Skip to main content
Language Translation
  Close Menu

Protect is the second function of NIST. The Protect function builds on the work accomplished in Identify. In the first function, Identify, we dealt with how to find, focus on, and prioritize your assets. The next question that comes to mind is now that we have identified all the assets, and rated how critical they are to our organization, how do we protect all of it?

If “an ounce of prevention is worth a pound of cure”, then this is the prevention part of your cybersecurity work. Yet, it can only be accomplished if you have first accomplished Identify. The questions in this category will help a business understand to what level they are protecting all the assets that are involved in their business. There are going to be resources along the way to help you “level up” your cybersecurity scores. There are going to be tips and checklists to help determine what to do next. Protect not only deals with protecting the hardware and the software involved, it also deals with the protection of data, physical assets, and personnel an organization or business deals with, so that it can better protect itself from cyber-attacks.

The questions in the Protect function emphasize the need to control access to all assets involved in an organization. They will emphasize the need to have policies, procedures, training, and technologies in place so that organizations better protect themselves.

Low – Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Low to Medium will be to 1) Keep all of your operating systems and software up to date by setting up automatic patching/updates to install either daily or at multiple points during the week,2) Educate both yourself and employees on cybersecurity awareness so your organization doesn’t fall prey to cyber criminal’s attempts because many attacks require individuals to take actions such as visit a malicious website, click on a link in a phishing email, etc…3) Create layers of defenses that will secure data wherever it resides such as 2FA/MFA (two-factor/multi-factor authentication), restrict all logins to the least amount of access each needs and no more, firewalls, anti-malware and ransomware protection, etc…

The following are additional resources to help you level up your game from Low to Medium:

Medium - Based on your responses to the scorecard, easy ways to “Level Up” your cybersecurity score from Medium to High will be to 1) Ensure your organization is using a risk-based Security strategy that will secure the organization based upon the business needs, not the “cyber-attack of the day”, 2) Use a free or paid Security awareness service that will provide regular monthly security training to move the culture to “Security First”, 3) Utilize layers of cybersecurity that will protect data no matter where it resides such as both on-site and off-site “disconnected” backups, advanced endpoint protections, Role Based Access Control, separation of duties, and processes such as blocking access to all Cloud storage services except for the agreed upon secure provider, and 4) Regularly scan all of the organization’s systems, software, services & smart devices (Internet of Things) for vulnerabilities and have a plan to fix what is found on a regular basis.

The following are additional resources to help you level up your game from Medium to High:

High - Based on your responses to the scorecard, ways to continue to “Level Up” your cybersecurity score and keep it at High is to 1) Regularly communicate with top leadership to ensure your priorities are properly aligned with the business risks and continual improvements are being employed at the proper speed, 2) Your security awareness program includes training for all roles and the associated responsibilities such as vendors, customers, privileged users, executives, physical security, and cybersecurity, 3) Securing both the organizational and customer data, so protect data in transit, data at rest, protect from unauthorized access, unavailability, and personal devices your employees use for business and test/practice regular data recovery plans, 3) Your identity and access solution(s) are centralized and every system, both physical and digital, are being centrally logged, orphaned accounts are automatically detected and removed, and logs are audited regularly, and 4) Regular automated vulnerability scanning is occurring that utilizes a risk-rating system and patching of both operating systems and software is automated as well.

The following are additional resources to help you level up your game and keep it at High: