Contents 1 1.1 1.2 1.3 1.4 1.4.1 1.4.2 1.4.3 1.5 1.5.1 1.5.2 1.5.3 1.5.4 1.6 1.6.1 1.6.2 1.6.3 1.6.4 1.6.5 1.6.6 1.6.7 1.6.8 1.6.9 1.6.10 1.6.11 1.6.12 1.6.13 1.6.14 1.6.15 1.6.16 1.6.17 1.7 1.7.1 1.7.2 Section 1 – Introduction Overview Legal foundations Background and objectives Scope Foundation documents and standards Principles Measures and references in this document Introducing the Minimum ICT Standard Principles of cybersecurity Organisation and responsibilities Policy, directives and guidelines Risk management Elements of a defence-in-depth strategy The defence-in-depth concept Industrial control systems (ICS) Risk management Business impact analysis Action Cybersecurity architecture Physical security Hardware life cycle management Mobile device configuration Industrial control systems ICS network architecture ICS network perimeter security Host security Security monitoring Information security strategy Vendor management The human element The NIST Framework The NIST Framework Core Implementation tiers 4 4 4 4 4 4 5 5 5 5 5 5 6 6 6 6 9 9 9 9 10 10 10 10 11 11 11 11 12 12 12 13 13 13 2 2.1 2.2 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 Part 2 – Implementation Overview Identify Asset management Business environment Governance Risk assessment Risk management strategy Supply chain risk management 14 15 15 16 16 17 18 19 20 2.3 2.3.1 2.3.2 2.3.3 2.3.4 2.3.5 2.3.6 2.4 2.4.1 2.4.2 2.4.3 2.5 2.5.1 2.5.2 2.5.3 2.5.4 2.5.5 2.6 2.6.1 2.6.2 2.6.3 Protect Access management Awareness and training Data security Information protection processes and procedures Maintenance Protective technology Detect Anomalies and events Security continuous monitoring Detection processes Respond Response planning Communications Analysis Mitigation Improvements Recover Recovery planning Improvements Communications 21 21 22 23 24 25 26 27 27 28 29 30 30 31 32 33 34 35 35 35 36 3 3.1 3.1.1 3.2 3.2.1 3.2.2 3.2.3 3.2.4 3.3 Section 3 – Assessment Introduction Task scoring system Description of an organisation‘s tier level Tier 1: partial Tier 2: risk informed Tier 3: repeatable Tier 4: adaptive Interpreting the assessment – an example 37 37 37 37 37 37 38 38 38 4 4.1 4.2 4.3 Appendix List of figures List of tables Glossary 40 40 40 41 Advisory Board, Authors Licence, Contact information 43 43 Minimum ICT standard 2018 3

Select target paragraph3