PDF p.14
In progress
Cybersecurity Framework
Summary
PDF p.14Cybersecurity focuses on securing processing hardware and software to ensure information security. The National Institute of Standards and Technology (NIST) framework classifies cybersecurity tasks into five functions: Identify, Protect, Detect, Respond, and Recover.
In plain words
Supplementary — not from your PDFThe NIST Cybersecurity Framework sorts security work into five jobs: Identify what you have and the risks to it, Protect it, Detect attacks, Respond to them, and Recover afterwards.
Detailed explanation
PDF p.14-
Identify
- Definition: Develop security policies and capabilities.
- Tasks: Evaluate risks, threats, and vulnerabilities; recommend security controls to mitigate them.
-
Protect
- Definition: Ensure security is embedded in every stage of IT hardware and software lifecycle.
- Tasks: Procure, develop, install, operate, and decommission IT assets securely.
-
Detect
- Definition: Perform ongoing monitoring to ensure controls are effective.
- Tasks: Proactively monitor for new types of threats.
-
Respond
- Definition: Address threats to systems and data security.
- Tasks: Identify, analyze, contain, and eradicate threats.
-
Recover
- Definition: Restore systems and data after an attack.
- Tasks: Implement cybersecurity resilience measures.
Important terms
taken from the text above- Identify
- Develop security policies and capabilities.
- Protect
- Ensure security is embedded in every stage of IT hardware and software lifecycle.
- Detect
- Perform ongoing monitoring to ensure controls are effective.
- Respond
- Address threats to systems and data security.
- Recover
- Restore systems and data after an attack.
NIST National Institute of Standards and Technology
Examples & real-world scenarios
Supplementary — not from your PDF- Identify: building an asset inventory and a risk assessment.
- Protect: hardening systems and training staff.
- Detect: a monitoring system alerting on suspicious logins.
- Respond: isolating an infected laptop from the network.
- Recover: restoring servers from backup and improving resilience.
Scenario
After a phishing attack, map each step to a NIST function. Spotting the malicious email is Detect. Disabling the stolen account and removing the malware is Respond. Restoring the affected mailboxes is Recover. Adding MFA and new policies so it can't happen again is Protect.
Common mistakes
Supplementary — not from your PDF- Mixing up Detect (finding threats through monitoring) with Respond (acting on them).
- Forgetting Recover. The framework expects you to plan how to restore systems, not just stop attacks.
- Treating the functions as one-time steps. They run continuously.
Practical skills
Supplementary — not from your PDF- Sort a list of security activities into the five NIST functions.
What I should remember
Key Points PDF p.14-
Identify
- Policies and Capabilities: Develop and evaluate.
- Risks and Controls: Assess and recommend.
-
Protect
- Lifecycle Security: Embed security in IT asset lifecycle.
- Operations: Securely manage IT assets.
-
Detect
- Monitoring: Ongoing and proactive.
- Threats: Identify new threats.
-
Respond
- Threat Management: Analyze and contain threats.
- Eradication: Remove threats.
-
Recover
- Resilience: Restore systems and data.
- Recovery Measures: Implement resilience strategies.