April 16, 2018
Cybersecurity Framework
Version 1.1
Appendix B: Glossary
This appendix defines selected terms used in the publication.
Table 3: Framework Glossary
Buyer
The people or organizations that consume a given product or service.
Category
The subdivision of a Function into groups of cybersecurity outcomes,
closely tied to programmatic needs and particular activities. Examples
of Categories include “Asset Management,” “Identity Management
and Access Control,” and “Detection Processes.”
Critical
Infrastructure
Systems and assets, whether physical or virtual, so vital to the United
States that the incapacity or destruction of such systems and assets
would have a debilitating impact on cybersecurity, national economic
security, national public health or safety, or any combination of those
matters.
Cybersecurity
The process of protecting information by preventing, detecting, and
responding to attacks.
Cybersecurity
Event
A cybersecurity change that may have an impact on organizational
operations (including mission, capabilities, or reputation).
Cybersecurity
Incident
A cybersecurity event that has been determined to have an impact on
the organization prompting the need for response and recovery.
Detect (function)
Develop and implement the appropriate activities to identify the
occurrence of a cybersecurity event.
Framework
A risk-based approach to reducing cybersecurity risk composed of
three parts: the Framework Core, the Framework Profile, and the
Framework Implementation Tiers. Also known as the “Cybersecurity
Framework.”
Framework Core
A set of cybersecurity activities and references that are common
across critical infrastructure sectors and are organized around
particular outcomes. The Framework Core comprises four types of
elements: Functions, Categories, Subcategories, and Informative
References.
Framework
Implementation
Tier
A lens through which to view the characteristics of an organization’s
approach to risk—how an organization views cybersecurity risk and
the processes in place to manage that risk.
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
45