Governance
Board direction, roles & responsibilities, security decision-making
Risk Management
Risk management process and understanding threat
Asset Management
Hardware, software, and data asset inventory
Supply Chain
Supplier assurance and secure software development
Service Protection Policies & Processes
Policy development and implementation for essential functions
Identity & Access Control
Authentication, device management, privileged access, and IAM
Data Security
Data classification, encryption in transit and at rest, mobile data, and sanitisation
System Security
Secure by design, configuration, management, and vulnerability management
Resilient Networks & Systems
Resilience preparation, design for resilience, and backups
Staff Awareness & Training
Security culture and role-appropriate training
Security Monitoring
Log coverage, alert generation, incident identification, tools & skills, and threat intelligence
Proactive Security Event Discovery
Detecting system abnormalities and threat hunting
Response & Recovery Planning
Incident response plan, capability, and testing
Lessons Learned
Root cause analysis and feeding improvements back into controls