Develop an understanding of your organization's environment to manage cybersecurity risk to systems, assets, data, and capabilities. This includes identifying critical assets, business environment, governance, risk assessment, and risk management strategy.
Implement appropriate safeguards to ensure the delivery of critical infrastructure services. This function focuses on access control, data security, maintenance, protective technology, and awareness training.
Develop and implement activities to identify the occurrence of a cybersecurity event. This includes anomaly and event detection, continuous security monitoring, and detection processes.
Develop and implement appropriate activities to take action regarding a detected cybersecurity incident. This function covers response planning, communications, analysis, mitigation, and improvements.
Develop and implement appropriate activities to maintain resilience plans and restore any capabilities or services that were impaired due to a cybersecurity incident. This includes recovery planning, improvements, and communications.