Table 1

Setting the objectives for prioritization decision in cybersecurity

NIST cybersecurity framework coresStraub and Welke (1998) security action cycleObjectiveOutcome
IdentifyDeterrenceEnhancement of organizational understanding of cybersecurity risk to systems, data, people, assets, data, and capabilityPassive countermeasures; guidelines, best practices, advisories, reminders
ProtectPreventionDevelopment and implementation of appropriate safeguardsActive countermeasures; enforceable policies, such as password and access control policies
DetectDetectionDevelopment and implementation of appropriate activities to recognize security eventsProactive countermeasures; intrusion detection systems, audits
RespondRemediesDevelopment and implementation of appropriate activities to take action against security incidentsReactive countermeasures; Incidence response procedure, disaster recovery
RecoverDevelopment and implementation of appropriate activities to take action to maintain resiliency and restore any impaired services

Source(s): Table by authors

or Create an Account

Close Modal
Close Modal