Cybersecurity Audit, Assessment, and Review
My Team will utilize the NIST Cybersecurity Framework (CSF) 2.0, which guides industry and government agencies, and the NAIC Financial Examiner Handbook.
The framework comprises six core functions: Govern, Identify, Protect, Detect, Respond, and Recover.
1) Govern: The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.
2) Identify: The organization’s current cybersecurity risks are understood.
3) Protect: Safeguards are used to manage the organization’s cybersecurity risks.
4) Detect: Possible cybersecurity attacks and compromises are found and analyzed.
5) Respond: Actions regarding a detected cybersecurity incident are taken.
6) Recover: Assets and operations affected by a cybersecurity incident are restored.