NIST CSF · Domain 2
Protect
About 20% of the exam
Protect categories in 2.0
- PR.AA
- identity, authentication and access control
- PR.AT
- awareness and training
- PR.DS
- data security
- PR.PS
- platform security
- PR.IR
- technology infrastructure resilience
- Retired
- older categories redistributed across these
- Purpose
- safeguards that limit the impact
CSF 2.0 folded the older information protection and maintenance categories into platform security and infrastructure resilience
PR.AA, access in practice
- Identities issued, proofed and bound
- Credentials protected across their lifecycle
- Authentication strength matched to risk
- Least privilege and separation of duties
- Physical access managed alongside logical
- Access reviewed and revoked promptly
- Developers kept out of production changes
Identity, authorization and physical entry are judged as one outcome here, not as three separate programs
PR.DS, protecting data
- Confidentiality, integrity and availability of data
- Encryption at rest and in transit
- Keys managed away from the data
- Backups created, protected and tested
- Immutable or offline copies resist ransomware
- Data destroyed securely at end of life
PR.PS, platform security
- Configuration baselines defined and enforced
- Patching and maintenance performed on schedule
- Logs generated and made available
- Software installed only from trusted sources
- Development practices integrate security
- Removable media restricted by policy
PR.IR, resilience built in
- Networks protected from unauthorized access
- Capacity managed to keep availability
- Redundancy sized to recovery objectives
- Resilience tested rather than assumed
- Alternate sites and paths available
- Protection adapts as the environment changes
PR.AT, awareness
- All staff trained for their role
- Privileged roles trained more deeply
- Training refreshed as threats change
- Phishing simulation measures the outcome
- Awareness measured, not merely delivered
Cloud shared responsibility
- Provider secures the underlying infrastructure
- Customer secures data and configuration
- Identity settings remain the customer duty
- The split differs across service tiers
- Contract states who does what
Container and workload protection
- Images scanned and signed before use
- Registries controlled and access limited
- Runtime policy limits container behavior
- Orchestrator roles kept least privileged
- Secrets kept outside the images
Segmentation
- Separate zones by trust level
- Limit lateral movement between zones
- Administrative paths kept out of band
- Rules reviewed rather than accumulated
- Enforcement tested, not just configured
Turning a target profile into safeguards
- Pick the gap subcategory
- Choose an informative reference
- Design the safeguard
- Assign an owner
- Deploy it
- Measure the outcome
- Update the current profile
- Outcome first, technology second
- One safeguard can close several gaps
- Record the evidence for each outcome
- Retest after major environment change
Protect failures
- Backups never restored in a test
- Encryption keys stored beside the data
- Shared administrator accounts still in use
- Leavers keeping access for weeks
- Baselines defined but never enforced
- Training completed with no behavior change
- Cloud defaults left exactly as delivered
Where the 1.1 protect categories went
- PR.AC
- renamed and widened to PR.AA
- PR.DS
- still data security
- PR.IP
- split across platform and resilience
- PR.MA
- maintenance folded into platform security
- PR.PT
- protective technology into platform security
- PR.AT
- still awareness and training
Protection words to separate
- Authentication
- proving who someone is
- Authorization
- deciding what they may do
- Least privilege
- only what the job needs
- Separation of duties
- no one person completes alone
- Hardening
- reducing the attack surface
- Resilience
- keeping service under stress
Backups that survive ransomware
- Offline or immutable copies retained
- Credentials separate from production
- Restores tested on real data
- Recovery time measured against objectives
- The backup catalog protected too
Reference strip: access, data, platform, resilience, people
Access
- Identity proofed and bound
- Strength matched to risk
- Reviewed, revoked, least privileged
Data
- Encrypted at rest and moving
- Keys held apart from data
- Backups tested and immutable
Platform
- Baselines enforced, not just written
- Patching on a schedule
- Trusted sources for software
Resilience
- Capacity and redundancy planned
- Alternate paths available
- Tested against recovery objectives
People
- Role based awareness training
- Privileged users trained deeper
- Behavior change measured
Quick exam traps
- Trap: Protect is only about technical controls
- Trap: A backup counts as tested because the job reported success
- Trap: The cloud provider is responsible for customer access configuration
- Trap: Completing awareness training proves the awareness outcome
- Trap: Segmentation is proven by the firewall rule set alone
- Trap: Encryption removes the need for access control
cybercertprep.com · original revision sheet written from the public body of knowledge