Example: bachelor of science

NIST Cybersecurity Framework SANS Policy Templates

NIST Cybersecurity FrameworkSANS Policy Templates12019 NCSR sans Policy TemplatesIntroductionThe Multi-State Information Sharing & Analysis Center (MS-ISAC) is offering this guide to the SLTT community, as a resource to assist with the application and advancement of Cybersecurity policies. The Policy Templates are provided courtesy of the sans Institute ( ). The Templates can be used as an outline of an organizational Policy , with additional details to be added by the end Framework referenced in this guide is the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) ( ). This guide gives the correlation between 35 of the NIST CSF subcategories, and applicable sans Policy Templates .

7 219 NCSR • SANS Policy Templates Respond – Improvements (RS.IM) RS.IM-1 Response plans incorporate lessons learned. SANS Policy Template: Data Breach Resp onse Policy SANS Policy Template: Pandemic Response Plan ning Policy SANS Policy Template: Security Response Plan Policy RS.IM-2 Response strategies are updated.

Tags:

  Policy, Template, Sans, Sans policy templates

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of NIST Cybersecurity Framework SANS Policy Templates

1 NIST Cybersecurity FrameworkSANS Policy Templates12019 NCSR sans Policy TemplatesIntroductionThe Multi-State Information Sharing & Analysis Center (MS-ISAC) is offering this guide to the SLTT community, as a resource to assist with the application and advancement of Cybersecurity policies. The Policy Templates are provided courtesy of the sans Institute ( ). The Templates can be used as an outline of an organizational Policy , with additional details to be added by the end Framework referenced in this guide is the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) ( ). This guide gives the correlation between 35 of the NIST CSF subcategories, and applicable sans Policy Templates .

2 A NIST subcategory is represented by text, such as . This represents the NIST function of Identify and the category of Asset additional information on services provided by the Multi-State Information Sharing & Analysis Center (MS-ISAC), please refer to the following page: NCSR sans Policy TemplatesNIST Function: IdentifyIdentify Asset Management ( ) Resources ( , hardware, devices, data, time, and software) are prioritized based on their classification, criticality, and business value). sans Policy template : Acquisition Assessment Policy Identify Supply Chain Risk Management ( ) Suppliers and third-party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment Policy template : Acquisition Assessment Policy Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual Policy template .

3 Acquisition Assessment Policy Response and recovery planning and testing are conducted with suppliers and third-party Policy template : Security Response Plan Policy 32019 NCSR sans Policy TemplatesNIST Function: ProtectProtect Identity Management and Access Control ( ) Remote access is Policy template : Remote Access Policy Network integrity is protected ( , network segregation, network segmentation). sans Policy template : Lab Security Policy sans Policy template : Router and Switch Security Policy Protect Data Security ( ) Assets are formally managed throughout removal, transfers, and Policy template : Acquisition Assessment PolicySANS Policy template : Technology Equipment Disposal Policy PR.

4 DS -7 The development and testing environment(s) are separate from the production Policy template : Lab Security Policy sans Policy template : Router and Switch Security Policy Integrity checking mechanisms are used to verify hardware Policy template : Acquisition Assessment Policy Protect Information Protection Processes and Procedures ( ) Backups of information are conducted, maintained, and Policy template : Disaster Recovery Plan Policy Data is destroyed according to Policy template : Technology Equipment Disposal Policy Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and Policy template : Data Breach Response Policy sans Policy template : Disaster Recovery Plan Policy sans Policy template : Pandemic Response Planning sans Policy template : Security Response Plan Policy 42019 NCSR sans Policy Templates Response and recovery plans are Policy template : Data Breach Response Policy sans Policy template : Disaster Recovery Plan Policy sans Policy template : Pandemic Response Planning sans Policy template .

5 Security Response Plan Policy Protect Maintenance ( ) Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized Policy template : Remote Access Policy sans Policy template : Remote Access Tools Policy Protect Protective Technology ( ) PR . P T-1 Audit/log records are determined, documented, implemented, and reviewed in accordance with Policy template : Information Logging Standard Removable media is protected and its use restricted according to Policy template : Acceptable Use Policy 4 Communications and control networks are Policy template : Router and Switch Security Policy Mechanisms ( , failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse Policy template : Disaster Recovery Plan Policy sans Policy template .

6 Security Response Plan Policy 52019 NCSR sans Policy TemplatesNIST Function: DetectDetect Anomalies and Events ( ) Event data are collected and correlated from multiple sources and Policy template : Information Logging Standard62019 NCSR sans Policy TemplatesNIST Function: RespondRespond Response Planning ( ) R S. RP-1 Response plan is executed during or after an Policy template : Security Response Plan Policy Respond Communications ( ) R -1 Personnel know their roles and order of operations when a response is Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Incidents are reported consistent with established Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template .

7 Security Response Plan Policy Information is shared consistent with response Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Coordination with stakeholders occurs consistent with response Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Voluntary information sharing occurs with external stakeholders to achieve broader Cybersecurity situational Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Respond Analysis ( ) Incidents are categorized consistent with response Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy 72019 NCSR sans Policy TemplatesRespond Improvements ( ) R S.

8 IM -1 Response plans incorporate lessons Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Response strategies are Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy 82019 NCSR sans Policy TemplatesNIST Function: RecoverRecover Recovery Planning ( ) RC . RP-1 Recovery plan is executed during or after a Cybersecurity Policy template : Disaster Recovery Plan Policy Recover Improvements ( ) Recovery plans incorporate lessons Policy template : Disaster Recovery Plan Policy Recovery strategies are Policy template : Disaster Recovery Plan PolicyRecover Communications ( ) RC.

9 CO -1 Public relations are Policy template : Disaster Recovery Plan Policy Reputation is repaired after an Policy template : Disaster Recovery Plan Policy Recovery activities are communicated to internal and external stakeholders as well as executive and management Policy template : Disaster Recovery Plan Policy92019 NCSR sans Policy TemplatesAdditional sans Policy TemplatesThe following Policy Templates address additional functions and processes related to an organization s information security:GeneralAcceptable Encryption PolicyClean Desk PolicyDigital Signature Acceptance PolicyEmail PolicyEthics PolicyPassword Construction GuidelinesPassword Protection PolicyNetworkBluetooth Baseline Requirements PolicyWireless Communication PolicyWireless Communication StandardServer SecurityDatabase Credentials PolicyServer Security PolicySoftware Installation PolicyWorkstation Security (For HIPAA) PolicyApplication SecurityWeb Application Security Policy


Related search queries