Example: confidence

NIST Cybersecurity Framework SANS Policy Templates

NIST Cybersecurity FrameworkSANS Policy Templates12019 NCSR sans Policy TemplatesIntroductionThe Multi-State information Sharing & Analysis Center (MS-ISAC) is offering this guide to the SLTT community, as a resource to assist with the application and advancement of Cybersecurity policies. The Policy Templates are provided courtesy of the sans Institute ( ). The Templates can be used as an outline of an organizational Policy , with additional details to be added by the end Framework referenced in this guide is the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) ( ).

1 219 NCSR • SANS Policy Templates Introduction The Multi-State Information Sharing & Analysis Center (MS-ISAC) is offering this guide to the SLTT community, as a resource to assist with the application and advancement of

Tags:

  Policy, Information, Template, Sans, Sans policy templates

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of NIST Cybersecurity Framework SANS Policy Templates

1 NIST Cybersecurity FrameworkSANS Policy Templates12019 NCSR sans Policy TemplatesIntroductionThe Multi-State information Sharing & Analysis Center (MS-ISAC) is offering this guide to the SLTT community, as a resource to assist with the application and advancement of Cybersecurity policies. The Policy Templates are provided courtesy of the sans Institute ( ). The Templates can be used as an outline of an organizational Policy , with additional details to be added by the end Framework referenced in this guide is the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) ( ).

2 This guide gives the correlation between 35 of the NIST CSF subcategories, and applicable sans Policy Templates . A NIST subcategory is represented by text, such as . This represents the NIST function of Identify and the category of Asset additional information on services provided by the Multi-State information Sharing & Analysis Center (MS-ISAC), please refer to the following page: NCSR sans Policy TemplatesNIST Function: IdentifyIdentify Asset Management ( ) Resources ( , hardware, devices, data, time, and software) are prioritized based on their classification, criticality, and business value).

3 sans Policy template : Acquisition Assessment Policy Identify Supply Chain Risk Management ( ) Suppliers and third-party partners of information systems, components, and services are identified, prioritized, and assessed using a cyber supply chain risk assessment Policy template : Acquisition Assessment Policy Suppliers and third-party partners are routinely assessed using audits, test results, or other forms of evaluations to confirm they are meeting their contractual Policy template : Acquisition Assessment Policy Response and recovery planning and testing are conducted with suppliers and third-party Policy template : Security Response Plan Policy 32019 NCSR sans Policy TemplatesNIST Function.

4 ProtectProtect Identity Management and Access Control ( ) Remote access is Policy template : Remote Access Policy Network integrity is protected ( , network segregation, network segmentation). sans Policy template : Lab Security Policy sans Policy template : Router and Switch Security Policy Protect Data Security ( ) Assets are formally managed throughout removal, transfers, and Policy template : Acquisition Assessment PolicySANS Policy template : Technology Equipment Disposal Policy PR.

5 DS -7 The development and testing environment(s) are separate from the production Policy template : Lab Security Policy sans Policy template : Router and Switch Security Policy Integrity checking mechanisms are used to verify hardware Policy template : Acquisition Assessment Policy Protect information Protection Processes and Procedures ( ) Backups of information are conducted, maintained, and Policy template : Disaster Recovery Plan Policy Data is destroyed according to Policy template : Technology Equipment Disposal Policy Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and Policy template : Data Breach Response Policy sans Policy template : Disaster Recovery Plan Policy sans Policy template : Pandemic Response Planning sans Policy template .

6 Security Response Plan Policy 42019 NCSR sans Policy Templates Response and recovery plans are Policy template : Data Breach Response Policy sans Policy template : Disaster Recovery Plan Policy sans Policy template : Pandemic Response Planning sans Policy template : Security Response Plan Policy Protect Maintenance ( ) Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized Policy template : Remote Access Policy sans Policy template : Remote Access Tools Policy Protect Protective Technology ( ) PR.

7 P T-1 Audit/log records are determined, documented, implemented, and reviewed in accordance with Policy template : information Logging Standard Removable media is protected and its use restricted according to Policy template : Acceptable Use Policy 4 Communications and control networks are Policy template : Router and Switch Security Policy Mechanisms ( , failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse Policy template : Disaster Recovery Plan Policy sans Policy template : Security Response Plan Policy 52019 NCSR sans Policy TemplatesNIST Function: DetectDetect Anomalies and Events ( ) Event data are collected and correlated from multiple sources and Policy template .

8 information Logging Standard62019 NCSR sans Policy TemplatesNIST Function: RespondRespond Response Planning ( ) R S. RP-1 Response plan is executed during or after an Policy template : Security Response Plan Policy Respond Communications ( ) R -1 Personnel know their roles and order of operations when a response is Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Incidents are reported consistent with established Policy template .

9 Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy information is shared consistent with response Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Coordination with stakeholders occurs consistent with response Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Voluntary information sharing occurs with external stakeholders to achieve broader Cybersecurity situational Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template .

10 Security Response Plan Policy Respond Analysis ( ) Incidents are categorized consistent with response Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy 72019 NCSR sans Policy TemplatesRespond Improvements ( ) R S. IM -1 Response plans incorporate lessons Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy Response strategies are Policy template : Data Breach Response Policy sans Policy template : Pandemic Response Planning Policy sans Policy template : Security Response Plan Policy 82019 NCSR sans Policy TemplatesNIST Function.


Related search queries