April 16, 2018
Cybersecurity Framework
Version 1.1
Appendix A: Framework Core
This appendix presents the Framework Core: a listing of Functions, Categories, Subcategories,
and Informative References that describe specific cybersecurity activities that are common
across all critical infrastructure sectors. The chosen presentation format for the Framework Core
does not suggest a specific implementation order or imply a degree of importance of the
Categories, Subcategories, and Informative References. The Framework Core presented in this
appendix represents a common set of activities for managing cybersecurity risk. While the
Framework is not exhaustive, it is extensible, allowing organizations, sectors, and other entities
to use Subcategories and Informative References that are cost-effective and efficient and that
enable them to manage their cybersecurity risk. Activities can be selected from the Framework
Core during the Profile creation process and additional Categories, Subcategories, and
Informative References may be added to the Profile. An organization’s risk management
processes, legal/regulatory requirements, business/mission objectives, and organizational
constraints guide the selection of these activities during Profile creation. Personal information is
considered a component of data or assets referenced in the Categories when assessing security
risks and protections.
While the intended outcomes identified in the Functions, Categories, and Subcategories are the
same for IT and ICS, the operational environments and considerations for IT and ICS differ. ICS
have a direct effect on the physical world, including potential risks to the health and safety of
individuals, and impact on the environment. Additionally, ICS have unique performance and
reliability requirements compared with IT, and the goals of safety and efficiency must be
considered when implementing cybersecurity measures.
For ease of use, each component of the Framework Core is given a unique identifier. Functions
and Categories each have a unique alphabetic identifier, as shown in Table 1. Subcategories
within each Category are referenced numerically; the unique identifier for each Subcategory is
included in Table 2.
Additional supporting material, including Informative References, relating to the Framework can
be found on the NIST website at http://www.nist.gov/cyberframework/.
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
22