The NIST Cybersecurity Framework includes different elements called Core function, categories, subcategories and informative references. The reason for this division is that each element provides an increasing level of detail to help explain and manage the specific security requirement. For example, consider the relationship (sometimes called a mapping) starting from the core function of Protect, to the category of Data Security (PR.DS) and then the subcategory PR.DS-1 which specifies that Data-at-rest is protected. An example of a product or service that implements this requirement would be whole disk encryption such as provided by File Vault in OSX or BitLocker in Windows.
Describe two other examples of this Core/Category/Subcategory mapping, and as part of your description, include information on a product or service that implements (or supports) the requirement. Your examples should be chosen from two different core functions.

 

 

This question has been answered.

Get Answer