit impact to the function and restore normal operations RS.MI-1 RS.MI-2 RC.RP-1
RESPONSE-3c MIL 1 — initiated Cybersecurity events and incidents are reported to cybersecurity stakeholders, at least in an ad hoc manner DE.DP-4
RESPONSE-3d MIL 2 — performed Cybersecurity incident response plans that address all phases of the incident lifecycle (e.g., triage, escalation, handling, communication, coordination, and closure) are established and maintained RS.RP-1 RS.CO-3 RS.CO-4 RS.AN-3 RC.RP-1 RC.CO-2 RC.CO-3
RESPONSE-3e MIL 2 — performed Cybersecurity event and incident response is executed according to defined plans and procedures PR.IP-9 RS.CO-2 RS.CO-3 RS.CO-4 RC.RP-1
RESPONSE-3f MIL 2 — performed Cybersecurity event and incident response plan exercises are conducted at an organization-defined frequency ID.SC-5 PR.IP-10 DE.DP-3
RESPONSE-3g MIL 3 — managed Cybersecurity event and incident root-cause analysis and lessons-learned activities are performed and corrective actions are taken, including updating incident response plans DE.AE-2 DE.DP-5 RS.AN-3 RS.IM-1 RS.IM-2 RC.IM-1 RC.IM-2
RESPONSE-3h MIL 3 — managed Cybersecurity event and incident responses are coordinated with law enforcement and other external entities as appropriate, including support for evidence collection and preservation RS.CO-3 RS.AN-3
RESPONSE-3i MIL 3 — managed Cybersecurity event and incident response personnel participate in joint cybersecurity exercises with other organizations (e.g., tabletops, simulated incidents) ID.SC-5 DE.DP-3
RESPONSE-3j MIL 3 — managed Cybersecurity event and incident responses leverage and trigger predefined states of operation (SITUATION-3h) RS.AN-4 RC.RP-1

Management Activities (RESPONSE-4)

Kybermittari practices in RESPONSE-4, Management Activities
Practice Level Title NIST CSF
RESPONSE-4a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the RESPONSE domain PR.IP-9 DE.DP-2
RESPONSE-4b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the RESPONSE domain
RESPONSE-4c MIL 2 — performed Personnel performing activities in the RESPONSE domain have the skills and knowledge needed to perform their assigned responsibilities PR.IP-9
RESPONSE-4d MIL 2 — performed Responsibility and authority for the performance of activities in the RESPONSE domain are assigned to personnel PR.IP-9
RESPONSE-4e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the RESPONSE domain PR.IP-9
RESPONSE-4f MIL 3 — managed Performance objectives for activities in the RESPONSE domain are established and monitored to track achievement (PROGRAM-1b)
RESPONSE-4g MIL 3 — managed Documented practices for activities in the RESPONSE domain are standardized and improved across the enterprise
RISK — Risk Management  · 22 practices

Manage Cybersecurity Risk (RISK-1)

Kybermittari practices in RISK-1, Manage Cybersecurity Risk
Practice Level Title NIST CSF
RISK-1a MIL 1 — initiated Cybersecurity risks are identified and documented, at least in an ad hoc manner ID.GV-4 ID.RM-1
RISK-1b MIL 1 — initiated Risks are mitigated, accepted, avoided, or transferred (i.e., risk responses are implemented), at least in an ad hoc manner ID.GV-4 ID.RM-1
RISK-1c MIL 2 — performed Risk assessments are performed to identify risks according to organization-defined triggers (e.g., time elapsed, changes to infrastructure, changes to threat environment) ID.RM-1
RISK-1d MIL 2 — performed Risks are recorded in a risk register (a structured repository of identified risks) ID.RA-1 ID.RA-3 ID.RA-5 ID.RA-6 ID.RM-1 DE.AE-4 DE.AE-5 DE.DP-2 RS.AN-2 RS.MI-3
RISK-1e MIL 2 — performed Risks are analyzed to select and prioritize risk responses using defined risk criteria (RISK-2b) ID.RA-6 ID.RM-1
RISK-1f MIL 2 — performed Risks are tracked to ensure that risk responses are implemented and meet organizational objectives (PROGRAM-1b)
RISK-1g MIL 3 — managed Risk assessments include all assets and activities that are critical to the achievement of the organization’s mission ID.RM-1
RISK-1h MIL 3 — managed The risk management program defines and operates risk management policies and procedures that implement the risk management strategy ID.GV-4 ID.RM-1
RISK-1i MIL 3 — managed A current cybersecurity architecture is used to inform risk analysis (ARCHITECTURE-1c)
RISK-1j MIL 3 — managed The risk register includes all risks identified through cybersecurity risk assessments and is used to support risk management activities ID.RA-1 ID.RA-3 ID.RA-5 ID.RA-6 ID.RM-1 DE.AE-4 DE.AE-5 DE.DP-2 RS.AN-2 RS.MI-3

Establish Cybersecurity Risk Management Strategy (RISK-2)

Kybermittari practices in RISK-2, Establish Cybersecurity Risk Management Strategy
Practice Level Title NIST CSF
RISK-2a MIL 2 — performed There is a documented cybersecurity risk management strategy ID.RM-1
RISK-2b MIL 2 — performed Organizational risk criteria (criteria that the organization uses for evaluating, categorizing, and prioritizing operational risks based on impact, risk tolerance, and risk response capabilities) are defined and available ID.AM-4 ID.BE-1 ID.BE-2 ID.BE-3 ID.BE-4 ID.GV-4 ID.RA-1 ID.RA-4 ID.RA-5 ID.RA-6 ID.RM-1 ID.RM-2 ID.RM-3 PR.AC-1 PR.IP-9 DE.CM-8 DE.DP-2
RISK-2c MIL 3 — managed The risk management strategy defines risk response options for the organization ID.RM-1 ID.RA-6
RISK-2d MIL 3 — managed The risk management strategy is periodically updated to reflect the current threat environment ID.RM-1
RISK-2e MIL 3 — managed An organization-specific risk taxonomy (a catalogued collection of common risks that the organization is subject to and must manage) is documented and is used in risk management activities ID.GV-4 ID.RM-1 ID.RM-2

Management Activities (RISK-3)

Kybermittari practices in RISK-3, Management Activities
Practice Level Title NIST CSF
RISK-3a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the RISK domain ID.RM-1
RISK-3b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the RISK domain ID.RM-1
RISK-3c MIL 2 — performed Personnel performing activities in the RISK domain have the skills and knowledge needed to perform their assigned responsibilities ID.RM-1
RISK-3d MIL 2 — performed Responsibility and authority for the performance of activities in the RISK domain are assigned to personnel ID.RM-1
RISK-3e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the RISK domain ID.GV-1 ID.GV-4
RISK-3f MIL 3 — managed Performance objectives for activities in the RISK domain are established and monitored to track achievement (PROGRAM-1b)
RISK-3g MIL 3 — managed Documented practices for activities in the RISK domain are standardized and improved across the enterprise ID.RM-1
SITUATION — Situational Awareness  · 29 practices

Perform Logging (SITUATION-1)

Kybermittari practices in SITUATION-1, Perform Logging
Practice Level Title NIST CSF
SITUATION-1a MIL 1 — initiated Logging is occurring for assets important to the function wherever feasible, at least in an ad hoc manner PR.MA-2 PR.PT-1
SITUATION-1b MIL 2 — performed Logging requirements are established and maintained for assets important to the function PR.DS-8.DISABLED PR.PT-1
SITUATION-1c MIL 2 — performed Log data are being aggregated within the function PR.PT-1
SITUATION-1d MIL 3 — managed Logging requirements are based on risk to the function (i.e., more rigorous logging for higher risk assets) PR.PT-1

Perform Monitoring (SITUATION-2)

Kybermittari practices in SITUATION-2, Perform Monitoring
Practice Level Title NIST CSF
SITUATION-2a MIL 1 — initiated Cybersecurity monitoring activities are performed (e.g., periodic reviews of log data), at least in an ad hoc manner PR.PT-1 DE.AE-1 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7
SITUATION-2b MIL 1 — initiated Operational environments are monitored for anomalous behavior that may indicate a cybersecurity event, at least in an ad hoc manner DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7
SITUATION-2c MIL 2 — performed Monitoring and analysis requirements are established and maintained for the function and address timely review of event data
SITUATION-2d MIL 2 — performed Indicators of anomalous activity are established and maintained based on system logs, data flows, cybersecurity events, and system architecture and are monitored across the operational environment PR.DS-6 PR.PT-1 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7
SITUATION-2e MIL 2 — performed Alarms and alerts are configured to support the identification of cybersecurity events (RESPONSE-1b) DE.AE-5
SITUATION-2f MIL 2 — performed Monitoring activities are aligned with the defined threat profile (THREAT-1d) DE.CM-1 DE.CM-7
SITUATION-2g MIL 3 — managed Monitoring requirements are based on the risk to the function (i.e., more rigorous monitoring for higher risk assets) DE.CM-1 DE.CM-7
SITUATION-2h MIL 3 — managed Automated monitoring is performed across the operational environment to identify anomalous activity PR.DS-6 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-7
SITUATION-2i MIL 3 — managed Risk register (RISK-1d) content is used to identify indicators of anomalous activity
SITUATION-2j MIL 3 — managed Indicators of anomalous activity are evaluated and updated at an organization-defined frequency DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-6 DE.CM-7

Establish and Maintain Situational Awareness (SITUATION-3)

Kybermittari practices in SITUATION-3, Establish and Maintain Situational Awareness
Practice Level Title NIST CSF
SITUATION-3a MIL 2 — performed Methods of communicating the current state of cybersecurity for the function are established and maintained
SITUATION-3b MIL 2 — performed Monitoring data are aggregated to provide an understanding of the operational state of the function
SITUATION-3c MIL 2 — performed Relevant information from across the organization is available to enhance situational awareness
SITUATION-3d MIL 3 — managed Situational awareness reporting requirements have been defined and address timely dissemination of cybersecurity information to organization-defined stakeholders (e.g., government, connected organizations, vendors, sector organizations, regulators, internal entities)
SITUATION-3e MIL 3 — managed Monitoring data are aggregated to provide near-real-time understanding of the cybersecurity state of the function
SITUATION-3f MIL 3 — managed Relevant information from outside the organization is collected and made available across the organization to enhance situational awareness (THREAT-1g, THREAT-2i)
SITUATION-3g MIL 3 — managed Procedures are in place to analyze and deconflict received cybersecurity information in support of situational awareness
SITUATION-3h MIL 3 — managed Predefined states of operation are documented and invoked (through manual or automated processes) based on the analysis of aggregated data (THREAT-1k, RESPONSE-3k)

Management Activities (SITUATION-4)

Kybermittari practices in SITUATION-4, Management Activities
Practice Level Title NIST CSF
SITUATION-4a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the SITUATION domain PR.PT-1
SITUATION-4b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the SITUATION domain
SITUATION-4c MIL 2 — performed Personnel performing activities in the SITUATION domain have the skills and knowledge needed to perform their assigned responsibilities
SITUATION-4d MIL 2 — performed Responsibility and authority for the performance of activities in the SITUATION domain are assigned to personnel
SITUATION-4e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the SITUATION domain PR.PT-1
SITUATION-4f MIL 3 — managed Performance objectives for activities in the SITUATION domain are established and monitored to track achievement (PROGRAM-1b)
SITUATION-4g MIL 3 — managed Documented practices for activities in the SITUATION domain are standardized and improved across the enterprise
THREAT — Threat and Vulnerability Management  · 32 practices

Identify and Respond to Threats (THREAT-1)

Kybermittari practices in THREAT-1, Identify and Respond to Threats
Practice Level Title NIST CSF
THREAT-1a MIL 1 — initiated Internal and external information sources to support threat management activities (e.g., NCCIC, appropriate ISACs, industry associations, vendors, federal briefings) are identified, at least in an ad hoc manner ID.RA-2 ID.RA-3
THREAT-1b MIL 1 — initiated Cybersecurity threat information is gathered and interpreted for the function, at least in an ad hoc manner ID.RA-2 ID.RA-3
THREAT-1c MIL 1 — initiated Threats that are relevant to the delivery of the function are addressed (e.g., implement mitigating controls, monitor threat status), at least in an ad hoc manner PR.DS-1 PR.DS-2 PR.DS-4 PR.DS-5
THREAT-1d MIL 2 — performed A threat profile for the function is established (e.g., characterization of potential threat actors, motives, intent, capabilities, and targets) ID.RA-3 ID.RA-4 ID.RA-6 PR.IP-9 DE.AE-4 DE.AE-5 DE.CM-1 DE.CM-7 DE.DP-2 RS.AN-2
THREAT-1e MIL 2 — performed Threat information sources that collectively address all components of the threat profile are prioritized and monitored ID.RA-3
THREAT-1f MIL 2 — performed Identified threats are analyzed and prioritized and are addressed accordingly ID.RA-4
THREAT-1g MIL 2 — performed Cybersecurity threat information is provided to selected individuals and/or organizations PR.IP-8 DE.DP-4 RS.CO-3 RS.CO-5
THREAT-1h MIL 3 — managed The threat profile for the function is updated at an organization-defined frequency
THREAT-1i MIL 3 — managed Threats that pose ongoing risk to the function are referred to the risk management process for action (RISK-1e) DE.DP-4 RS.CO-3
THREAT-1j MIL 3 — managed Threat monitoring and response activities leverage and trigger predefined states of operation (SITUATION-3h) PR.IP-12 DE.AE-5
THREAT-1k MIL 3 — managed Threat information-sharing stakeholders are identified and engaged based on their relevance to the continued operation of the function (e.g., government, connected organizations, vendors, sector organizations, regulators, information sharing and analysis centers (ISACs), internal entities) PR.IP-8 DE.DP-4 RS.CO-3 RS.CO-5 RC.CO-1
THREAT-1l MIL 3 — managed Secure, automated workflows are used to publish, consume, analyze, and act upon cyber threat information ID.RA-2 DE.DP-4 RS.CO-3 RS.CO-5 RS.AN-5

Reduce Cybersecurity Vulnerabilities (THREAT-2)

Kybermittari practices in THREAT-2, Reduce Cybersecurity Vulnerabilities
Practice Level Title NIST CSF
THREAT-2a MIL 1 — initiated Information sources to support cybersecurity vulnerability discovery are identified (e.g., NCCIC, appropriate ISACs, industry associations, vendors, federal briefings, internal assessments), at least in an ad hoc manner ID.RA-1 ID.RA-2 PR.IP-8 RS.CO-5 RS.AN-5
THREAT-2b MIL 1 — initiated Cybersecurity vulnerability information is gathered and interpreted for the function, at least in an ad hoc manner ID.RA-1 ID.RA-2 RS.AN-5
THREAT-2c MIL 1 — initiated Cybersecurity vulnerability assessments (e.g., end-of-life and end-of-support asset review, software-based scans, penetration tests) are performed, at least in an ad hoc manner ID.RA-1 DE.CM-8 RS.AN-5
THREAT-2d MIL 1 — initiated Cybersecurity vulnerabilities that are relevant to the delivery of the function are addressed (e.g., implement mitigating controls, apply cybersecurity patches), at least in an ad hoc manner PR.DS-1 PR.DS-2 PR.DS-4 PR.DS-5 RS.AN-5 RS.MI-3
THREAT-2e MIL 2 — performed Cybersecurity vulnerability information sources that collectively address all assets important to the function are monitored ID.RA-1 ID.RA-2 RS.AN-5
THREAT-2f MIL 2 — performed Cybersecurity vulnerability assessments are performed at an organization-defined frequency ID.RA-1 ID.RA-3 ID.RA-4
THREAT-2g MIL 2 — performed Identified cybersecurity vulnerabilities are analyzed and prioritized (e.g., the NIST Common Vulnerability Scoring System could be used for software vulnerabilities; internal guidelines could be used to prioritize other types of vulnerabilities) and are addressed accordingly ID.RA-1 RS.AN-5 RS.MI-3
THREAT-2h MIL 2 — performed Operational impact to the function is evaluated prior to deploying patches RS.AN-5
THREAT-2i MIL 2 — performed Information on any discovered cybersecurity vulnerabilities is shared with organization-defined stakeholders PR.IP-8 DE.DP-4 RS.CO-3 RS.CO-5
THREAT-2j MIL 3 — managed Cybersecurity vulnerability assessments are performed for all assets important to the delivery of the function at an organization-defined frequency ID.RA-1 DE.CM-8 RS.AN-5
THREAT-2k MIL 3 — managed Cybersecurity vulnerability assessments are performed by parties that are independent of the operations of the function ID.RA-1 DE.CM-8 RS.AN-5
THREAT-2l MIL 3 — managed Identified vulnerabilities that pose ongoing risk to the function are referred to the risk management process for response (RISK-1e) DE.DP-4 RS.CO-3
THREAT-2m MIL 3 — managed Ongoing risk monitoring includes review and confirmation of actions taken in response to cybersecurity vulnerabilities (e.g., deployment of patches or other activities) where appropriate PR.DS-5 RS.AN-5 RS.MI-3

Management Activities (THREAT-3)

Kybermittari practices in THREAT-3, Management Activities
Practice Level Title NIST CSF
THREAT-3a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the THREAT domain PR.IP-12
THREAT-3b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the THREAT domain
THREAT-3c MIL 2 — performed Personnel performing activities in the THREAT domain have the skills and knowledge needed to perform their assigned responsibilities
THREAT-3d MIL 2 — performed Responsibility and authority for the performance of activities in the THREAT domain are assigned to personnel
THREAT-3e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the THREAT domain PR.IP-12
THREAT-3f MIL 3 — managed Performance objectives for activities in the THREAT domain are established and monitored to track achievement (PROGRAM-1b)
THREAT-3g MIL 3 — managed Documented practices for activities in the THREAT domain are standardized and improved across the enterprise
WORKFORCE — Workforce Management  · 30 practices

Assign Cybersecurity Responsibilities (WORKFORCE-1)

Kybermittari practices in WORKFORCE-1, Assign Cybersecurity Responsibilities
Practice Level Title NIST CSF
WORKFORCE-1a MIL 1 — initiated Cybersecurity responsibilities for the function are identified, at least in an ad hoc manner ID.AM-6 ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 DE.DP-1
WORKFORCE-1b MIL 1 — initiated Cybersecurity responsibilities are assigned to specific people, at least in an ad hoc manner ID.AM-6 ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5
WORKFORCE-1c MIL 2 — performed Cybersecurity responsibilities are assigned to specific roles, including external service providers (e.g., Internet service providers, security as a service providers, cloud service providers, IT/OT service providers) ID.AM-6 ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5
WORKFORCE-1d MIL 2 — performed Cybersecurity responsibilities are documented (e.g., in position descriptions, in performance criteria) PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 DE.DP-1
WORKFORCE-1e MIL 3 — managed Cybersecurity responsibilities and job requirements are reviewed and updated in accordance with organization-defined triggers (e.g., time elapsed, personnel changes, process changes) ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5
WORKFORCE-1f MIL 3 — managed Assigned cybersecurity responsibilities are managed to ensure adequacy and redundancy of coverage, including succession planning ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5

Develop Cybersecurity Workforce (WORKFORCE-2)

Kybermittari practices in WORKFORCE-2, Develop Cybersecurity Workforce
Practice Level Title NIST CSF
WORKFORCE-2a MIL 1 — initiated Cybersecurity training is made available to personnel with assigned cybersecurity responsibilities, at least in an ad hoc manner PR.AT-1
WORKFORCE-2b MIL 1 — initiated Cybersecurity knowledge, skill, and ability requirements and gaps are identified for both current and future operational needs PR.AT-1
WORKFORCE-2c MIL 2 — performed Training, recruiting, and retention efforts are aligned to address identified workforce gaps PR.AT-1
WORKFORCE-2d MIL 2 — performed Cybersecurity training is provided as a prerequisite to granting access to assets that support the delivery of the function (e.g., new personnel training, personnel transfer training) PR.AT-1
WORKFORCE-2e MIL 3 — managed The effectiveness of training programs is evaluated at an organization-defined frequency, and improvements are made as appropriate PR.AT-1
WORKFORCE-2f MIL 3 — managed Training programs include continuing education and professional development opportunities for personnel with significant cybersecurity responsibilities PR.AT-1

Implement Workforce Controls (WORKFORCE-3)

Kybermittari practices in WORKFORCE-3, Implement Workforce Controls
Practice Level Title NIST CSF
WORKFORCE-3a MIL 1 — initiated Personnel vetting (e.g., background checks, drug tests) is performed, at least in an ad hoc manner, at hire for positions that have access to the assets required for delivery of the function PR.IP-11
WORKFORCE-3b MIL 1 — initiated Personnel termination procedures address cybersecurity, at least in an ad hoc manner PR.IP-11
WORKFORCE-3c MIL 2 — performed Personnel vetting is performed at an organization-defined frequency for positions that have access to the assets required for delivery of the function PR.IP-11
WORKFORCE-3d MIL 2 — performed Personnel transfer procedures address cybersecurity ID.GV-2 PR.IP-11
WORKFORCE-3e MIL 3 — managed Vetting is performed for all positions (including employees, vendors, and contractors) at a level commensurate with position risk PR.IP-11
WORKFORCE-3f MIL 3 — managed A formal accountability process that includes disciplinary actions is implemented for personnel who fail to comply with established security policies and procedures PR.IP-11

Increase Cybersecurity Awareness (WORKFORCE-4)

Kybermittari practices in WORKFORCE-4, Increase Cybersecurity Awareness
Practice Level Title NIST CSF
WORKFORCE-4a MIL 1 — initiated Cybersecurity awareness activities occur, at least in an ad hoc manner PR.AT-1
WORKFORCE-4b MIL 2 — performed Objectives for cybersecurity awareness activities are established and maintained (PROGRAM-1b)
WORKFORCE-4c MIL 2 — performed Cybersecurity awareness objectives are aligned with the defined threat profile (THREAT-1d)
WORKFORCE-4d MIL 3 — managed Cybersecurity awareness activities are aligned with the predefined states of operation (SITUATION-3h)
WORKFORCE-4e MIL 3 — managed The effectiveness of cybersecurity awareness activities is evaluated at an organization-defined frequency and improvements are made as appropriate

Management Activities (WORKFORCE-5)

Kybermittari practices in WORKFORCE-5, Management Activities
Practice Level Title NIST CSF
WORKFORCE-5a MIL 2 — performed Documented practices are established, followed, and maintained for activities in the WORKFORCE domain
WORKFORCE-5b MIL 2 — performed Adequate resources (people, funding, and tools) are provided to support activities in the WORKFORCE domain
WORKFORCE-5c MIL 2 — performed Personnel performing activities in the WORKFORCE domain have the skills and knowledge needed to perform their assigned responsibilities
WORKFORCE-5d MIL 2 — performed Responsibility and authority for the performance of activities in the WORKFORCE domain are assigned to personnel
WORKFORCE-5e MIL 3 — managed Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the WORKFORCE domain
WORKFORCE-5f MIL 3 — managed Performance objectives for activities in the WORKFORCE domain are established and monitored to track achievement (PROGRAM-1b)
WORKFORCE-5g MIL 3 — managed Documented practices for activities in the WORKFORCE domain are standardized and improved across the enterprise

Where each reference takes you

Every identifier on this page is a link. Inside the site: a practice identifier links to itself, so you can cite a single row in an audit note; a group heading links to itself; and every article 21(2) letter opens that measure in full — its wording, what it means and what an auditor asks for. Off the site: NIST CSF (NIST Cybersecurity Framework) leave for their own publisher. We hold their identifiers, not their text — those standards are sold or licensed by their owners, and reproducing them here is not ours to do.

Catalogue reviewed , against Kybermittari assessment tool V1 requirements of C2M2-derived, tool version V1. Kybermittari and the documents it comes from belong to Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland.

Sources

We are not affiliated with Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland. Kybermittari and related marks belong to their owners.

Cart 0