April 16, 2018
Function
Category
Business Environment (ID.BE):
The organization’s mission,
objectives, stakeholders, and
activities are understood and
prioritized; this information is
used to inform cybersecurity
roles, responsibilities, and risk
management decisions.
Governance (ID.GV): The
policies, procedures, and
processes to manage and monitor
the organization’s regulatory,
legal, risk, environmental, and
operational requirements are
understood and inform the
Cybersecurity Framework
Subcategory
Version 1.1
Informative References
third-party stakeholders (e.g., suppliers,
customers, partners) are established
ISA 62443-2-1:2009 4.3.2.3.3
ISO/IEC 27001:2013 A.6.1.1
NIST SP 800-53 Rev. 4 CP-2, PS-7, PM-11
ID.BE-1: The organization’s role in the
supply chain is identified and
communicated
COBIT 5 APO08.01, APO08.04, APO08.05,
APO10.03, APO10.04, APO10.05
ISO/IEC 27001:2013 A.15.1.1, A.15.1.2,
A.15.1.3, A.15.2.1, A.15.2.2
NIST SP 800-53 Rev. 4 CP-2, SA-12
ID.BE-2: The organization’s place in
critical infrastructure and its industry sector
is identified and communicated
COBIT 5 APO02.06, APO03.01
ISO/IEC 27001:2013 Clause 4.1
NIST SP 800-53 Rev. 4 PM-8
ID.BE-3: Priorities for organizational
mission, objectives, and activities are
established and communicated
COBIT 5 APO02.01, APO02.06, APO03.01
ISA 62443-2-1:2009 4.2.2.1, 4.2.3.6
NIST SP 800-53 Rev. 4 PM-11, SA-14
ID.BE-4: Dependencies and critical
functions for delivery of critical services
are established
COBIT 5 APO10.01, BAI04.02, BAI09.02
ISO/IEC 27001:2013 A.11.2.2, A.11.2.3, A.12.1.3
NIST SP 800-53 Rev. 4 CP-8, PE-9, PE-11, PM-8,
SA-14
ID.BE-5: Resilience requirements to
support delivery of critical services are
established for all operating states (e.g.
under duress/attack, during recovery,
normal operations)
COBIT 5 BAI03.02, DSS04.02
ISO/IEC 27001:2013 A.11.1.4, A.17.1.1,
A.17.1.2, A.17.2.1
NIST SP 800-53 Rev. 4 CP-2, CP-11, SA-13, SA14
ID.GV-1: Organizational cybersecurity
policy is established and communicated
CIS CSC 19
COBIT 5 APO01.03, APO13.01, EDM01.01,
EDM01.02
ISA 62443-2-1:2009 4.3.2.6
ISO/IEC 27001:2013 A.5.1.1
NIST SP 800-53 Rev. 4 -1 controls from all
security control families
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
25