April 16, 2018 Cybersecurity Framework Version 1.1 Appendix B: Glossary This appendix defines selected terms used in the publication. Table 3: Framework Glossary Buyer The people or organizations that consume a given product or service. Category The subdivision of a Function into groups of cybersecurity outcomes, closely tied to programmatic needs and particular activities. Examples of Categories include “Asset Management,” “Identity Management and Access Control,” and “Detection Processes.” Critical Infrastructure Systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on cybersecurity, national economic security, national public health or safety, or any combination of those matters. Cybersecurity The process of protecting information by preventing, detecting, and responding to attacks. Cybersecurity Event A cybersecurity change that may have an impact on organizational operations (including mission, capabilities, or reputation). Cybersecurity Incident A cybersecurity event that has been determined to have an impact on the organization prompting the need for response and recovery. Detect (function) Develop and implement the appropriate activities to identify the occurrence of a cybersecurity event. Framework A risk-based approach to reducing cybersecurity risk composed of three parts: the Framework Core, the Framework Profile, and the Framework Implementation Tiers. Also known as the “Cybersecurity Framework.” Framework Core A set of cybersecurity activities and references that are common across critical infrastructure sectors and are organized around particular outcomes. The Framework Core comprises four types of elements: Functions, Categories, Subcategories, and Informative References. Framework Implementation Tier A lens through which to view the characteristics of an organization’s approach to risk—how an organization views cybersecurity risk and the processes in place to manage that risk. This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018 45

Select target paragraph3