February 2025
Beginner to intermediate
94 pages
1h 27m
English
The CSF is a risk-based cybersecurity framework. It does not expect organizations to invest in defenses they do not need, or to have sophisticated and expensive defenses for low-level risks.
The core also respects general risk management processes, which are:
1. Identifying risks
2. Determining the level of risk in terms of impact and likelihood/frequency
3. Comparing those risks to the organization’s risk appetite (risk tolerance)
4. Determining an appropriate response to the level and type of risk
There are several methodologies an organization can apply in assessing and managing its risks, which generally fall into two schools:
1. Asset-based assessments: An asset-based risk assessment examines the ...