Setting the objectives for prioritization decision in cybersecurity
| NIST cybersecurity framework cores | Straub and Welke (1998) security action cycle | Objective | Outcome |
|---|---|---|---|
| Identify | Deterrence | Enhancement of organizational understanding of cybersecurity risk to systems, data, people, assets, data, and capability | Passive countermeasures; guidelines, best practices, advisories, reminders |
| Protect | Prevention | Development and implementation of appropriate safeguards | Active countermeasures; enforceable policies, such as password and access control policies |
| Detect | Detection | Development and implementation of appropriate activities to recognize security events | Proactive countermeasures; intrusion detection systems, audits |
| Respond | Remedies | Development and implementation of appropriate activities to take action against security incidents | Reactive countermeasures; Incidence response procedure, disaster recovery |
| Recover | Development and implementation of appropriate activities to take action to maintain resiliency and restore any impaired services |
| NIST cybersecurity framework cores | Objective | Outcome | |
|---|---|---|---|
| Identify | Deterrence | Enhancement of organizational understanding of cybersecurity risk to systems, data, people, assets, data, and capability | Passive countermeasures; guidelines, best practices, advisories, reminders |
| Protect | Prevention | Development and implementation of appropriate safeguards | Active countermeasures; enforceable policies, such as password and access control policies |
| Detect | Detection | Development and implementation of appropriate activities to recognize security events | Proactive countermeasures; intrusion detection systems, audits |
| Respond | Remedies | Development and implementation of appropriate activities to take action against security incidents | Reactive countermeasures; Incidence response procedure, disaster recovery |
| Recover | Development and implementation of appropriate activities to take action to maintain resiliency and restore any impaired services |
Source(s): Table by authors
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.