×

Functions of Cyber Security

Let’s learn about the Cybersecurity Framework's five Functions that are the key pillars of wholistic and successful cyber security programs. These five functions result from the highest level of abstraction included in the framework and act as its backbone. Here we learn about the value of functions within the framework, and here all the presented information builds upon the material introduced in the Components of the Framework module. Description of the five functions in the function core:

  • Identify
  • Protect
  • Detect
  • Respond
  • Recover

Identify

Identifying function in the framework helps an organization understand the system of managing the cyber security risk to people, system, assets, capabilities, and data. This function defines the risks on which an organization must focus and prioritize its efforts and business needs with its risk management strategy. It identifies the resources that support the critical functions in the business context.

Tasks performed by identification function in an organization:-

  • This function is utilized to identify cyber security policies in an organization regarding the need for legal rules and regulations regularly in an organization.
  • It establishes the basic structure of an asset management program within an organization by identifying all the software and physical assets.
  • It identifies the business environment supported by an organization that includes the place of an organization in critical infrastructure and its role in the supply chain.
  • It identifies organization risk assessment through risk-responsive activities.
  • Also, identify threats to internal and external organizational resources and asset vulnerabilities.
  • Risk management strategies are also identified, including establishing risk tolerances.
  • Identification of supply chain risk management in an organization that include
    -priorities
    -Risk tolerance
    -constraints
    -assumptions used to support risk decision

Protect

The Protect Function in the cyber security framework provides an outline of appropriate safeguards to ensure the delivery of critical infrastructure services. It provides a limit to cyber security events and also contains its impact.

Following are the functions of the protect function:

  • Access control and identity management are protected in an organization that includes remote and physical access.
  • Protection provides awareness and training to the staff that empowers them, and this training includes privileged user and role-based training.
  • Organizational resources are protected through remote maintenance activities.
  • Maintaining and managing the protection of assets and information systems implements information protection processes and procedure
  • It manages protective technology consistent with organizational procedures, policies, and agreements

to ensure the resilience and security of assets and systems.

  • Protect integrity, confidentiality, and availability of information within an organization is protected by establishing data security protection consistent with the company's risk strategy.

Detect

The Detect Function of the cyber security framework defines the activities that timely detect the occurrence of a cybersecurity event.

The following functions are performed by detect function:

  • This function detects the events and anomalies and their potential impact.
  • It monitors cyber security events by implementing continuous security monitoring capabilities to verify the effectiveness of protective measures (physical and network activities).
  • For providing awareness of strange events, it maintains the detection process.

Respond

The Respond Function is designed in the framework to take appropriate actions by appropriate activities during a detected Cybersecurity incident. Its record and response to the impact of a potential Cybersecurity incident.

The functions of the response function are as follows:

  • Respond function implements the response planning process during and after an incident.
  • Respond function manages the communication during and after an event with external and internal stakeholders, law enforcement, etc.
  • Prevention of event expansion and solution to an incident is provided by performing mitigation activities.
  • An analysis is conducted to determine the impact of incidents and effective responses. It also supports recovery activities, including forensic analysis.
  • The organization's improvements incorporate lessons learned from previous and current response/ detection activities.

Recover

The Recover Function in the cyber security framework is used to reduce the impact of a cyber-security incident by timely recovering the normal operations and identifying appropriate activities to maintain plans for resilience. This function also restores the diminished services and capabilities because of a cyber-security incident.

Functions performed by the recover function are as follows:

  • The recover function implements a recovery planning procedure and process in an organization to restore assets and systems affected by cyber security incidents.
  • It makes to review the existing strategies and apply some improvements based on learned lessons.
  • After any cyber security incident, all the internal and external communications are synchronized for the recovery phase.

Related Topics

Types of security policies

Policies act as a protection field for the business, organization, and individual users to allow them and protect their rights. Security policies are meant to provide security for the technology...

9 minutes read.

Reverse engineering in cyber security

Introduction Most probably, everyone has heard about engineering as "an act or work of creation to simplify day-to-day work," and a person who does it is called an engineer who thinks...

13 minutes read.

Botnet in cyber security

Introduction Since people started using computer systems, they have become victims of cyber-attack. The reason and medium of cyber-attack vary from attack to attack like phishing attack uses email, DDOS attack...

14 minutes read.

Cyber security frameworks

Introduction "Frameworks are defined as documents that describe guidelines, rules and regulations, standards and best practices.” A real-world framework is defined as "a structure that supports a building or other large objects." Cyber...

5 minutes read.

Types of cyber security vulnerabilities

The user must know all the vulnerabilities to understand cyber security vulnerabilities and build a vulnerability management program. Here are some of the common types of cyber security vulnerabilities: System misconfigurationsThe...

8 minutes read.

Cyber Security Vulnerability

Introduction Cyber security is the security provided to the internet to protect and secure valuable information. Security is needed against the system's threats, risks, exploits, and vulnerabilities. Here we goanna understand what...

6 minutes read.

Penetration Testing

Introduction When software or a system is designed, it is not fully secured as human creates it, and human is a mannequin of mistakes. In the cyber industry, no device, system...

7 minutes read.

Difference between Network Security and Cyber Security

Introduction While learning about cyber security, usually terms like information security and network security come to have a familiar ring. Still, they are different from each other on numerous factors.  The technology...

3 minutes read.

Importance of cyber security in education sector

Education is the necessity of human beings and the most prominent and growing industry in businesses and commercial establishments everywhere. Educational institutes are increasingly fast, and with the merger of...

6 minutes read.

Eavesdropping attack in cyber security

Introduction Eavesdropping is a technique of finding someone's conversation details for personal benefit. When an ongoing communication between two people is interrupted, or a third person tries to listen to that...

6 minutes read.

Cyber Security Standards

Top Cyber Security Frameworks/ Standards Experts of cyber security safeguard the internet against different cyber-crimes by making different rules and protocols to follow by the user. Still, these rules and regulations...

10 minutes read.

Vulnerability management

A process of managing the vulnerabilities in the system is called vulnerability management. Vulnerability management is the cyclic process of identifying, evaluating, reporting and treating the system vulnerabilities and IT...

6 minutes read.

Canary in Cyber security

Introduction Cyber security is meant to provide security to the cyber/ internet/ IT world. It aims to secure the organization against cyber-attacks by using various security products. Not just data, applications...

5 minutes read.

ISO certification

Why do a company/organization/ business need certification? Certification is not a paper. It is a declaration and insurance of a certain thing, status, or event that is true. It's a written...

8 minutes read.

Elements of cyber security

"Cyber security" encompasses many things, including shielding web-associated systems like software, hardware, and information from cyber dangers. A business can't use a single tactic to secure its technology infrastructure. Therefore...

6 minutes read.

Cyber Security job qualifications

Requirements and Responsibilities for Cybersecurity Entry-Level Jobs The thread to the network and computer are increasing rapidly every day with the internet and technology. Cyber attackers compromise large companies' confidential information...

3 minutes read.

NIST- National Institute of Standard and technology

This security standard or framework was founded in 1901 and designed to protect data. It consists of several guidelines that help companies protect government data and establish standards and technology...

4 minutes read.

Characteristics of cyber security policies

Security policies have the motive to protect the right of employees, customers, partners, vendors, and the integrity of information from being misused, disclosed of information, or national, international, or accidental...

6 minutes read.

Ethical Hacking

Introduction Rather for a long, we have been living in a digital era, but after COVID 2019, almost everything has become online & connected to the internet. It makes life easier,...

11 minutes read.

Types of Cyber Security

Cyber security is designed to provide security to cyber users, including the integrity of the interconnected system, software, hardware, and data from cyber-attacks. Everything personal or professional rely on computers and...

6 minutes read.