April 16, 2018 Cybersecurity Framework Version 1.1 Framework Profile A representation of the outcomes that a particular system or organization has selected from the Framework Categories and Subcategories. Function One of the main components of the Framework. Functions provide the highest level of structure for organizing basic cybersecurity activities into Categories and Subcategories. The five functions are Identify, Protect, Detect, Respond, and Recover. Identify (function) Develop the organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities. Informative Reference A specific section of standards, guidelines, and practices common among critical infrastructure sectors that illustrates a method to achieve the outcomes associated with each Subcategory. An example of an Informative Reference is ISO/IEC 27001 Control A.10.8.3, which supports the “Data-in-transit is protected” Subcategory of the “Data Security” Category in the “Protect” function. Mobile Code A program (e.g., script, macro, or other portable instruction) that can be shipped unchanged to a heterogeneous collection of platforms and executed with identical semantics. Protect (function) Develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services. Privileged User A user that is authorized (and, therefore, trusted) to perform securityrelevant functions that ordinary users are not authorized to perform. Recover (function) Develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event. Respond (function) Develop and implement the appropriate activities to take action regarding a detected cybersecurity event. Risk A measure of the extent to which an entity is threatened by a potential circumstance or event, and typically a function of: (i) the adverse impacts that would arise if the circumstance or event occurs; and (ii) the likelihood of occurrence. Risk Management The process of identifying, assessing, and responding to risk. Subcategory The subdivision of a Category into specific outcomes of technical and/or management activities. Examples of Subcategories include “External information systems are catalogued,” “Data-at-rest is protected,” and “Notifications from detection systems are investigated.” This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018 46

Select target paragraph3