April 16, 2018
Cybersecurity Framework
Version 1.1
31000:20096, ISO/International Electrotechnical Commission (IEC) 27005:20117, NIST Special
Publication (SP) 800-398, and the Electricity Subsector Cybersecurity Risk Management Process
(RMP) guideline9.
1.3
Docume nt Overview
The remainder of this document contains the following sections and appendices:
Section 2 describes the Framework components: the Framework Core, the Tiers, and the
Profiles.
Section 3 presents examples of how the Framework can be used.
Section 4 describes how to use the Framework for self-assessing and demonstrating
cybersecurity through measurements.
Appendix A presents the Framework Core in a tabular format: the Functions, Categories,
Subcategories, and Informative References.
Appendix B contains a glossary of selected terms.
Appendix C lists acronyms used in this document.
6
7
8
9
International Organization for Standardization, Risk management – Principles and guidelines, ISO 31000:2009,
2009. http://www.iso.org/iso/home/standards/iso31000.htm
International Organization for Standardization/International Electrotechnical Commission, Information
technology – Security techniques – Information security risk management, ISO/IEC 27005:2011, 2011.
https://www.iso.org/standard/56742.html
Joint Task Force Transformation Initiative, Managing Information Security Risk: Organization, Mission, and
Information System View, NIST Special Publication 800-39, March 2011. https://doi.org/10.6028/NIST.SP.80039
U.S. Department of Energy, Electricity Subsector Cybersecurity Risk Management Process, DOE/OE-0003, May
2012. https://energy.gov/sites/prod/files/Cybersecurity Risk Management Process Guideline - Final - May
2012.pdf
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
5