Ilmainen e-kirja: NIS2 haltuun hyödyntäen ISO 27001 -käytäntöjä
Lataa e-kirja

Vaatimuskehikkoon sisältyvät vaatimukset

ID.RM
NIST

Risk Management Strategy

ID.RM-1
NIST

Risk management processes

ID.RM-2
NIST

Risk tolerance

ID.RM-3
NIST

Informing of risk tolerance

ID.SC
NIST

Supply Chain Risk Management

ID.SC-1
NIST

Cyber supply chain

ID.SC-2
NIST

Suppliers and third party partners of information systems

ID.SC-3
NIST

Contracts with suppliers and third-party partners

ID.SC-4
NIST

Audit suppliers and third-party partners

ID.SC-5
NIST

Response and recovery

PR
NIST

PROTECT

PR.AC
NIST

Identity Management

PR.AC-1
NIST

Identity and credential management

PR.AC-2
NIST

Physical access control

PR.AC-3
NIST

Remote access management

PR.AC-4
NIST

Access permissions and authorizations

PR.AC-5
NIST

Network integrity

PR.AC-6
NIST

Proof of identity

PR.AC-7
NIST

User, Authentication and Access Control

PR.AT
NIST

Awareness and Training

PR.AT-1
NIST

Awareness

PR.AT-2
NIST

Privileged users

PR.AT-3
NIST

Third-party stakeholders

PR.AT-4
NIST

Senior executives

NIST Cybersecurity Framework

NIST Cybersecurity Framework is a collaborative effort coordinated by The National Institute of Standards and Technology (NIST, part of the U.S. Department of Commerce) and involving industry, academia, and government.

Framework is designed to help owners and operators of critical infrastructure to identify, assess and manage cyber risks.

  • Advanced tasks e.g. about risk management and incident detection, response and recovery
  • Advanced documentation e.g. on information security risks
  • Generic cyber security guidelines for empoyees, priviliged users, senior management and other stakeholders

Vaatimuskehikon teema-alueet

No items found.