April 16, 2018
Cybersecurity Framework
Version 1.1
Framework
Profile
A representation of the outcomes that a particular system or
organization has selected from the Framework Categories and
Subcategories.
Function
One of the main components of the Framework. Functions provide the
highest level of structure for organizing basic cybersecurity activities
into Categories and Subcategories. The five functions are Identify,
Protect, Detect, Respond, and Recover.
Identify (function)
Develop the organizational understanding to manage cybersecurity
risk to systems, assets, data, and capabilities.
Informative
Reference
A specific section of standards, guidelines, and practices common
among critical infrastructure sectors that illustrates a method to
achieve the outcomes associated with each Subcategory. An example
of an Informative Reference is ISO/IEC 27001 Control A.10.8.3,
which supports the “Data-in-transit is protected” Subcategory of the
“Data Security” Category in the “Protect” function.
Mobile Code
A program (e.g., script, macro, or other portable instruction) that can
be shipped unchanged to a heterogeneous collection of platforms and
executed with identical semantics.
Protect (function)
Develop and implement the appropriate safeguards to ensure delivery
of critical infrastructure services.
Privileged User
A user that is authorized (and, therefore, trusted) to perform securityrelevant functions that ordinary users are not authorized to perform.
Recover (function)
Develop and implement the appropriate activities to maintain plans for
resilience and to restore any capabilities or services that were impaired
due to a cybersecurity event.
Respond
(function)
Develop and implement the appropriate activities to take action
regarding a detected cybersecurity event.
Risk
A measure of the extent to which an entity is threatened by a potential
circumstance or event, and typically a function of: (i) the adverse
impacts that would arise if the circumstance or event occurs; and (ii)
the likelihood of occurrence.
Risk Management
The process of identifying, assessing, and responding to risk.
Subcategory
The subdivision of a Category into specific outcomes of technical
and/or management activities. Examples of Subcategories include
“External information systems are catalogued,” “Data-at-rest is
protected,” and “Notifications from detection systems are
investigated.”
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
46