5.12 Cybersecurity (detail)
收藏资源简介:
The National Institute of Standards and Technology (NIST) provides a Cybersecurity Framework (CSF) for benchmarking and measuring the maturity level of cybersecurity programs across all industries. The City uses this framework and toolset to measure and report on its internal cybersecurity program. The foundation for this measure is the Framework Core, a set of cybersecurity activities, desired outcomes, and applicable references that are common across critical infrastructure/industry sectors. These activities come from the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) published standard, along with the information security and customer privacy controls it references (NIST 800 Series Special Publications). The Framework Core presents industry standards, guidelines, and practices in a manner that allows for communication of cybersecurity activities and outcomes across the organization from the executive level to the implementation/operations level. The Framework Core consists of five concurrent and continuous functions: identify, protect, detect, respond, and recover. When considered together, these functions provide a high-level, strategic view of the lifecycle of an organization’s management of cybersecurity risk. The Framework Core identifies underlying key categories and subcategories for each function, and matches them with example references, such as existing standards, guidelines, and practices for each subcategory. This page provides data for the Cybersecurity performance measure. Cybersecurity Framework (CSF) scores by each CSF category per fiscal year quarter (Performance Measure 5.12) The performance measure dashboard is available at 5.12 Cybersecurity. Additional Information Source: Maturity assessment /https://www.nist.gov/topics/cybersecurity Contact: Scott Campbell Contact E-Mail: Scott_Campbell@tempe.gov Data Source Type: Excel Preparation Method: The data is a summary of a detailed and confidential analysis of the city's cybersecurity program. Maturity scores of subcategories within NIST CFS are combined, averaged, and rolled up to a summary score for each major category. Publish Frequency: Annual Publish Method: Manual Data Dictionary
美国国家标准与技术研究院(National Institute of Standards and Technology,NIST)推出了网络安全框架(Cybersecurity Framework,CSF),用于跨全行业开展网络安全项目的基准测试与成熟度评估。该市采用该框架及配套工具集,对内部网络安全项目进行测评并形成汇报材料。 该测评的核心基础为框架核心(Framework Core),其包含一套适用于关键基础设施/行业领域的通用网络安全活动、预期成果与适用参考依据。此类活动源自美国国家标准与技术研究院(NIST)发布的《网络安全框架》标准,以及该标准引用的信息安全与客户隐私控制措施(NIST 800系列专项出版物)。 框架核心以可实现组织内部从高管层到执行运维层全层级沟通网络安全活动与成果的形式,整合了行业标准、指南与实践方法。框架核心包含五项并行且持续的功能:识别(identify)、保护(protect)、检测(detect)、响应(respond)与恢复(recover)。 将这些功能综合考量后,可形成组织网络安全风险管理生命周期的高层战略视图。框架核心为每项功能明确了核心类别与子类别,并为每个子类别匹配了各类参考示例,包括现有标准、指南与实践方法等。 本页面提供网络安全性能测评相关数据,即按财年季度划分的、各网络安全框架(CSF)类别对应的得分(性能测评指标5.12)。 该性能测评仪表盘可在"5.12 网络安全"板块查询获取。 附加信息: 来源:成熟度评估 /https://www.nist.gov/topics/cybersecurity 联系人:Scott Campbell 联系邮箱:Scott_Campbell@tempe.gov 数据源类型:Excel 数据制备方法:本数据为该市网络安全项目详细保密分析的汇总结果。将NIST CSF各子类别下的成熟度得分进行合并、平均,并汇总至各主要类别对应的综合得分。 发布频率:年度 发布方式:手动 数据字典



