Jason Edwards
Framework: The NIST Cybersecurity Framework (CSF)
**Framework** is your go-to podcast for mastering the **NIST Cybersecurity Framework (CSF)**—the foundational model for building and improving organizational security programs. This series breaks down every function, category, and subcategory within the CSF, helping professionals, educators, and leaders understand how to apply the framework in real-world environments. Each episode delivers clear, practical explanations that connect framework concepts to daily security operations, governance, and risk management practices. Whether you’re new to cybersecurity or refining an established program,...
Autor
Jason Edwards
Kategorie
Podcast-Website
Neueste Folge
14. Okt 2025
Wo hören?
Podcasts in der App Replaio Radio Bald verfügbarPodcasts kommen bald in die App. Installiere sie jetzt und erlebe als Erster einen ganz neuen Blick auf Podcasts
Folgen
DE.AE-04 - Estimating the Impact of Adverse Events 25.02.2025 19:31
DE.AE-04 estimates the impact and scope of adverse events to gauge their potential harm, using tools like SIEMs or manual analysis to assess affected assets and severity. This process refines initial estimates through review, ensuring a clear understanding of consequences like data loss or downtime. It informs prioritization of response efforts. This subcategory aligns analysis with risk managemen...
DE.AE-03 - Correlating Data from Multiple Sources 25.02.2025 19:09
DE.AE-03 correlates information from diverse sources—like logs, sensors, and threat intelligence—to build a unified picture of potential adverse events. This involves consolidating log data into centralized servers and using event correlation tools (e.g., SIEM) to identify patterns or connections. It enhances detection by linking disparate clues into coherent threats. This subcategory strengthens...
DE.AE-02 - Analyzing Adverse Events for Insights 25.02.2025 18:44
DE.AE-02 focuses on analyzing potentially adverse events to understand their nature, using tools like SIEM systems to examine log events for malicious or suspicious activity. This includes leveraging cyber threat intelligence to characterize threat actors, tactics, and indicators of compromise, supplemented by manual reviews where automation falls short. It turns raw detections into actionable ins...
DE.CM-09 - Detecting Threats Across Technology Stacks 25.02.2025 20:08
DE.CM-09 involves monitoring hardware, software, runtime environments, and associated data to detect adverse events like malware, phishing, or tampering. This includes tracking authentication attempts, configuration changes, and endpoint health to identify risks such as unauthorized software or credential attacks. It ensures a deep, system-level view of potential threats. This subcategory enhances...
DE.CM-06 - Monitoring External Service Providers 25.02.2025 19:10
DE.CM-06 requires monitoring the activities and services of external providers—like cloud platforms or ISPs—to detect adverse events that could impact the organization. This includes tracking remote administration or onsite maintenance by third parties for deviations from expected behavior. It ensures external dependencies don’t become blind spots. This subcategory mitigates risks from outsourced...
DE.CM-03 - Tracking Personnel and Technology Usage 25.02.2025 18:37
DE.CM-03 monitors personnel activity and technology usage to identify potentially adverse events, such as insider threats or policy violations, using tools like behavior analytics and access logs. This includes tracking unusual access patterns or interactions with deception technologies, like honeypot accounts, to detect malicious intent. It focuses on the human element of security risks. This sub...
DE.CM-02 - Watching the Physical Environment for Threats 25.02.2025 18:30
DE.CM-02 involves monitoring the physical environment housing technology assets to detect adverse events, such as unauthorized access or tampering with controls like locks and alarms. This includes reviewing logs from badge readers and visitor records for unusual patterns, supplemented by tools like cameras and security guards. It protects the physical layer of cybersecurity. This subcategory ensu...
DE.CM-01 - Monitoring Networks for Adverse Events 25.02.2025 18:06
DE.CM-01 focuses on continuously monitoring networks and network services, such as DNS and BGP, to detect potentially adverse events like unauthorized connections or traffic anomalies. This involves comparing real-time network flows against established baselines to identify deviations that could signal a security threat. It ensures visibility into network activity to catch issues early. This subca...
PR.IR-04 - Maintaining Resource Capacity for Availability 25.02.2025 18:03
PR.IR-04 maintains sufficient resource capacity—storage, compute, power, and bandwidth—to ensure system availability, monitoring usage and forecasting needs. This proactive scaling prevents performance bottlenecks or failures that could disrupt operations. It aligns capacity planning with risk and resilience objectives. This subcategory supports uninterrupted access to critical systems by anticipa...
PR.IR-03 - Building Resilient Technology Systems 25.02.2025 20:06
PR.IR-03 implements mechanisms like redundant storage, load balancing, and high-availability components to meet resilience requirements under both normal and adverse conditions. This avoids single points of failure, ensuring systems remain operational during disruptions. It supports continuous service delivery aligned with risk goals. This subcategory enhances infrastructure reliability by distrib...
PR.IR-02 - Shielding Assets from Environmental Threats 25.02.2025 19:59
PR.IR-02 safeguards technology assets from environmental threats like flooding, fire, or excessive heat, using physical protections and resilient infrastructure. This includes requiring service providers to mitigate such risks in their operations, ensuring consistent protection across owned and outsourced systems. It maintains asset availability under adverse conditions. This subcategory aligns en...
PR.IR-01 - Protecting Against Unauthorized Network Access 25.02.2025 18:45
PR.IR-01 protects networks and environments from unauthorized logical access by segmenting them based on trust boundaries (e.g., IT, IoT, OT) and restricting communications to essentials. This includes zero trust architectures and endpoint health checks to limit access to verified devices only. It prevents intruders from moving freely within systems. This subcategory enhances resilience by isolati...
PR.PS-06 - Securing the Software Development Process 25.02.2025 17:38
PR.PS-06 integrates secure development practices into the software lifecycle, protecting code from tampering and ensuring releases have minimal vulnerabilities. This includes monitoring performance to maintain security in production and securely disposing of software when obsolete. It ensures organization-developed software meets high security standards. This subcategory enhances software integrit...
PR.PS-05 - Preventing Unauthorized Software Use 25.02.2025 17:03
PR.PS-05 prevents the installation and execution of unauthorized software by restricting platforms to approved applications and verifying software integrity before use. This includes using approved DNS services to block malicious domains and limiting execution to permitted products where risk warrants. It reduces the risk of malware or unvetted software compromising systems. This subcategory stren...
PR.PS-04 - Enabling Continuous Monitoring with Logs 25.02.2025 17:22
PR.PS-04 requires configuring systems, applications, and services to generate log records that support continuous monitoring, ensuring visibility into activities and events. This includes securely sharing logs with centralized infrastructure for analysis, tailored to needs like zero trust architectures. It provides the data needed to detect and respond to threats. This subcategory enhances securit...
PR.PS-03 - Managing Hardware Lifecycles 25.02.2025 16:24
PR.PS-03 ensures hardware is maintained, replaced, or securely removed based on its security capabilities and risk profile, such as replacing devices unable to support modern software protections. This includes planning for end-of-life support and disposing of hardware responsibly to prevent data leakage. It keeps the physical infrastructure secure and functional. This subcategory reduces risks by...
PR.PS-02 - Maintaining Software Security 25.02.2025 16:31
PR.PS-02 focuses on maintaining, replacing, or removing software based on risk, including timely patching, updating container images, and phasing out end-of-life versions. This ensures software remains supported and secure, reducing vulnerabilities from outdated or unauthorized applications. It includes plans for obsolescence to manage lifecycle risks. This subcategory strengthens resilience by un...
PR.PS-01 - Implementing Configuration Management 25.02.2025 17:44
PR.PS-01 establishes and applies configuration management practices to maintain secure baselines for hardware, software, and services, adhering to the principle of least functionality. This involves testing and deploying hardened configurations while reviewing defaults for potential risks during installations or upgrades. It ensures platforms are set up to minimize vulnerabilities. This subcategor...
PR.DS-11 - Ensuring Reliable Data Backups 25.02.2025 25:53
PR.DS-11 ensures that data backups are regularly created, securely stored, and tested to maintain availability and integrity for recovery purposes. This includes near-real-time backups for critical data, offline storage to protect against incidents, and annual testing to verify restorability. It supports resilience by enabling rapid restoration after disruptions. This subcategory mitigates risks l...
PR.DS-10 - Safeguarding Data-in-Use 25.02.2025 18:36
PR.DS-10 protects data-in-use—actively processed in memory or applications—by removing it when no longer needed and isolating it from other users or processes on the same platform. This prevents unauthorized access or leakage during active operations, a critical concern for sensitive computations. It ensures data remains secure while being manipulated. This subcategory enhances runtime security by...
PR.DS-02 - Securing Data-in-Transit 25.02.2025 18:17
PR.DS-02 secures data-in-transit—moving across networks or communications—using encryption and integrity checks like digital signatures to prevent interception or alteration. This includes blocking or encrypting sensitive outbound emails and restricting access to personal communication tools on organizational systems. It ensures data remains protected during transmission. This subcategory mitigate...
PR.DS-01 - Protecting Data-at-Rest 25.02.2025 18:06
PR.DS-01 focuses on securing data-at-rest—stored in files, databases, or devices—using encryption, digital signatures, and physical controls to protect confidentiality, integrity, and availability. This includes full disk encryption for endpoints and restricting removable media to prevent unauthorized access or exfiltration. It safeguards data when it’s not actively being used. This subcategory en...
PR.AT-02 - Preparing Specialists for Cybersecurity Roles 25.02.2025 19:52
PR.AT-02 targets individuals in specialized roles—like cybersecurity staff, finance personnel, or senior leaders—with tailored training to address role-specific risks. This advanced education ensures they can manage complex tasks, such as handling critical data or responding to incidents, with security in mind. It extends beyond general awareness to meet unique job demands. This subcategory enhanc...
PR.AT-01 - Training Personnel on Cybersecurity Basics 25.02.2025 17:48
PR.AT-01 ensures that all personnel—employees, contractors, and partners—receive basic cybersecurity awareness and training to handle tasks securely. This includes recognizing phishing attempts, adhering to acceptable use policies, and practicing cyber hygiene like password management. It builds a foundational layer of human-centric security across the organization. This subcategory reinforces a s...
PR.AA-06 - Controlling Physical Access to Assets 25.02.2025 18:48
PR.AA-06 addresses the management and monitoring of physical access to assets, using controls like security guards, cameras, and locked entries to restrict entry based on risk levels. High-risk areas receive enhanced protections, while guests or vendors are escorted to limit exposure. It prevents unauthorized physical interactions that could compromise systems or data. This subcategory aligns phys...
Ähnliche Podcasts
Replaio ist kein Herausgeber von Podcasts; die Namen der Sendungen, Cover und Audioinhalte gehören ihren Autoren und werden über öffentliche RSS-Feeds verbreitet