A set of comprehensive guidelines and best practices developed by the National Institute of Standards and Technology to manage cybersecurity risk.
Core Functions
Identify - Understand the organizational context, assets, and risks
Protect - Implement safeguards to ensure service delivery
Detect - Develop activities to identify cybersecurity events
Respond - Take action regarding detected incidents
Recover - Restore capabilities after a cybersecurity event.
Implementation Tiers
Tier 1: Partial
Tier 2: Risk-Informed
Tier 3: Repeatable
Tier 4: Adaptive