Skip to main content

Framework Core

The Framework Core consists of common cybersecurity activities and goals. It is comprised of five concurrent and continuous functions representing activities that assist with defining and implementing the cybersecurity program. The functions are Identify, Protect, Detect, Respond, and Recover.

Functions are subdivided into categories representing cybersecurity goals which tie agency and security needs to desired outcomes. Examples of categories include Asset Management, Access Control, and Detection Processes.

Categories are further divided into subcategories that provide specific outcomes of technical and/or management activities. Examples of subcategories include External information systems are catalogued, Data-at-rest is protected, and Notifications from detection systems are investigated.

Recover

The Recover Function describes activities that will help an agency to develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event. These activities will support the timely recovery to normal operations to reduce the impact of a cybersecurity event.

Recovery Planning

RC.RP

Executing and maintaining recovery processes to ensure timely restoration of systems or assets affected by cybersecurity events.

  1. Execute the recovery plan during or after an event.

Improvements

RC.IM

Improving recovery planning and processes by incorporating lessons learned into future activities.

  1. Incorporate lessons learned into recovery plans.
  2. Periodically update recovery strategies.

Communications

RC.CO

Coordinating restoration activities with internal and external parties, such as coordinating centers, Internet Service Providers, owners of attacking systems (i.e. owners of internal or external systems that have become compromised and were subsequently used in the attack of an internal system) , victims (i.e. inform victims of the security breach in a timely manner, what they can do to get more information, and/or need to do to protect themselves), other CSIRTs (i.e. CSIRT stands for computer security incident response team and is an external group of knowledgeable information security professionals able to offer incident response services), and vendors.

  1. Manage public relations.
  2. Address any reputation issues after an event is repaired.
  3. Communicate recovery activities to internal stakeholders and executive and management teams.