The Protect Function describes activities that will help an agency to develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services (i.e. services that are so vital that their discontinuation would have a debilitating effect). These activities will support the ability to limit or contain the impact of a potential cybersecurity event.
Identity Management, Authentication and Access Control
Limiting access to assets and associated facilities to only authorized users, processes or devices, and to authorized activities and transactions.
- Manage identities and credentials (i.e. credentials (e.g. passwords, tokens) are used to verify the identity of users and devices to determine if they are authorized to use the system, system component, or network for devices and users.
- Manage and protect physical access to assets.
- Manage remote access (i.e. authorize remote access before connections are established, and implement usage restrictions and connection requirements) .
- Manage access permissions, incorporating the principles of least privilege (i.e. provide users the fewest privileges consist with assigned duties) and separation of duties (i.e. divide tasks for specific/related processes among multiple users/roles).
- Protect network integrity (i.e. keep unauthorized users from gaining access/modifying information) , incorporating network segregation where appropriate (i.e. use subnetworks to separate publicly accessible information/components from internal agency information/components).
- Identities are proofed and bound to credentials and asserted in interactions.
- Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks).
Associated Artifacts
- Access Control Policy Boilerplate v1.1.docx
- Access Control Procedure Boilerplate v1.1.docx
- Mobile Device Management Policy Boilerplate v1.1.docx
- Mobile Device Management Procedure Boilerplate v1.1..docx
- Identification and Authentication Policy Boilerplate v1.1.docx
- Identification and Authentication Procedure Boilerplate v1.1.docx
Awareness and Training
Providing personnel and partners (i.e. contractors, interns, volunteers, etc.) with cybersecurity awareness education. In addition, adequate training should be provided to personnel and partners to perform their information security-related duties and responsibilities consistent with related policies, procedures, and agreements.
- Ensure that all users are informed (i.e. provided with cybersecurity awareness education) and trained (i.e. provided with adequate training for information security-related duties/responsibilities).
- Ensure privileged users (i.e. users who have been given elevated access to information assets to perform administrative functions (e.g. system administrators, information security personnel, etc.)) understand their roles and responsibilities.
- Verify that third-party stakeholders (e.g. suppliers, customers, and partners) understand their information security-related roles and responsibilities.
- Verify that senior executives understand their security-related roles and responsibilities.
- Ensure that both physical security and information security personnel understand their information security-related roles and responsibilities.
Associated Artifacts
Data Security
Managing information and records (data) in accordance with an agency's risk strategy to protect confidentiality, integrity, and availability of information.
- Protect data-at-rest (i.e. stored data not traversing a network (e.g. data on servers at an offsite backup facility, data on external backup mediums)) .
- Protect data-in-transit (i.e., data that can be transmitted, intercepted, and modified by unauthorized users/devices (e.g., data on servers, mobile devices, computers, printers, copiers, scanners, and fax machines)) .
- Formally (i.e., through the use of agency-wide policies and/or procedures) manage assets throughout removals, transfers, and disposal.
- Maintain adequate capacity (e.g. for networks, bandwidth) to ensure continuous availability of information (i.e. prevent the disruption of access to information or to the use of an information system).
- Protect against data leaks (i.e. intentional or unintentional transmission of information from inside an agency to outside the agency (e.g. customer data, confidential agency information, health information, etc.)) .
- Verify the integrity (i.e. preventing the unauthorized modification or destruction of information) of software, firmware, and information through the use of integrity checking mechanisms (e.g. encrypting file systems, making stored files read-only, etc.).
- Ensure development and testing environment(s) (i.e. portion of the network where applications are developed for use or tested before use on the network) are kept separate from the portion of the network where applications are used for business functions production environment.
- Integrity checking mechanisms are used to verify hardware integrity.
Associated Artifacts
- Privacy Data Protection Policy Boilerplate v1.1.docx
- Privacy Data Protection Procedure Boilerplate v1.1.docx
- System and Communications Protection Policy Boilerplate v1.1.docx
- System and Communications Protection Procedure Boilerplate v1.1.docx
- System and Information Integrity Policy Boilerplate v1.1.docx
- System and Information Integrity Procedure Boilerplate v1.1.docx
Information Protection Processes and Procedures
Using regularly maintained security policies (that address purpose, scope, roles, responsibilities, management commitment, and coordination among agency entities) to manage protection of information systems and assets.
- Create and maintain a baseline configuration (i.e. a documented reference of the initial state ("preferred working state") of a system before changes occur, and included should be a detailed inventory of installed software packages and versions, a list of critical files, network configuration, and hardware configuration) of information technology/industrial systems.
- Implement a System Development Life Cycle (SDLC) (i.e. a documented process for planning, creating, testing, and deploying information systems and applications) to manage systems.
- Ensure configuration change control (i.e. a process, initiated by a request for change, for the tracking and approval of all configuration changes an information system undergoes. Examples of an event may include, the desire to upgrade the software of an information system or the need to expand the use of an information system to multiple departments or to multiple sections within a department) processes are in place.
- Conduct, maintain, and periodically test backups of information.
- Adhere to policy and regulations regarding the physical operating environment (e.g. emergency power shutoff, emergency lighting, humidity and temperature controls, fire protection, water damage protections, and careful positioning of information assets) for agency assets.
- Ensure data is destroyed according to policy.
- Ensure protection processes are continuously improved.
- Ensure effectiveness of protection technologies is shared with appropriate parties.
- Ensure response plans (e.g. Incident Response and Business Continuity) and recovery plans (e.g. Incident Recovery and Disaster Recovery) are in place and managed.
- Periodically test the response and recovery plans.
- Ensure cybersecurity is included in human resources practices (e.g., deprovisioning (revoking a user's access to information systems upon termination of employment) , establishing the risk for authorizing access to information assets via background checks or security clearance investigations personnel screening).
- Develop and maintain a vulnerability management plan.
Associated Artifacts
- Configuration Management Policy Boilerplate v1.1.docx
- Configuration Management Procedure Boilerplate v1.1.docx
- Physical and Environmental Protection Policy Boilerplate v1.1.docx
- Physical and Environmental Protection Procedure Boilerplate v1.1.docx
- Security Planning Policy Boilerplate v1.1.docx
- Security Planning Procedure Boilerplate v1.1.docx
- System and Services Acquisition Policy Boilerplate v1.1.docx
- System and Services Acquisition Procedure Boilerplate v1.1.docx
Maintenance
Ensuring maintenance and repairs of agency access control mechanisms (i.e. methods that selectively restrict access to an information asset (e.g. separation of duties, least privilege, and locking user sessions after periods of inactivity)) and information system components are performed consistent with policies and procedures.
- Using approved and controlled tools, perform and log maintenance and repair of agency assets in a timely manner.
- Perform, log, and approve remote maintenance of agency assets in a manner that prevents unauthorized access.
Associated Artifacts
Protective Technology
Managing technical security solutions to ensure the security and resilience of systems and assets. The management of these solutions should align with related agency policies, procedures, and agreements.
- Ensure audit/log records are determined, documented, implemented, and reviewed in accordance with policy.
- Protect and restrict the use of removable media (e.g. thumb drives, external hard drives, etc.) according to policy.
- Incorporate the principle of least functionality (i.e. configuring an information system or component to provide only the essential functions and services required by an agency. This also applies to limiting information assets to single functions (e.g. a server may be an email server or a web server but not both)) to control access to systems and information assets.
- Protect communications and control networks.
- Mechanisms (e.g., failsafe, load balancing, hot swap) are implemented to achieve resilience requirements in normal and adverse situations.
Associated Artifacts