Contents
1
1.1
1.2
1.3
1.4
1.4.1
1.4.2
1.4.3
1.5
1.5.1
1.5.2
1.5.3
1.5.4
1.6
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.6.10
1.6.11
1.6.12
1.6.13
1.6.14
1.6.15
1.6.16
1.6.17
1.7
1.7.1
1.7.2
Section 1 – Introduction
Overview
Legal foundations
Background and objectives
Scope
Foundation documents and standards
Principles
Measures and references in this document
Introducing the Minimum ICT Standard
Principles of cybersecurity
Organisation and responsibilities
Policy, directives and guidelines
Risk management
Elements of a defence-in-depth strategy
The defence-in-depth concept
Industrial control systems (ICS)
Risk management
Business impact analysis
Action
Cybersecurity architecture
Physical security
Hardware life cycle management
Mobile device configuration
Industrial control systems
ICS network architecture
ICS network perimeter security
Host security
Security monitoring
Information security strategy
Vendor management
The human element
The NIST Framework
The NIST Framework Core
Implementation tiers
4
4
4
4
4
4
5
5
5
5
5
5
6
6
6
6
9
9
9
9
10
10
10
10
11
11
11
11
12
12
12
13
13
13
2
2.1
2.2
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
Part 2 – Implementation
Overview
Identify
Asset management
Business environment
Governance
Risk assessment
Risk management strategy
Supply chain risk management
14
15
15
16
16
17
18
19
20
2.3
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.4
2.4.1
2.4.2
2.4.3
2.5
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.6
2.6.1
2.6.2
2.6.3
Protect
Access management
Awareness and training
Data security
Information protection processes and procedures
Maintenance
Protective technology
Detect
Anomalies and events
Security continuous monitoring
Detection processes
Respond
Response planning
Communications
Analysis
Mitigation
Improvements
Recover
Recovery planning
Improvements
Communications
21
21
22
23
24
25
26
27
27
28
29
30
30
31
32
33
34
35
35
35
36
3
3.1
3.1.1
3.2
3.2.1
3.2.2
3.2.3
3.2.4
3.3
Section 3 – Assessment
Introduction
Task scoring system
Description of an organisation‘s tier level
Tier 1: partial
Tier 2: risk informed
Tier 3: repeatable
Tier 4: adaptive
Interpreting the assessment – an example
37
37
37
37
37
37
38
38
38
4
4.1
4.2
4.3
Appendix
List of figures
List of tables
Glossary
40
40
40
41
Advisory Board, Authors
Licence, Contact information
43
43
Minimum ICT standard 2018
3