NIST CSF · Domain 1
Identify
About 20% of the exam
CSF 2.0 architecture
- Functions
- six, the highest level
- Order
- govern, identify, protect, detect, respond, recover
- Categories
- twenty two outcome groups
- Subcategories
- one hundred and six outcomes
- Identifier form
- function, category, then number
- Informative references
- how other standards map across
- Implementation examples
- illustrations, never requirements
The Core states outcomes, not actions; nothing in the framework names a product or mandates a control
Identify categories in 2.0
- ID.AM
- asset management
- ID.RA
- risk assessment
- ID.IM
- improvement outcomes
- ID.GV
- retired, absorbed into GOVERN
- ID.BE
- retired, business context moved
- ID.SC
- supply chain now in GV.SC
Version 1.1 to 2.0
- Five functions became six
- GOVERN created and listed first
- Governance elements moved out of Identify
- Supply chain now sits in GV.SC
- Scope widened beyond critical infrastructure
- Implementation examples and quick start guides
Profiles
- Scope the profile
- Gather information
- Create the current profile
- Create the target profile
- Analyze the gaps
- Prioritize an action plan
- Implement and update
- Current profile
- outcomes you achieve today
- Target profile
- outcomes you actually need
- Gap analysis
- the distance between the two
- Action plan
- prioritized work with named owners
- Community profile
- baseline shared across a sector
- Organizational profile
- current and target held together
A profile belongs to a scope, so a business unit and the enterprise can legitimately hold different ones
The four tiers
- Tier 1 Partial
- ad hoc, reactive, little awareness
- Tier 2 Risk Informed
- aware but not organization wide
- Tier 3 Repeatable
- formal policy, practices regularly updated
- Tier 4 Adaptive
- improved continuously from lessons learned
- Applied to
- risk governance and risk management
- Choice
- driven by risk, resources, obligations
Tiers describe how risk gets managed, not how good the controls are, and tier four is not the goal for everyone
ID.AM outcomes
- Hardware and software inventoried
- Services and data flows mapped
- Suppliers and external systems recorded
- Assets prioritized by criticality
- Lifecycle tracked to secure disposal
- Inventory accuracy checked, not assumed
ID.RA outcomes
- Vulnerabilities identified and recorded
- Threat intelligence received and used
- Likelihood and impact both estimated
- Risks prioritized and responses chosen
- Responses accept, mitigate, transfer or avoid
- Risk register kept current
ID.IM outcomes
- Improvements found from evaluations
- Lessons from tests and exercises
- Lessons from real incidents
- Improvement plan communicated and tracked
- Continuous, not an annual event
Asset criticality
- Rank by mission dependency
- Weigh data sensitivity and volume
- Consider recovery time needs
- Map upstream and downstream dependencies
- Feeds protection and recovery priorities
Identify failures
- Inventory built once, never refreshed
- Shadow cloud accounts outside the list
- Data flows undocumented across partners
- Supplier tiers based on spend alone
- Risk register with no owners
- Target profile with no gap plan
Supply chain seen from Identify
- Suppliers tiered by access and criticality
- Fourth parties inherit the same exposure
- Due diligence before contracts are signed
- Security requirements written into agreements
- Monitoring continues after onboarding
- Governance for this lives in GV.SC
Informative references
- Map subcategories to other frameworks
- SP 800-53 controls are a common target
- ISO/IEC 27001 mappings ease dual work
- References are guidance, never mandatory
- Check the mapping version is current
- Published mapping tools stay updated
Running an implementation
- Form a cross functional team
- Scope the profile before anything else
- Involve business units in the target
- Prioritize gaps by risk, not ease
- Sequence the work into a roadmap
- Report progress to executives regularly
- Refresh profiles as the business changes
Rapid recall: identifiers
- GV
- the govern function
- ID
- the identify function
- PR
- the protect function
- DE
- the detect function
- RS
- the respond function
- RC
- the recover function
- ID.AM-01
- one subcategory level outcome
CSF next to the RMF
- NIST CSF
- outcome language for the organization
- SP 800-53
- the security and privacy catalog
- SP 800-37
- the risk management framework process
- SP 800-30
- risk assessment guidance
- SP 800-161
- supply chain risk practices
- Relationship
- CSF frames, the others implement
Reference strip: core, profiles, tiers, assets, risk
Core
- Six functions, twenty two categories
- Subcategories state outcomes
- References and examples are guidance
Profiles
- Current shows today
- Target shows what is needed
- Gap drives the action plan
Tiers
- Partial, risk informed, repeatable, adaptive
- About risk management, not maturity
- Chosen, never automatically maximized
Assets
- Hardware, software, services, data
- Flows mapped across boundaries
- Criticality drives protection order
Risk
- Threats, vulnerabilities, likelihood, impact
- Accept, mitigate, transfer, avoid
- Register owned and reviewed
Quick exam traps
- Trap: Every organization should aim for tier four
- Trap: Tiers are maturity levels with a required progression
- Trap: The current profile is written after the target profile is approved
- Trap: Informative references are mandatory controls inside the framework
- Trap: Supply chain outcomes still live in the Identify function
- Trap: An asset inventory once approved does not need reverifying
- Trap: The framework tells you which technologies to deploy
cybercertprep.com · original revision sheet written from the public body of knowledge