02 - Govern and Identify Functions
govern-and-identify-functions', 'appsec', 'security', 'compliance']
02 - Govern and Identify Functions
GOVERN (GV)
The new GOVERN function emphasizes that cybersecurity risk is a board-level issue, integrating it with the organization's broader enterprise risk management strategy.
Key Categories
- Organizational Context (GV.OC): Understanding the business mission, stakeholder expectations, and legal/regulatory requirements.
- Risk Management Strategy (GV.RM): Establishing the organization's risk tolerance and risk management processes.
- Roles, Responsibilities, and Authorities (GV.RR): Defining who is accountable for cybersecurity outcomes.
- Policy (GV.PO): Establishing and communicating organizational cybersecurity policy.
Strategic Implementation
- Establish a Cybersecurity Steering Committee.
- Integrate cyber risk into the Enterprise Risk Register.
IDENTIFY (ID)
Understanding what you have is the prerequisite to protecting it. The Identify function focuses on discovering and assessing assets, vulnerabilities, and third-party risks.
Asset Management (ID.AM)
You cannot secure what you cannot see.
- Hardware & Software Inventories: Maintain automated CMDBs (Configuration Management Databases).
- Data Mapping: Understand data flows, classification (e.g., PII, PHI), and storage locations.
Risk Assessment (ID.RA)
- Identify internal and external threats.
- Perform continuous vulnerability scanning.
- Quantify risks based on likelihood and impact.
Cybersecurity Supply Chain Risk Management (C-SCRM) (ID.SC)
Third-party risk is one of the largest attack vectors.
- Implement vendor risk assessments.
- Require software bills of materials (SBOMs) from suppliers.
- Monitor open-source dependencies.
[!TIP] Automate asset discovery using cloud-native tools like AWS Systems Manager or Azure Resource Graph to ensure your ID.AM outcomes are accurate and continuously updated.