Kybermittari — Cybermeter
NIS2 says what you must achieve, never how you demonstrate it. Finland answers with Kybermittari. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
Kybermittari is a self-assessment instrument published by the authority, not a certification scheme and not a legal requirement. A completed assessment evidences that you have measured yourself against a recognised model — it does not certify anything, and it does not by itself demonstrate NIS2 compliance.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 remains the certifiable route in Finland; Kybermittari is commonly used alongside it to direct effort rather than to replace it.
What it is built on
Kybermittari does not invent its own taxonomy. It sits on The US Department of Energy Cybersecurity Capability Maturity Model (C2M2) and the NIST Cybersecurity Framework.
Kybermittari is a capability maturity assessment rather than a control checklist: an organisation scores its own practices by domain and by maturity indicator level, then works the gaps. It was built for critical infrastructure operators but the authority presents it as suitable for any size and sector.
How it covers the ten NIS2 measures
Article 21(2) is the article of NIS2 — Directive (EU) 2022/2555 — that lists the ten risk-management measures every entity in scope owes, lettered (a) to (j). Those ten letters are the first column of each table on this page, and the keys every mapping we publish hangs off. The ten measures, one by one.
Kybermittari follows the domains of the DoE Cybersecurity Capability Maturity Model, each assessed across maturity indicator levels MIL 0 to MIL 3. Traficom carries eleven domains rather than the ten of C2M2: it adds CRITICAL, the protection of services critical to society, and it names the supply chain domain DEPENDENCIES.
Domain level. The model scores capability maturity, not conformity, so it tells you where you are weak rather than whether you meet a legal obligation. It also says nothing about which MIL satisfies article 21(2) — nothing does, because the directive sets no maturity target. CRITICAL is not placed against a measure here: it is Traficom's own addition, and putting it under a letter would be our invention rather than their model.
| NIS2 art. 21(2) Directive (EU) 2022/2555 | Measure | Kybermittari — Kybermittari domain |
|---|---|---|
| (a) | Risk analysis and security policies | RISK PROGRAM |
| (b) | Incident handling | RESPONSE SITUATION |
| (c) | Business continuity | RESPONSE ARCHITECTURE |
| (d) | Supply chain security | DEPENDENCIES |
| (e) | Security in acquisition, development and maintenance | THREAT ARCHITECTURE |
| (f) | Assessing the effectiveness of the measures | PROGRAM RISK |
| (g) | Basic cyber hygiene and cybersecurity training | WORKFORCE |
| (h) | Cryptography and encryption | ARCHITECTURE |
| (i) | Human resources security, access control and asset management | ACCESS ASSET WORKFORCE |
| (j) | Multi-factor authentication and secured communications | ACCESS ARCHITECTURE |
11 Kybermittari domain units, in full
- ASSET — Asset Management
- THREAT — Threat and Vulnerability Management
- RISK — Risk Management
- ACCESS — Identity and Access Management
- SITUATION — Situational Awareness
- RESPONSE — Event and Incident Response, Continuity of Operations
- DEPENDENCIES — Supply Chain and External Dependencies Management
- CRITICAL — Protection of services critical to society
- WORKFORCE — Workforce Management
- ARCHITECTURE — Cybersecurity Architecture
- PROGRAM — Cybersecurity Program Management
What you already have, for the same measure
Nobody in scope starts from nothing. Kybermittari is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| NIS2 art. 21(2) Directive (EU) 2022/2555 | Kybermittari | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|---|
| (a) Risk analysis | RISK PROGRAM | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | RESPONSE SITUATION | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | RESPONSE ARCHITECTURE | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | DEPENDENCIES | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | THREAT ARCHITECTURE | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | PROGRAM RISK | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | WORKFORCE | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | ARCHITECTURE | 8.24 | SC |
| (i) HR, access, assets | ACCESS ASSET WORKFORCE | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | ACCESS ARCHITECTURE | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
325 practices, and the level each one enters at
A mapping says which of the ten measures a framework serves. A catalogue says which practice, at which level. Here are all 325, as Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland publishes them.
Published by Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland, under CC BY 4.0
Traficom / NCSC-FI, Kybermittari assessment tool V1 — CC BY 4.0. Structure and counts here are derived from that publication; identifiers and wording are theirs.
- Traficom / NCSC-FI, Kybermittari assessment tool V1 (Excel), sheets Data, Languages and NISTMap
Get the official documents from https://www.kyberturvallisuuskeskus.fi/en/our-services/situation-awareness-and-network-management/kybermittari-cybermeter — the framework and everything published with it belong to its owner, and that publication is the version that binds. Kybermittari material is published by Traficom under CC BY 4.0.
- Practice wording is the English column of the tool itself, published alongside Finnish and Swedish.
- The NIST CSF column is the crosswalk Traficom publishes in the tool. There is no crosswalk to article 21(2) — the letters on this page are our own thematic mapping, at domain level.
- The tool carries eleven domains, not the ten of C2M2: Traficom adds CRITICAL, the protection of services critical to society, which is the NIS2 angle exactly.
What each level adds
Depth here is one thing: how many more practices the next level pulls in. Each level contains everything below it, which is checked on every extraction.
| Level | Adds | Cumulative |
|---|---|---|
| MIL 1 — initiated | +60 | 60 |
| MIL 2 — performed | +147 | 207 |
| MIL 3 — managed | +118 | 325 |
What these levels are, and are not
MIL levels are not assurance tiers you are assigned: you reach MIL 2 in a domain only by performing every MIL 1 practice in it, and you set your own target profile. Nothing in Finnish law assigns you a MIL, and reaching one discharges no obligation.
The catalogue, practice by practice
11 domains, 42 objectives, 325 practices. Each row carries the level at which it becomes due.
ACCESS — Identity and Access Management · 22 practices
Establish and Maintain Identities (ACCESS-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ACCESS-1a | MIL 1 — initiated | Identities are provisioned, at least in an ad hoc manner, for personnel and other entities (e.g., services, devices) that require access to assets (note that this does not preclude shared identities) | PR.AC-1 |
| ACCESS-1b | MIL 1 — initiated | Credentials are issued for personnel and other entities that require access to assets (e.g., passwords, smart cards, certificates, keys, lock combinations), at least in an ad hoc manner | PR.AC-1 |
| ACCESS-1c | MIL 1 — initiated | Identities are deprovisioned, at least in an ad hoc manner, when no longer required | PR.AC-1 |
| ACCESS-1d | MIL 2 — performed | Identity repositories are reviewed and updated to ensure accuracy, at an organization-defined frequency | PR.AC-1 |
| ACCESS-1e | MIL 2 — performed | Credentials are periodically reviewed to ensure that they are associated with the correct person or entity | PR.AC-1 PR.AC-6 |
| ACCESS-1f | MIL 2 — performed | Identities are deprovisioned within organization-defined time thresholds when no longer required | PR.AC-1 |
| ACCESS-1g | MIL 3 — managed | Requirements for credentials are based on the organization’s risk criteria (RISK-2b) (e.g., multifactor credentials for higher risk access) and cybersecurity architecture (e.g., credential requirements for accessing security zones (ARCHITECTURE-2b)) | PR.AC-1 PR.AC-7 |
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ACCESS-2a | MIL 1 — initiated | Access requirements (e.g., rules for which types of entities are allowed to access an asset, the limits of allowed access, constraints on remote access, and authentication parameters) are determined, at least in an ad hoc manner | PR.AC-2 PR.AC-3 PR.AC-7 PR.MA-2 PR.PT-2 PR.PT-3 |
| ACCESS-2b | MIL 1 — initiated | Access is granted to identities based on the access requirements, at least in an ad hoc manner | PR.AC-2 PR.AC-3 PR.PT-2 PR.PT-3 |
| ACCESS-2c | MIL 1 — initiated | Access is revoked when no longer required, at least in an ad hoc manner | PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-2 PR.PT-3 |
| ACCESS-2d | MIL 2 — performed | Access requirements incorporate least privilege and separation of duties principles | PR.AC-2 PR.AC-3 PR.AC-4 PR.MA-2 PR.PT-3 |
| ACCESS-2e | MIL 2 — performed | Access requests are reviewed and approved by the asset owner | PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-3 |
| ACCESS-2f | MIL 2 — performed | Root privileges, administrative access, emergency access, and shared accounts receive additional scrutiny and monitoring | PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-3 |
| ACCESS-2g | MIL 3 — managed | Access privileges are reviewed and updated to ensure conformance with access requirements, at an organization-defined frequency | PR.AC-2 PR.AC-3 PR.MA-2 PR.PT-3 |
| ACCESS-2h | MIL 3 — managed | Anomalous access attempts are monitored as indicators of cybersecurity events | PR.PT-3 |
Management Activities (ACCESS-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ACCESS-3a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the ACCESS domain | — |
| ACCESS-3b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the ACCESS domain | — |
| ACCESS-3c | MIL 2 — performed | Personnel performing activities in the ACCESS domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| ACCESS-3d | MIL 2 — performed | Responsibility and authority for the performance of activities in the ACCESS domain are assigned to personnel | — |
| ACCESS-3e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the ACCESS domain | PR.PT-2 |
| ACCESS-3f | MIL 3 — managed | Performance objectives for activities in the ACCESS domain are established and monitored to track achievement (PROGRAM-1b) | — |
| ACCESS-3g | MIL 3 — managed | Documented practices for activities in the ACCESS domain are standardized and improved across the enterprise | — |
ARCHITECTURE — Cybersecurity Architecture · 32 practices
Establish and Maintain Cybersecurity Architecture Strategy and Program (ARCHITECTURE-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ARCHITECTURE-1a | MIL 1 — initiated | The organization has a strategy for cybersecurity architecture, which may be developed and/or managed in an ad hoc manner | PR.AC-5 |
| ARCHITECTURE-1b | MIL 2 — performed | A strategy for cybersecurity architecture is established and maintained to support the organization’s cybersecurity program strategy (PROGRAM-1b) and enterprise architecture | PR.AC-5 |
| ARCHITECTURE-1c | MIL 2 — performed | A documented cybersecurity architecture is established and maintained that includes IT and OT systems and networks and aligns with system and asset categorization and prioritization | PR.AC-5 PR.PT-4 |
| ARCHITECTURE-1d | MIL 2 — performed | Governance for cybersecurity architecture is established and maintained that includes provisions for periodic architectural reviews and an exceptions process (e.g., an architecture review board) | — |
| ARCHITECTURE-1e | MIL 2 — performed | The cybersecurity architecture incorporates confidentiality, integrity, and availability requirements for the function’s assets | PR.AC-5 PR.DS-4 |
| ARCHITECTURE-1f | MIL 2 — performed | The cybersecurity architecture incorporates cybersecurity principles (e.g., least functionality, default deny, least privilege) | PR.AC-5 PR.DS-4 PR.DS-5 PR.PT-4 PR.PT-5 |
| ARCHITECTURE-1g | MIL 3 — managed | The cybersecurity architecture strategy and program are aligned with the organization’s enterprise architecture strategy and program | — |
| ARCHITECTURE-1h | MIL 3 — managed | Conformance of the organization’s systems and networks to the cybersecurity architecture is evaluated according to organization-defined triggers (e.g., time elapsed, changes to systems, networks, or assets) | PR.DS-4 |
| ARCHITECTURE-1i | MIL 3 — managed | The cybersecurity architecture is guided by the information from the organization’s risk taxonomy (RISK-2e) and threat profile (THREAT-1d) to support the implementation of protections against identified threats | — |
Implement Segmentation as an Element of the Cybersecurity Architecture (ARCHITECTURE-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ARCHITECTURE-2a | MIL 1 — initiated | The organization’s IT systems are separated from OT systems through segmentation, either through physical means (e.g., air gaps) or logical means (e.g., network configuration or appliances), at least in an ad hoc manner | PR.AC-5 PR.PT-4 PR.PT-5 |
| ARCHITECTURE-2b | MIL 2 — performed | Assets that are important to the delivery of the function are segmented into multiple security zones based on criteria defined in the cybersecurity architecture (e.g., risk analysis results, security requirements, remote access, functional requirements) | PR.AC-5 PR.PT-4 |
| ARCHITECTURE-2c | MIL 3 — managed | All assets are segmented into security zones based on criteria defined in the cybersecurity architecture | PR.AC-5 PR.PT-4 |
Implement Application Security as an Element of the Cybersecurity Architecture (ARCHITECTURE-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ARCHITECTURE-3a | MIL 2 — performed | Software developed in-house that is to be deployed on assets that are important to the delivery of the function is developed using secure software development practices | DE.CM-4 |
| ARCHITECTURE-3b | MIL 2 — performed | The selection of procured software (e.g., mobile applications, applications to be hosted on premises, software-as-a-service applications) to be deployed on assets that are important to the delivery of the function includes consideration of the vendor’s secure software development practices (DEPENDENCIES-2e) | — |
| ARCHITECTURE-3c | MIL 3 — managed | The architecture review process evaluates the security of new and revised applications prior to deployment (ARCHITECTURE-1h) | PR.DS-6 PR.IP-3 |
| ARCHITECTURE-3d | MIL 3 — managed | Security testing (e.g., static testing, dynamic testing, fuzz testing, penetration testing) is performed for in-house-developed and in-house-tailored applications based on identified risk according to organization-defined triggers (e.g., time elapsed, changes to applications, changes to threat environment) | DE.CM-4 DE.CM-5 |
Implement Data Security as an Element of the Cybersecurity Architecture (ARCHITECTURE-4)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ARCHITECTURE-4a | MIL 1 — initiated | Sensitive data (e.g., PII, PCI, PHI, CEII, IP, operations data) is protected at rest (e.g., encrypted, masked, password-protected, subject to access control lists) at least in an ad hoc manner | PR.DS-1 PR.DS-5 |
| ARCHITECTURE-4b | MIL 1 — initiated | Sensitive data (e.g., PII, PCI, PHI, CEII, IP, operations data) is protected in transit (e.g., encrypted, masked, transmitted using protected mechanisms) at least in an ad hoc manner (ASSET-2c) | PR.DS-2 PR.DS-5 |
| ARCHITECTURE-4c | MIL 2 — performed | Key management infrastructure (i.e., key generation, key storage, key destruction, key update, and key revocation) are established and maintained to support the protection of data-at-rest and data-in-transit | PR.DS-1 PR.DS-2 PR.DS-5 |
| ARCHITECTURE-4d | MIL 2 — performed | Cryptographic controls are established and maintained to support the protection of data-at-rest and data-in-transit as required in the cybersecurity architecture | PR.DS-1 PR.DS-2 PR.DS-5 |
| ARCHITECTURE-4e | MIL 2 — performed | The cybersecurity architecture includes controls (e.g., data loss prevention tools, physical data exfiltration controls) to manage the transmission of data within and between systems based on security requirements (ARCHITECTURE-1e) | PR.AC-5 PR.PT-4 |
| ARCHITECTURE-4f | MIL 3 — managed | The cybersecurity architecture includes protections for all data-at-rest (i.e., on-premise and cloud-based file storage and databases) for selected data categories (ASSET-2c) | PR.DS-1 PR.DS-5 |
| ARCHITECTURE-4g | MIL 3 — managed | The cybersecurity architecture includes protections for all data-in-transit (e.g., within internal networks, across network boundaries, and external traffic, including cloud solutions) for selected data categories (ASSET-2c) | PR.DS-2 PR.DS-5 |
| ARCHITECTURE-4h | MIL 3 — managed | Data protections are tested (e.g., controls validation) according to organization-defined triggers (e.g., time elapsed, changes to system architecture, changes to threat environment) | PR.IP-7 |
| ARCHITECTURE-4i | MIL 3 — managed | The cybersecurity architecture includes protections against unauthorized changes to software, firmware, and information (due to errors or malicious activity) | PR.DS-6 |
Management Activities (ARCHITECTURE-5)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ARCHITECTURE-5a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the ARCHITECTURE domain | — |
| ARCHITECTURE-5b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the ARCHITECTURE domain | — |
| ARCHITECTURE-5c | MIL 2 — performed | Personnel performing activities in the ARCHITECTURE domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| ARCHITECTURE-5d | MIL 2 — performed | Responsibility and authority for the performance of activities in the ARCHITECTURE domain are assigned to personnel | — |
| ARCHITECTURE-5e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the ARCHITECTURE domain | PR.PT-4 |
| ARCHITECTURE-5f | MIL 3 — managed | Performance objectives for activities in the ARCHITECTURE domain are established and monitored to track achievement (PROGRAM-1b) | — |
| ARCHITECTURE-5g | MIL 3 — managed | Documented practices for activities in the ARCHITECTURE domain are standardized and improved across the enterprise | — |
ASSET — Asset, Change and Configuration Management · 31 practices
Manage IT and OT Asset Inventory (ASSET-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ASSET-1a | MIL 1 — initiated | There is an inventory of IT and OT assets that are important to the delivery of the function; management of the inventory may be ad hoc | ID.AM-1 ID.AM-2 ID.AM-5 ID.BE-4 |
| ASSET-1b | MIL 2 — performed | Inventory attributes include information to support the cybersecurity program strategy (PROGRAM-1a) (e.g., locations, asset owners, applicable cybersecurity requirements, service dependencies, service level agreements, end of life dates, end of support dates, and conformance of assets to relevant industry standards) | ID.AM-1 ID.AM-2 ID.AM-5 ID.BE-4 |
| ASSET-1c | MIL 2 — performed | Inventoried assets for the delivery of the function are prioritized based on formally defined criteria | ID.AM-5 ID.BE-4 |
| ASSET-1d | MIL 3 — managed | All IT and OT assets for the delivery of the function are inventoried | ID.AM-1 ID.AM-2 ID.AM-3 ID.BE-4 |
| ASSET-1e | MIL 3 — managed | The asset inventory is current (as defined by the organization) | ID.AM-1 ID.AM-2 ID.BE-4 |
| ASSET-1f | MIL 3 — managed | The asset inventory is used to identify cybersecurity risks (e.g., asset end of life or end of support, single points of failure) | ID.BE-4 ID.RA-5 |
Manage Information Asset Inventory (ASSET-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ASSET-2a | MIL 1 — initiated | There is an inventory of information assets that are important to the delivery of the function (e.g., SCADA set points, customer information, financial data, log data); management of the inventory may be ad hoc | ID.AM-5 ID.BE-4 |
| ASSET-2b | MIL 2 — performed | Inventory attributes include information to support the cybersecurity program strategy (PROGRAM-1a) (e.g., storage locations, backup locations and frequencies, asset owners, applicable cybersecurity requirements, service dependencies, service level agreements) | ID.AM-3 ID.AM-5 ID.BE-4 PR.IP-4 |
| ASSET-2c | MIL 2 — performed | Inventoried information assets are categorized based on a defined scheme | ID.AM-5 ID.BE-4 PR.IP-4 |
| ASSET-2d | MIL 3 — managed | There is an inventory for all information assets related to the delivery of the function | ID.AM-3 ID.AM-5 ID.BE-4 PR.IP-4 |
| ASSET-2e | MIL 3 — managed | The asset inventory is current (as defined by the organization) | ID.AM-3 ID.BE-4 PR.IP-4 |
| ASSET-2f | MIL 3 — managed | The asset inventory is used to identify cybersecurity risks (e.g., risk of disclosure, risk of destruction, risk of tampering) | ID.BE-4 ID.RA-5 |
Manage Asset Configuration (ASSET-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ASSET-3a | MIL 1 — initiated | Configuration baselines are established, at least in an ad hoc manner, for inventoried assets where it is desirable to ensure that multiple assets are configured similarly | PR.DS-8.DISABLED PR.IP-1 |
| ASSET-3b | MIL 1 — initiated | Configuration baselines are used, at least in an ad hoc manner, to configure assets at deployment and restoration | PR.DS-8.DISABLED PR.IP-1 |
| ASSET-3c | MIL 2 — performed | The design of configuration baselines includes cybersecurity objectives (PROGRAM-1b) | PR.IP-1 |
| ASSET-3d | MIL 3 — managed | Asset configurations are monitored for consistency with baselines throughout the assets’ lifecycles | PR.DS-8.DISABLED PR.IP-1 |
| ASSET-3e | MIL 3 — managed | Configuration baselines are reviewed and updated at an organization-defined frequency | PR.IP-1 |
| ASSET-3f | MIL 3 — managed | Configuration baselines incorporate requirements from the applicable security zone (ARCHITECTURE-2b) (e.g., network appliance configurations are tailored to the traffic restrictions for the zone) | PR.IP-1 |
Manage Changes to Assets (ASSET-4)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ASSET-4a | MIL 1 — initiated | Changes to inventoried assets are evaluated before being implemented, at least in an ad hoc manner | PR.DS-3 PR.IP-3 |
| ASSET-4b | MIL 1 — initiated | Changes to inventoried assets are logged, at least in an ad hoc manner | PR.DS-3 PR.IP-3 PR.MA-1 |
| ASSET-4c | MIL 2 — performed | Changes to assets are tested prior to being deployed, whenever possible | PR.DS-3 PR.DS-7 PR.IP-3 |
| ASSET-4d | MIL 2 — performed | Change management practices address the full life cycle of assets (i.e., acquisition, deployment, operation, retirement) | PR.DS-3 PR.IP-2 PR.IP-3 PR.IP-6 |
| ASSET-4e | MIL 3 — managed | Changes to assets are tested for cybersecurity impact prior to being deployed | PR.DS-7 PR.IP-3 |
| ASSET-4f | MIL 3 — managed | Change logs include information about modifications that impact the cybersecurity requirements of assets (availability, integrity, confidentiality) | PR.DS-3 PR.IP-3 PR.MA-1 |
Management Activities (ASSET-5)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| ASSET-5a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the ASSET domain | PR.DS-3 PR.IP-3 |
| ASSET-5b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the ASSET domain | PR.DS-3 PR.MA-1 |
| ASSET-5c | MIL 2 — performed | Personnel performing activities in the ASSET domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| ASSET-5d | MIL 2 — performed | Responsibility and authority for the performance of activities in the ASSET domain are assigned to personnel | — |
| ASSET-5e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the ASSET domain | PR.DS-3 PR.IP-3 PR.IP-5 |
| ASSET-5f | MIL 3 — managed | Performance objectives for activities in the ASSET domain are established and monitored to track achievement (PROGRAM-1b) | — |
| ASSET-5g | MIL 3 — managed | Documented practices for activities in the ASSET domain are standardized and improved across the enterprise | ID.SC-3 |
CRITICAL — Critical Service Protection · 27 practices
Identification of Critical Services and their dependencies (CRITICAL-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| CRITICAL-1a | MIL 1 — initiated | Organization provided services that are critical to the society (critical services), have been identified and documented. | — |
| CRITICAL-1b | MIL 1 — initiated | The data needed to provide the critical services, has been mapped and documented. | — |
| CRITICAL-1c | MIL 1 — initiated | The processes needed to provide the critical services, have been mapped and documented. | — |
| CRITICAL-1d | MIL 1 — initiated | The systems (IT and OT assets) needed to provide the critical services, have been mapped and documented. | — |
| CRITICAL-1e | MIL 2 — performed | The facilities needed to provide the critical services, have been mapped and documented. | — |
| CRITICAL-1f | MIL 2 — performed | The supply chain needed to provide the critical services, has been mapped and documented. | — |
| CRITICAL-1g | MIL 2 — performed | The period of time how quickly the failure of resources (data, processes, systems, facilities, supply chain) needed by critical services, would have a significant impact on the normal operation of the society, has been determined and documented. | — |
| CRITICAL-1h | MIL 3 — managed | The cascade effects across the society of a degraded or failed critical services have been identified and documented. | — |
Governance of Critical Services (CRITICAL-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| CRITICAL-2a | MIL 1 — initiated | All resources (data, processes, systems, facilities, supply chain) that are needed to provide the services critical to the society, are within the scope of the organization's security management policies and processes. | — |
| CRITICAL-2b | MIL 1 — initiated | All resources (data, processes, systems, facilities, supply chain) that are needed to provide the services critical to the society, are within the scope of the organization's risk management policies and processes. | — |
| CRITICAL-2c | MIL 2 — performed | Your organisation's approach and policy relating to the security of networks and information systems supporting the delivery of services critical to the society, are owned and managed at board level. These are communicated, in a meaningful way, to risk management decision-makers across the organisation. | — |
| CRITICAL-2d | MIL 2 — performed | Regular board discussions on the security of network and information systems supporting the delivery of your services critical to the society take place, based on timely and accurate information and informed by expert guidance. | — |
| CRITICAL-2e | MIL 2 — performed | There is a board-level individual who has overall accountability for the security of networks and information systems needed by the critical services and drives regular discussion at board-level. | — |
| CRITICAL-2f | MIL 2 — performed | Direction set at board level is translated into effective organisational practices that direct and control the security of the networks and information systems supporting your critical services. | — |
| CRITICAL-2g | MIL 2 — performed | Senior management have visibility of key risk decisions made throughout the organisation. | — |
| CRITICAL-2h | MIL 2 — performed | Risk management decision-makers understand their responsibilities for making effective and timely decisions in the context of the risk appetite regarding the essential service, as set by senior management. | — |
| CRITICAL-2i | MIL 2 — performed | Risk management decision-making is delegated and escalated where necessary, across the organisation, to people who have the skills, knowledge, tools, and authority they need. | — |
| CRITICAL-2j | MIL 3 — managed | Risk management decisions are periodically reviewed to ensure their continued relevance and validity. | — |
| CRITICAL-2k | MIL 3 — managed | The risk management process takes into account the resources (data, processes, systems, facilities, supply chain), critical period of time and cascade effects. | — |
Minimisation of the impact of cyber security incidents on Critical Services (CRITICAL-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| CRITICAL-3a | MIL 1 — initiated | Your response plan covers all of your critical services. | — |
| CRITICAL-3b | MIL 1 — initiated | Your response plan comprehensively covers scenarios that are focused on likely impacts of known and well-understood attacks only. | — |
| CRITICAL-3c | MIL 1 — initiated | Your response plan is understood by all staff who are involved with your organisation's response function | — |
| CRITICAL-3d | MIL 1 — initiated | Your response plan is documented and shared with all relevant stakeholders | — |
| CRITICAL-3e | MIL 2 — performed | Your incident response plan is based on a clear understanding of the security risks to the networks and information systems supporting your essential service . | — |
| CRITICAL-3f | MIL 2 — performed | Your incident response plan is comprehensive (i.e. covers the complete lifecycle of an incident, roles and responsibilities, and reporting) and covers likely impacts of both known attack patterns and of possible attacks, previously unseen. | — |
| CRITICAL-3g | MIL 3 — managed | Your incident response plan is documented and integrated with wider organisational business and supply chain response plans. | — |
| CRITICAL-3h | MIL 3 — managed | Your incident response plan is communicated and understood by the business areas involved with the supply or maintenance of your essential services. | — |
DEPENDENCIES — Supply Chain and External Dependencies Management · 28 practices
Identify Dependencies (DEPENDENCIES-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| DEPENDENCIES-1a | MIL 1 — initiated | Important IT and OT supplier dependencies are identified (i.e., internal and external parties on which the delivery of the function depends, including operating partners), at least in an ad hoc manner | ID.AM-4 ID.BE-4 ID.SC-2 |
| DEPENDENCIES-1b | MIL 1 — initiated | Important customer dependencies are identified (i.e., internal and external parties that are dependent on the delivery of the function, including operating partners), at least in an ad hoc manner | ID.BE-1 ID.BE-2 ID.SC-2 |
| DEPENDENCIES-1c | MIL 2 — performed | Supplier dependencies are identified according to established criteria | ID.AM-4 ID.BE-4 ID.SC-2 |
| DEPENDENCIES-1d | MIL 2 — performed | Customer dependencies are identified according to established criteria | ID.BE-1 ID.BE-2 ID.SC-2 |
| DEPENDENCIES-1e | MIL 2 — performed | Single-source and other essential dependencies are identified | ID.AM-4 ID.BE-4 ID.SC-2 |
| DEPENDENCIES-1f | MIL 2 — performed | Dependencies are prioritized | ID.BE-1 ID.BE-2 ID.SC-2 |
| DEPENDENCIES-1g | MIL 3 — managed | Dependency prioritization and identification are based on defined risk criteria (RISK-2b) | ID.AM-4 ID.BE-1 ID.BE-2 ID.BE-4 ID.SC-2 |
Manage Dependency Risk (DEPENDENCIES-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| DEPENDENCIES-2a | MIL 1 — initiated | Significant cybersecurity risks due to suppliers and other dependencies are identified and addressed, at least in an ad hoc manner | ID.SC-1 DE.CM-6 |
| DEPENDENCIES-2b | MIL 1 — initiated | Cybersecurity requirements are considered when establishing relationships with suppliers and other third parties, at least in an ad hoc manner | ID.SC-1 ID.SC-3 |
| DEPENDENCIES-2c | MIL 2 — performed | Identified cybersecurity dependency risks are entered into the risk register (RISK-1d) | ID.SC-1 |
| DEPENDENCIES-2d | MIL 2 — performed | Contracts and agreements with third parties incorporate sharing of cybersecurity threat information | ID.SC-3 |
| DEPENDENCIES-2e | MIL 2 — performed | Cybersecurity requirements are established for suppliers according to a defined practice, including requirements for secure software development practices where appropriate | ID.SC-3 |
| DEPENDENCIES-2f | MIL 2 — performed | Agreements with suppliers and other external entities include cybersecurity requirements | ID.SC-3 |
| DEPENDENCIES-2g | MIL 2 — performed | Evaluation and selection of suppliers and other external entities includes consideration of their ability to meet cybersecurity requirements | ID.SC-3 |
| DEPENDENCIES-2h | MIL 2 — performed | Agreements with suppliers require notification of cybersecurity incidents related to the delivery of the product or service | ID.SC-3 |
| DEPENDENCIES-2i | MIL 2 — performed | Suppliers and other external entities are periodically reviewed for their ability to continually meet the cybersecurity requirements | ID.SC-4 |
| DEPENDENCIES-2j | MIL 3 — managed | Cybersecurity requirements are established for supplier dependencies based on defined risk criteria (RISK-2b) | ID.SC-1 |
| DEPENDENCIES-2k | MIL 3 — managed | Vendor selection criteria include consideration of end-of-life and end-of-support timelines | ID.SC-3 |
| DEPENDENCIES-2l | MIL 3 — managed | Vendor selection criteria include consideration of safeguards against counterfeit or compromised software, hardware, and services | ID.SC-2 ID.SC-3 DE.CM-5 |
| DEPENDENCIES-2m | MIL 3 — managed | Information sources are monitored to identify and avoid supply chain risks (e.g., counterfeit or compromised software, hardware, and services) | ID.SC-4 DE.CM-5 DE.CM-6 |
| DEPENDENCIES-2n | MIL 3 — managed | Acceptance testing of procured assets includes testing for cybersecurity requirements | ID.SC-4 |
Management Activities (DEPENDENCIES-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| DEPENDENCIES-3a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the DEPENDENCIES domain | — |
| DEPENDENCIES-3b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the DEPENDENCIES domain | — |
| DEPENDENCIES-3c | MIL 2 — performed | Personnel performing activities in the DEPENDENCIES domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| DEPENDENCIES-3d | MIL 2 — performed | Responsibility and authority for the performance of activities in the DEPENDENCIES domain are assigned to personnel | — |
| DEPENDENCIES-3e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the DEPENDENCIES domain | — |
| DEPENDENCIES-3f | MIL 3 — managed | Performance objectives for activities in the DEPENDENCIES domain are established and monitored to track achievement (PROGRAM-1b) | — |
| DEPENDENCIES-3g | MIL 3 — managed | Documented practices for activities in the DEPENDENCIES domain are standardized and improved across the enterprise | — |
PROGRAM — Cybersecurity Program Management · 40 practices
Establish Cybersecurity Program Strategy (PROGRAM-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| PROGRAM-1a | MIL 1 — initiated | The organization has a cybersecurity program strategy, which may be developed and/or managed in an ad hoc manner | — |
| PROGRAM-1b | MIL 2 — performed | The cybersecurity program strategy defines objectives for the organization’s cybersecurity activities | — |
| PROGRAM-1c | MIL 2 — performed | The cybersecurity program strategy and priorities are documented and aligned with the organization’s strategic objectives and risk to critical infrastructure | ID.BE-2 |
| PROGRAM-1d | MIL 2 — performed | The cybersecurity program strategy defines the organization’s approach to provide program oversight and governance for cybersecurity activities | — |
| PROGRAM-1e | MIL 2 — performed | The cybersecurity program strategy defines the structure and organization of the cybersecurity program | — |
| PROGRAM-1f | MIL 2 — performed | The cybersecurity program strategy identifies standards and/or guidelines intended to be followed by the program | — |
| PROGRAM-1g | MIL 2 — performed | The cybersecurity program strategy identifies any applicable compliance requirements that must be satisfied by the program | ID.GV-3 |
| PROGRAM-1h | MIL 3 — managed | The cybersecurity program strategy is updated to reflect business changes, changes in the operating environment, and changes in the threat profile (THREAT-1d) | PR.IP-7 |
Sponsor Cybersecurity Program (PROGRAM-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| PROGRAM-2a | MIL 1 — initiated | Resources (people, funding, and tools) are provided, at least in an ad hoc manner, to establish the cybersecurity program | — |
| PROGRAM-2b | MIL 1 — initiated | Senior management, with proper authority, provides support for the cybersecurity program, at least in an ad hoc manner | — |
| PROGRAM-2c | MIL 2 — performed | The cybersecurity program is established according to the cybersecurity program strategy | — |
| PROGRAM-2d | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to operate a cybersecurity program aligned with the program strategy | — |
| PROGRAM-2e | MIL 2 — performed | Senior management sponsorship for the cybersecurity program is visible and active (e.g., the importance and value of cybersecurity activities is regularly communicated by senior management) | — |
| PROGRAM-2f | MIL 2 — performed | Senior management sponsorship is provided for the development, maintenance, and enforcement of cybersecurity policies | ID.GV-1 |
| PROGRAM-2g | MIL 2 — performed | Responsibility for the cybersecurity program is assigned to a role with requisite authority | — |
| PROGRAM-2h | MIL 2 — performed | Stakeholders for cybersecurity program management activities are identified and involved | ID.AM-6 |
| PROGRAM-2i | MIL 3 — managed | The performance of the cybersecurity program is monitored to ensure it aligns with the cybersecurity program strategy | — |
| PROGRAM-2j | MIL 3 — managed | Cybersecurity activities are independently reviewed (i.e., by reviewers outside the cybersecurity program under direction from the organization's governing body) to ensure conformance with cybersecurity policies and procedures | — |
| PROGRAM-2k | MIL 3 — managed | The cybersecurity program addresses and enables the achievement of regulatory compliance as appropriate | ID.GV-3 |
| PROGRAM-2l | MIL 3 — managed | The organization collaborates with external entities to contribute to the development and implementation of cybersecurity standards, guidelines, leading practices, lessons learned, and emerging technologies | — |
Address Cybersecurity in Continuity of Operations (PROGRAM-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| PROGRAM-3a | MIL 1 — initiated | Continuity plans are developed to sustain and restore operation of the function if a cyber event or incident occurs, at least in an ad hoc manner | ID.BE-5 PR.IP-9 |
| PROGRAM-3b | MIL 1 — initiated | Backups of IT, OT, and information assets are available and tested, at least in an ad hoc manner | PR.IP-4 |
| PROGRAM-3c | MIL 2 — performed | An analysis of the impacts from potential cyber events informs the development of continuity plans | PR.IP-9 |
| PROGRAM-3d | MIL 2 — performed | The assets and activities necessary to sustain minimum operations of the function are identified and documented in continuity plans | ID.BE-5 PR.IP-4 |
| PROGRAM-3e | MIL 2 — performed | Continuity plans address IT, OT, and information assets important to the delivery of the function, including the availability of backup data and replacement, redundant, and spare IT and OT assets | PR.PT-5 ID.BE-5 PR.IP-4 PR.IP-9 |
| PROGRAM-3f | MIL 2 — performed | Continuity plans are tested through evaluations and exercises (e.g., walkthroughs, tabletops, dependency testing, testing backups and spares) at an organization-defined frequency | ID.SC-5 PR.IP-9 PR.IP-10 |
| PROGRAM-3g | MIL 2 — performed | Recovery time objectives (RTOs) and recovery point objectives (RPOs) for assets important to the delivery of the function are incorporated into continuity plans | ID.BE-5 |
| PROGRAM-3h | MIL 2 — performed | Cybersecurity incident criteria that trigger the execution of continuity plans are established and communicated to incident response and continuity management functions | RC.RP-1 PR.IP-9 |
| PROGRAM-3i | MIL 3 — managed | Continuity plans are tested through evaluations and exercises at an organization-defined frequency and include current cyber threat scenarios | ID.SC-5 PR.IP-9 PR.IP-10 |
| PROGRAM-3j | MIL 3 — managed | Continuity plans are aligned with the function’s risk taxonomy (RISK-2e) and threat profile (THREAT-1d) to ensure coverage of identified risk categories and threats | — |
| PROGRAM-3k | MIL 3 — managed | The results of continuity plan testing or activation are compared to recovery objectives, and plans are improved accordingly | PR.IP-9 PR.IP-10 RC.IM-1 |
| PROGRAM-3l | MIL 3 — managed | Cybersecurity incident content within continuity plans is periodically reviewed and updated | PR.IP-10 RC.IM-1 |
| PROGRAM-3m | MIL 3 — managed | Continuity plans are periodically reviewed and updated | PR.IP-9 PR.IP-10 |
Management Activities (PROGRAM-4)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| PROGRAM-4a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the PROGRAM domain | — |
| PROGRAM-4b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the PROGRAM domain | — |
| PROGRAM-4c | MIL 2 — performed | Personnel performing activities in the PROGRAM domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| PROGRAM-4d | MIL 2 — performed | Responsibility and authority for the performance of activities in the PROGRAM domain are assigned to personnel | — |
| PROGRAM-4e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the PROGRAM domain | ID.GV-1 |
| PROGRAM-4f | MIL 3 — managed | Performance objectives for activities in the PROGRAM domain are established and monitored to track achievement | — |
| PROGRAM-4g | MIL 3 — managed | Documented practices for activities in the PROGRAM domain are standardized and improved across the enterprise | — |
RESPONSE — Event and Incident Response · 32 practices
Detect Cybersecurity Events (RESPONSE-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| RESPONSE-1a | MIL 1 — initiated | Detected cybersecurity events are reported to a specified person or role and logged, at least in an ad hoc manner | DE.DP-4 RS.CO-2 PR.MA-2 |
| RESPONSE-1b | MIL 2 — performed | Criteria are established for cybersecurity event detection (e.g., what constitutes a cybersecurity event, where to look for cybersecurity events) | DE.DP-2 RS.AN-4 |
| RESPONSE-1c | MIL 2 — performed | Cybersecurity events are centrally logged based on the established criteria | DE.AE-3 RS.AN-1 RS.AN-4 |
| RESPONSE-1d | MIL 3 — managed | Event information is correlated to support incident analysis by identifying patterns, trends, and other common features | DE.AE-2 DE.AE-3 RS.AN-1 |
| RESPONSE-1e | MIL 3 — managed | Cybersecurity event detection activities are adjusted based on information from the organization’s risk register (RISK-1d) and threat profile (THREAT-1d) to help monitor for identified risks and detect known threats | DE.DP-2 |
| RESPONSE-1f | MIL 3 — managed | Situational awareness for the function is monitored to support the identification of cybersecurity events (SITUATION-2i) | — |
Analyze Cybersecurity Events and Declare Incidents (RESPONSE-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| RESPONSE-2a | MIL 1 — initiated | Criteria for declaring cybersecurity incidents are established, at least in an ad hoc manner | DE.AE-5 RS.AN-4 |
| RESPONSE-2b | MIL 1 — initiated | Cybersecurity events are analyzed to support the declaration of cybersecurity incidents, at least in an ad hoc manner | DE.AE-4 |
| RESPONSE-2c | MIL 2 — performed | Cybersecurity incident declaration criteria are formally established based on the potential impact to the function (RISK-1c) | DE.AE-4 DE.AE-5 RS.AN-2 |
| RESPONSE-2d | MIL 2 — performed | Cybersecurity incident declaration criteria are updated at an organization defined frequency | — |
| RESPONSE-2e | MIL 2 — performed | Events are escalated based on established criteria | — |
| RESPONSE-2f | MIL 2 — performed | There is a repository where escalated cybersecurity events and incidents are logged and tracked to closure | — |
| RESPONSE-2g | MIL 2 — performed | Cybersecurity stakeholders (e.g., government, connected organizations, vendors, sector organizations, regulators, internal entities) are identified and notified of events and incidents based on organization-defined criteria (SITUATION-3d) | RS.CO-2 RS.CO-3 RS.CO-4 RC.CO-3 |
| RESPONSE-2h | MIL 3 — managed | Criteria for cybersecurity incident declaration are aligned with the organization’s risk criteria (RISK-2b) | DE.AE-4 DE.AE-5 RS.AN-2 |
| RESPONSE-2i | MIL 3 — managed | Cybersecurity incidents are correlated to support the discovery of patterns, trends, and other common features | DE.AE-2 DE.AE-3 |
Respond to Cybersecurity Events and Incidents (RESPONSE-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| RESPONSE-3a | MIL 1 — initiated | Cybersecurity event and incident response personnel are identified and roles are assigned, at least in an ad hoc manner | RS.CO-1 |
| RESPONSE-3b | MIL 1 — initiated | Responses to cybersecurity events and incidents are executed, at least in an ad hoc manner, to limit impact to the function and restore normal operations | RS.MI-1 RS.MI-2 RC.RP-1 |
| RESPONSE-3c | MIL 1 — initiated | Cybersecurity events and incidents are reported to cybersecurity stakeholders, at least in an ad hoc manner | DE.DP-4 |
| RESPONSE-3d | MIL 2 — performed | Cybersecurity incident response plans that address all phases of the incident lifecycle (e.g., triage, escalation, handling, communication, coordination, and closure) are established and maintained | RS.RP-1 RS.CO-3 RS.CO-4 RS.AN-3 RC.RP-1 RC.CO-2 RC.CO-3 |
| RESPONSE-3e | MIL 2 — performed | Cybersecurity event and incident response is executed according to defined plans and procedures | PR.IP-9 RS.CO-2 RS.CO-3 RS.CO-4 RC.RP-1 |
| RESPONSE-3f | MIL 2 — performed | Cybersecurity event and incident response plan exercises are conducted at an organization-defined frequency | ID.SC-5 PR.IP-10 DE.DP-3 |
| RESPONSE-3g | MIL 3 — managed | Cybersecurity event and incident root-cause analysis and lessons-learned activities are performed and corrective actions are taken, including updating incident response plans | DE.AE-2 DE.DP-5 RS.AN-3 RS.IM-1 RS.IM-2 RC.IM-1 RC.IM-2 |
| RESPONSE-3h | MIL 3 — managed | Cybersecurity event and incident responses are coordinated with law enforcement and other external entities as appropriate, including support for evidence collection and preservation | RS.CO-3 RS.AN-3 |
| RESPONSE-3i | MIL 3 — managed | Cybersecurity event and incident response personnel participate in joint cybersecurity exercises with other organizations (e.g., tabletops, simulated incidents) | ID.SC-5 DE.DP-3 |
| RESPONSE-3j | MIL 3 — managed | Cybersecurity event and incident responses leverage and trigger predefined states of operation (SITUATION-3h) | RS.AN-4 RC.RP-1 |
Management Activities (RESPONSE-4)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| RESPONSE-4a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the RESPONSE domain | PR.IP-9 DE.DP-2 |
| RESPONSE-4b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the RESPONSE domain | — |
| RESPONSE-4c | MIL 2 — performed | Personnel performing activities in the RESPONSE domain have the skills and knowledge needed to perform their assigned responsibilities | PR.IP-9 |
| RESPONSE-4d | MIL 2 — performed | Responsibility and authority for the performance of activities in the RESPONSE domain are assigned to personnel | PR.IP-9 |
| RESPONSE-4e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the RESPONSE domain | PR.IP-9 |
| RESPONSE-4f | MIL 3 — managed | Performance objectives for activities in the RESPONSE domain are established and monitored to track achievement (PROGRAM-1b) | — |
| RESPONSE-4g | MIL 3 — managed | Documented practices for activities in the RESPONSE domain are standardized and improved across the enterprise | — |
RISK — Risk Management · 22 practices
Manage Cybersecurity Risk (RISK-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| RISK-1a | MIL 1 — initiated | Cybersecurity risks are identified and documented, at least in an ad hoc manner | ID.GV-4 ID.RM-1 |
| RISK-1b | MIL 1 — initiated | Risks are mitigated, accepted, avoided, or transferred (i.e., risk responses are implemented), at least in an ad hoc manner | ID.GV-4 ID.RM-1 |
| RISK-1c | MIL 2 — performed | Risk assessments are performed to identify risks according to organization-defined triggers (e.g., time elapsed, changes to infrastructure, changes to threat environment) | ID.RM-1 |
| RISK-1d | MIL 2 — performed | Risks are recorded in a risk register (a structured repository of identified risks) | ID.RA-1 ID.RA-3 ID.RA-5 ID.RA-6 ID.RM-1 DE.AE-4 DE.AE-5 DE.DP-2 RS.AN-2 RS.MI-3 |
| RISK-1e | MIL 2 — performed | Risks are analyzed to select and prioritize risk responses using defined risk criteria (RISK-2b) | ID.RA-6 ID.RM-1 |
| RISK-1f | MIL 2 — performed | Risks are tracked to ensure that risk responses are implemented and meet organizational objectives (PROGRAM-1b) | — |
| RISK-1g | MIL 3 — managed | Risk assessments include all assets and activities that are critical to the achievement of the organization’s mission | ID.RM-1 |
| RISK-1h | MIL 3 — managed | The risk management program defines and operates risk management policies and procedures that implement the risk management strategy | ID.GV-4 ID.RM-1 |
| RISK-1i | MIL 3 — managed | A current cybersecurity architecture is used to inform risk analysis (ARCHITECTURE-1c) | — |
| RISK-1j | MIL 3 — managed | The risk register includes all risks identified through cybersecurity risk assessments and is used to support risk management activities | ID.RA-1 ID.RA-3 ID.RA-5 ID.RA-6 ID.RM-1 DE.AE-4 DE.AE-5 DE.DP-2 RS.AN-2 RS.MI-3 |
Establish Cybersecurity Risk Management Strategy (RISK-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| RISK-2a | MIL 2 — performed | There is a documented cybersecurity risk management strategy | ID.RM-1 |
| RISK-2b | MIL 2 — performed | Organizational risk criteria (criteria that the organization uses for evaluating, categorizing, and prioritizing operational risks based on impact, risk tolerance, and risk response capabilities) are defined and available | ID.AM-4 ID.BE-1 ID.BE-2 ID.BE-3 ID.BE-4 ID.GV-4 ID.RA-1 ID.RA-4 ID.RA-5 ID.RA-6 ID.RM-1 ID.RM-2 ID.RM-3 PR.AC-1 PR.IP-9 DE.CM-8 DE.DP-2 |
| RISK-2c | MIL 3 — managed | The risk management strategy defines risk response options for the organization | ID.RM-1 ID.RA-6 |
| RISK-2d | MIL 3 — managed | The risk management strategy is periodically updated to reflect the current threat environment | ID.RM-1 |
| RISK-2e | MIL 3 — managed | An organization-specific risk taxonomy (a catalogued collection of common risks that the organization is subject to and must manage) is documented and is used in risk management activities | ID.GV-4 ID.RM-1 ID.RM-2 |
Management Activities (RISK-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| RISK-3a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the RISK domain | ID.RM-1 |
| RISK-3b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the RISK domain | ID.RM-1 |
| RISK-3c | MIL 2 — performed | Personnel performing activities in the RISK domain have the skills and knowledge needed to perform their assigned responsibilities | ID.RM-1 |
| RISK-3d | MIL 2 — performed | Responsibility and authority for the performance of activities in the RISK domain are assigned to personnel | ID.RM-1 |
| RISK-3e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the RISK domain | ID.GV-1 ID.GV-4 |
| RISK-3f | MIL 3 — managed | Performance objectives for activities in the RISK domain are established and monitored to track achievement (PROGRAM-1b) | — |
| RISK-3g | MIL 3 — managed | Documented practices for activities in the RISK domain are standardized and improved across the enterprise | ID.RM-1 |
SITUATION — Situational Awareness · 29 practices
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| SITUATION-1a | MIL 1 — initiated | Logging is occurring for assets important to the function wherever feasible, at least in an ad hoc manner | PR.MA-2 PR.PT-1 |
| SITUATION-1b | MIL 2 — performed | Logging requirements are established and maintained for assets important to the function | PR.DS-8.DISABLED PR.PT-1 |
| SITUATION-1c | MIL 2 — performed | Log data are being aggregated within the function | PR.PT-1 |
| SITUATION-1d | MIL 3 — managed | Logging requirements are based on risk to the function (i.e., more rigorous logging for higher risk assets) | PR.PT-1 |
Perform Monitoring (SITUATION-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| SITUATION-2a | MIL 1 — initiated | Cybersecurity monitoring activities are performed (e.g., periodic reviews of log data), at least in an ad hoc manner | PR.PT-1 DE.AE-1 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7 |
| SITUATION-2b | MIL 1 — initiated | Operational environments are monitored for anomalous behavior that may indicate a cybersecurity event, at least in an ad hoc manner | DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7 |
| SITUATION-2c | MIL 2 — performed | Monitoring and analysis requirements are established and maintained for the function and address timely review of event data | — |
| SITUATION-2d | MIL 2 — performed | Indicators of anomalous activity are established and maintained based on system logs, data flows, cybersecurity events, and system architecture and are monitored across the operational environment | PR.DS-6 PR.PT-1 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7 |
| SITUATION-2e | MIL 2 — performed | Alarms and alerts are configured to support the identification of cybersecurity events (RESPONSE-1b) | DE.AE-5 |
| SITUATION-2f | MIL 2 — performed | Monitoring activities are aligned with the defined threat profile (THREAT-1d) | DE.CM-1 DE.CM-7 |
| SITUATION-2g | MIL 3 — managed | Monitoring requirements are based on the risk to the function (i.e., more rigorous monitoring for higher risk assets) | DE.CM-1 DE.CM-7 |
| SITUATION-2h | MIL 3 — managed | Automated monitoring is performed across the operational environment to identify anomalous activity | PR.DS-6 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-7 |
| SITUATION-2i | MIL 3 — managed | Risk register (RISK-1d) content is used to identify indicators of anomalous activity | — |
| SITUATION-2j | MIL 3 — managed | Indicators of anomalous activity are evaluated and updated at an organization-defined frequency | DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-6 DE.CM-7 |
Establish and Maintain Situational Awareness (SITUATION-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| SITUATION-3a | MIL 2 — performed | Methods of communicating the current state of cybersecurity for the function are established and maintained | — |
| SITUATION-3b | MIL 2 — performed | Monitoring data are aggregated to provide an understanding of the operational state of the function | — |
| SITUATION-3c | MIL 2 — performed | Relevant information from across the organization is available to enhance situational awareness | — |
| SITUATION-3d | MIL 3 — managed | Situational awareness reporting requirements have been defined and address timely dissemination of cybersecurity information to organization-defined stakeholders (e.g., government, connected organizations, vendors, sector organizations, regulators, internal entities) | — |
| SITUATION-3e | MIL 3 — managed | Monitoring data are aggregated to provide near-real-time understanding of the cybersecurity state of the function | — |
| SITUATION-3f | MIL 3 — managed | Relevant information from outside the organization is collected and made available across the organization to enhance situational awareness (THREAT-1g, THREAT-2i) | — |
| SITUATION-3g | MIL 3 — managed | Procedures are in place to analyze and deconflict received cybersecurity information in support of situational awareness | — |
| SITUATION-3h | MIL 3 — managed | Predefined states of operation are documented and invoked (through manual or automated processes) based on the analysis of aggregated data (THREAT-1k, RESPONSE-3k) | — |
Management Activities (SITUATION-4)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| SITUATION-4a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the SITUATION domain | PR.PT-1 |
| SITUATION-4b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the SITUATION domain | — |
| SITUATION-4c | MIL 2 — performed | Personnel performing activities in the SITUATION domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| SITUATION-4d | MIL 2 — performed | Responsibility and authority for the performance of activities in the SITUATION domain are assigned to personnel | — |
| SITUATION-4e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the SITUATION domain | PR.PT-1 |
| SITUATION-4f | MIL 3 — managed | Performance objectives for activities in the SITUATION domain are established and monitored to track achievement (PROGRAM-1b) | — |
| SITUATION-4g | MIL 3 — managed | Documented practices for activities in the SITUATION domain are standardized and improved across the enterprise | — |
THREAT — Threat and Vulnerability Management · 32 practices
Identify and Respond to Threats (THREAT-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| THREAT-1a | MIL 1 — initiated | Internal and external information sources to support threat management activities (e.g., NCCIC, appropriate ISACs, industry associations, vendors, federal briefings) are identified, at least in an ad hoc manner | ID.RA-2 ID.RA-3 |
| THREAT-1b | MIL 1 — initiated | Cybersecurity threat information is gathered and interpreted for the function, at least in an ad hoc manner | ID.RA-2 ID.RA-3 |
| THREAT-1c | MIL 1 — initiated | Threats that are relevant to the delivery of the function are addressed (e.g., implement mitigating controls, monitor threat status), at least in an ad hoc manner | PR.DS-1 PR.DS-2 PR.DS-4 PR.DS-5 |
| THREAT-1d | MIL 2 — performed | A threat profile for the function is established (e.g., characterization of potential threat actors, motives, intent, capabilities, and targets) | ID.RA-3 ID.RA-4 ID.RA-6 PR.IP-9 DE.AE-4 DE.AE-5 DE.CM-1 DE.CM-7 DE.DP-2 RS.AN-2 |
| THREAT-1e | MIL 2 — performed | Threat information sources that collectively address all components of the threat profile are prioritized and monitored | ID.RA-3 |
| THREAT-1f | MIL 2 — performed | Identified threats are analyzed and prioritized and are addressed accordingly | ID.RA-4 |
| THREAT-1g | MIL 2 — performed | Cybersecurity threat information is provided to selected individuals and/or organizations | PR.IP-8 DE.DP-4 RS.CO-3 RS.CO-5 |
| THREAT-1h | MIL 3 — managed | The threat profile for the function is updated at an organization-defined frequency | — |
| THREAT-1i | MIL 3 — managed | Threats that pose ongoing risk to the function are referred to the risk management process for action (RISK-1e) | DE.DP-4 RS.CO-3 |
| THREAT-1j | MIL 3 — managed | Threat monitoring and response activities leverage and trigger predefined states of operation (SITUATION-3h) | PR.IP-12 DE.AE-5 |
| THREAT-1k | MIL 3 — managed | Threat information-sharing stakeholders are identified and engaged based on their relevance to the continued operation of the function (e.g., government, connected organizations, vendors, sector organizations, regulators, information sharing and analysis centers (ISACs), internal entities) | PR.IP-8 DE.DP-4 RS.CO-3 RS.CO-5 RC.CO-1 |
| THREAT-1l | MIL 3 — managed | Secure, automated workflows are used to publish, consume, analyze, and act upon cyber threat information | ID.RA-2 DE.DP-4 RS.CO-3 RS.CO-5 RS.AN-5 |
Reduce Cybersecurity Vulnerabilities (THREAT-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| THREAT-2a | MIL 1 — initiated | Information sources to support cybersecurity vulnerability discovery are identified (e.g., NCCIC, appropriate ISACs, industry associations, vendors, federal briefings, internal assessments), at least in an ad hoc manner | ID.RA-1 ID.RA-2 PR.IP-8 RS.CO-5 RS.AN-5 |
| THREAT-2b | MIL 1 — initiated | Cybersecurity vulnerability information is gathered and interpreted for the function, at least in an ad hoc manner | ID.RA-1 ID.RA-2 RS.AN-5 |
| THREAT-2c | MIL 1 — initiated | Cybersecurity vulnerability assessments (e.g., end-of-life and end-of-support asset review, software-based scans, penetration tests) are performed, at least in an ad hoc manner | ID.RA-1 DE.CM-8 RS.AN-5 |
| THREAT-2d | MIL 1 — initiated | Cybersecurity vulnerabilities that are relevant to the delivery of the function are addressed (e.g., implement mitigating controls, apply cybersecurity patches), at least in an ad hoc manner | PR.DS-1 PR.DS-2 PR.DS-4 PR.DS-5 RS.AN-5 RS.MI-3 |
| THREAT-2e | MIL 2 — performed | Cybersecurity vulnerability information sources that collectively address all assets important to the function are monitored | ID.RA-1 ID.RA-2 RS.AN-5 |
| THREAT-2f | MIL 2 — performed | Cybersecurity vulnerability assessments are performed at an organization-defined frequency | ID.RA-1 ID.RA-3 ID.RA-4 |
| THREAT-2g | MIL 2 — performed | Identified cybersecurity vulnerabilities are analyzed and prioritized (e.g., the NIST Common Vulnerability Scoring System could be used for software vulnerabilities; internal guidelines could be used to prioritize other types of vulnerabilities) and are addressed accordingly | ID.RA-1 RS.AN-5 RS.MI-3 |
| THREAT-2h | MIL 2 — performed | Operational impact to the function is evaluated prior to deploying patches | RS.AN-5 |
| THREAT-2i | MIL 2 — performed | Information on any discovered cybersecurity vulnerabilities is shared with organization-defined stakeholders | PR.IP-8 DE.DP-4 RS.CO-3 RS.CO-5 |
| THREAT-2j | MIL 3 — managed | Cybersecurity vulnerability assessments are performed for all assets important to the delivery of the function at an organization-defined frequency | ID.RA-1 DE.CM-8 RS.AN-5 |
| THREAT-2k | MIL 3 — managed | Cybersecurity vulnerability assessments are performed by parties that are independent of the operations of the function | ID.RA-1 DE.CM-8 RS.AN-5 |
| THREAT-2l | MIL 3 — managed | Identified vulnerabilities that pose ongoing risk to the function are referred to the risk management process for response (RISK-1e) | DE.DP-4 RS.CO-3 |
| THREAT-2m | MIL 3 — managed | Ongoing risk monitoring includes review and confirmation of actions taken in response to cybersecurity vulnerabilities (e.g., deployment of patches or other activities) where appropriate | PR.DS-5 RS.AN-5 RS.MI-3 |
Management Activities (THREAT-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| THREAT-3a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the THREAT domain | PR.IP-12 |
| THREAT-3b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the THREAT domain | — |
| THREAT-3c | MIL 2 — performed | Personnel performing activities in the THREAT domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| THREAT-3d | MIL 2 — performed | Responsibility and authority for the performance of activities in the THREAT domain are assigned to personnel | — |
| THREAT-3e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the THREAT domain | PR.IP-12 |
| THREAT-3f | MIL 3 — managed | Performance objectives for activities in the THREAT domain are established and monitored to track achievement (PROGRAM-1b) | — |
| THREAT-3g | MIL 3 — managed | Documented practices for activities in the THREAT domain are standardized and improved across the enterprise | — |
WORKFORCE — Workforce Management · 30 practices
Assign Cybersecurity Responsibilities (WORKFORCE-1)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| WORKFORCE-1a | MIL 1 — initiated | Cybersecurity responsibilities for the function are identified, at least in an ad hoc manner | ID.AM-6 ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 DE.DP-1 |
| WORKFORCE-1b | MIL 1 — initiated | Cybersecurity responsibilities are assigned to specific people, at least in an ad hoc manner | ID.AM-6 ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 |
| WORKFORCE-1c | MIL 2 — performed | Cybersecurity responsibilities are assigned to specific roles, including external service providers (e.g., Internet service providers, security as a service providers, cloud service providers, IT/OT service providers) | ID.AM-6 ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 |
| WORKFORCE-1d | MIL 2 — performed | Cybersecurity responsibilities are documented (e.g., in position descriptions, in performance criteria) | PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 DE.DP-1 |
| WORKFORCE-1e | MIL 3 — managed | Cybersecurity responsibilities and job requirements are reviewed and updated in accordance with organization-defined triggers (e.g., time elapsed, personnel changes, process changes) | ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 |
| WORKFORCE-1f | MIL 3 — managed | Assigned cybersecurity responsibilities are managed to ensure adequacy and redundancy of coverage, including succession planning | ID.GV-2 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 |
Develop Cybersecurity Workforce (WORKFORCE-2)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| WORKFORCE-2a | MIL 1 — initiated | Cybersecurity training is made available to personnel with assigned cybersecurity responsibilities, at least in an ad hoc manner | PR.AT-1 |
| WORKFORCE-2b | MIL 1 — initiated | Cybersecurity knowledge, skill, and ability requirements and gaps are identified for both current and future operational needs | PR.AT-1 |
| WORKFORCE-2c | MIL 2 — performed | Training, recruiting, and retention efforts are aligned to address identified workforce gaps | PR.AT-1 |
| WORKFORCE-2d | MIL 2 — performed | Cybersecurity training is provided as a prerequisite to granting access to assets that support the delivery of the function (e.g., new personnel training, personnel transfer training) | PR.AT-1 |
| WORKFORCE-2e | MIL 3 — managed | The effectiveness of training programs is evaluated at an organization-defined frequency, and improvements are made as appropriate | PR.AT-1 |
| WORKFORCE-2f | MIL 3 — managed | Training programs include continuing education and professional development opportunities for personnel with significant cybersecurity responsibilities | PR.AT-1 |
Implement Workforce Controls (WORKFORCE-3)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| WORKFORCE-3a | MIL 1 — initiated | Personnel vetting (e.g., background checks, drug tests) is performed, at least in an ad hoc manner, at hire for positions that have access to the assets required for delivery of the function | PR.IP-11 |
| WORKFORCE-3b | MIL 1 — initiated | Personnel termination procedures address cybersecurity, at least in an ad hoc manner | PR.IP-11 |
| WORKFORCE-3c | MIL 2 — performed | Personnel vetting is performed at an organization-defined frequency for positions that have access to the assets required for delivery of the function | PR.IP-11 |
| WORKFORCE-3d | MIL 2 — performed | Personnel transfer procedures address cybersecurity | ID.GV-2 PR.IP-11 |
| WORKFORCE-3e | MIL 3 — managed | Vetting is performed for all positions (including employees, vendors, and contractors) at a level commensurate with position risk | PR.IP-11 |
| WORKFORCE-3f | MIL 3 — managed | A formal accountability process that includes disciplinary actions is implemented for personnel who fail to comply with established security policies and procedures | PR.IP-11 |
Increase Cybersecurity Awareness (WORKFORCE-4)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| WORKFORCE-4a | MIL 1 — initiated | Cybersecurity awareness activities occur, at least in an ad hoc manner | PR.AT-1 |
| WORKFORCE-4b | MIL 2 — performed | Objectives for cybersecurity awareness activities are established and maintained (PROGRAM-1b) | — |
| WORKFORCE-4c | MIL 2 — performed | Cybersecurity awareness objectives are aligned with the defined threat profile (THREAT-1d) | — |
| WORKFORCE-4d | MIL 3 — managed | Cybersecurity awareness activities are aligned with the predefined states of operation (SITUATION-3h) | — |
| WORKFORCE-4e | MIL 3 — managed | The effectiveness of cybersecurity awareness activities is evaluated at an organization-defined frequency and improvements are made as appropriate | — |
Management Activities (WORKFORCE-5)
| Practice | Level | Title | NIST CSF |
|---|---|---|---|
| WORKFORCE-5a | MIL 2 — performed | Documented practices are established, followed, and maintained for activities in the WORKFORCE domain | — |
| WORKFORCE-5b | MIL 2 — performed | Adequate resources (people, funding, and tools) are provided to support activities in the WORKFORCE domain | — |
| WORKFORCE-5c | MIL 2 — performed | Personnel performing activities in the WORKFORCE domain have the skills and knowledge needed to perform their assigned responsibilities | — |
| WORKFORCE-5d | MIL 2 — performed | Responsibility and authority for the performance of activities in the WORKFORCE domain are assigned to personnel | — |
| WORKFORCE-5e | MIL 3 — managed | Policies or other organizational directives are established and maintained that enact specific organizational requirements for the implementation of activities in the WORKFORCE domain | — |
| WORKFORCE-5f | MIL 3 — managed | Performance objectives for activities in the WORKFORCE domain are established and monitored to track achievement (PROGRAM-1b) | — |
| WORKFORCE-5g | MIL 3 — managed | Documented practices for activities in the WORKFORCE domain are standardized and improved across the enterprise | — |
Where each reference takes you
Every identifier on this page is a link. Inside the site: a practice identifier links to itself, so you can cite a single row in an audit note; a group heading links to itself; and every article 21(2) letter opens that measure in full — its wording, what it means and what an auditor asks for. Off the site: NIST CSF (NIST Cybersecurity Framework) leave for their own publisher. We hold their identifiers, not their text — those standards are sold or licensed by their owners, and reproducing them here is not ours to do.
Catalogue reviewed , against Kybermittari assessment tool V1 requirements of C2M2-derived, tool version V1. Kybermittari and the documents it comes from belong to Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland.
We are not affiliated with Liikenne- ja viestintävirasto Traficom — National Cyber Security Centre Finland. Kybermittari and related marks belong to their owners.