Generated by All in One SEO v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # Cyber Security Center ## Sitemaps - [XML Sitemap](https://cybersecuritycenter.shantuapps.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Home](https://cybersecuritycenter.shantuapps.com/home/) - [GV.RM-01: Do you know the cybersecurity risk objectives for your organization ?](https://cybersecuritycenter.shantuapps.com/nist-csf/gv/gv-rm/gv-oc-05-2/) - GV.RM-01: Risk management objectives are established and agreed to by organizational stakeholders.Implementation ExamplesExample 1: Update near-term and long-term cybersecurity risk management objectives as part of annual strategic planning and when major changes occur.Example 2: Establish measurable objectives for cybersecurity risk management (e.g., manage the quality of user training, ensure adequate risk protection for industrial control - [GV.OC-05: Do you have a record of external resources that could affect your organization ?](https://cybersecuritycenter.shantuapps.com/nist-csf/gv/gv-oc/gv-oc-05/) - GV.OC-05: Outcomes, capabilities, and services that the organization depends on are determined and communicatedImplementation ExamplesExample 1: Create an inventory of the organization’s dependencies on external resources (e.g., facilities, cloud-based hosting providers) and their relationships to organizational assets and business functions. Example 2: Identify and document external dependencies that are potential points of failure for the organization’s - [GV.OC-04: Do you know and share what stakeholders expect from the organization ?](https://cybersecuritycenter.shantuapps.com/nist-csf/gv/gv-oc/gv-oc-04/) - GV.OC-04: Critical objectives, capabilities, and services that stakeholders depend on or expect from the organization are determined and communicated. Implementation ExamplesExample 1: Establish criteria for determining the criticality of capabilities and services as viewed by internal and external stakeholders. Example 2: Determine (e.g., from a business impact analysis) assets and business operations that are vital to achieving - [What is NIST CSF ?](https://cybersecuritycenter.shantuapps.com/nist-csf/nist-csf/) - NIST CSF, or the National Institute of Standards and Technology Cybersecurity Framework, is a set of guidelines, best practices, and standards designed to help organizations manage and improve their cybersecurity risk management processes. The framework provides a common language for understanding, managing, and expressing cybersecurity risks. The NIST CSF is widely used by businesses and - [GV.OC-03: How to manage legal, regulatory, and cybersecurity obligations ?](https://cybersecuritycenter.shantuapps.com/nist-csf/gv/gv-oc/gv-oc-03/) - GV.OC-03: Legal, regulatory, and contractual requirements regarding cybersecurity – including privacy and civil liberties obligations – are understood and managed. Example 1: Determine a process to track and manage legal and regulatory requirements regarding protection of individuals’ information (e.g., Health Insurance Portability and Accountability Act, California Consumer Privacy Act, General Data Protection Regulation). Example 2: - [GV.OC-01: How does your organization should share its mission to identify cybersecurity risks ?](https://cybersecuritycenter.shantuapps.com/nist-csf/gv/gv-oc/gv-oc-01/) - GV.OC-01: The organizational mission is understood and informs cybersecurity risk management.Example 1: Share the organization’s mission (e.g., through vision and mission statements, marketing, and service strategies) to provide a basis for identifying risks that may impede that mission.Source: The NIST Cybersecurity Framework 2.0 Core with Implementation Examples. 54 LikeShare this Post GV.OC-01: The organizational mission is understood and informs cybersecurity risk management.Example 1: Share the organization’s mission (e.g., through vision and mission statements, marketing, and service strategies) to provide a basis for identifying risks that may impede that mission.Source: The NIST Cybersecurity Framework 2.0 Core with Implementation Examples. 54 LikeShare this Post - [GV.OC-02: How to determine stakeholders for cybersecurity risk management ?](https://cybersecuritycenter.shantuapps.com/nist-csf/gv/gv-oc/gv-oc-02/) - GV.OC-02: Internal and external stakeholders are determined, and their needs and expectations regarding cybersecurity risk management are understood. Example 1: Identify relevant internal stakeholders and their cybersecurity-related expectations (e.g., performance and risk expectations of officers, directors, and advisors; cultural expectations of employees) Example 2: Identify relevant external stakeholders and their cybersecurity-related expectations (e.g., privacy expectations - [What are the 10 common security errors that you should avoid ?](https://cybersecuritycenter.shantuapps.com/security-awareness/what-are-the-10-common-security-errors-that-you-should-avoid/) - Weak Passwords: Using weak passwords is a common security error. Examples include using simple passwords like “123456” or using easily guessable information like your birthdate or pet’s name. Weak passwords make it easier for attackers to gain unauthorized access to your accounts.Phishing Attacks: Phishing is a type of cyber attack where attackers trick individuals into - [Password: How to make your password secure?](https://cybersecuritycenter.shantuapps.com/does-and-donts/password-how-to-make-your-password-secure/) - Do: Use long password e.g., “This is most secure password 786″. Choose unique passwords for every websites. Use second factor authentication e.g., Biometric, Email or SMS code. Change password regularly. Don’t: Do not share your password with anyone anymore. Do not reuse any password. 48 LikeShare this Post - [Zero Trust: What is Zero Trust in Internet World?](https://cybersecuritycenter.shantuapps.com/memorable-images/zero-trust-what-is-zero-trust-in-internet-world/) - Zero Trust: Verify every User, Device, API Request, Response etc every time. 38 LikeShare this Post - [Least Privilege: This is what happens when you give Too Much Authorizations to any User?](https://cybersecuritycenter.shantuapps.com/memorable-images/least-privilege-this-is-what-happens-when-you-give-too-much-authorizations-to-any-user/) - Least Privilege: This is what happens when you give Too Much Authorizations to any User. 52 LikeShare this Post - [AI Security: What's wrong with AI?](https://cybersecuritycenter.shantuapps.com/memorable-images/ai-security-whats-wrong-with-ai/) - AI Security: Someone is actively trying to hack AI. 49 LikeShare this Post ## Categories - [Memorable Images](https://cybersecuritycenter.shantuapps.com/category/memorable-images/) - Security is difficult topic in general, our mission is no make is simple to understand using Memorable Images. - [Does and Don'ts](https://cybersecuritycenter.shantuapps.com/category/does-and-donts/) - Simple list of things you should do and avoid in order to stay secure. - [Security Awareness](https://cybersecuritycenter.shantuapps.com/category/security-awareness/) - Needed knowledge of potential threats and risks to personal or organizational security. - [NIST CSF](https://cybersecuritycenter.shantuapps.com/category/nist-csf/) - The National Institute of Standards and Technology (NIST) provides The Cybersecurity Framework (CSF), which is a set of cybersecurity best practices and recommendations. The CSF makes it easier to understand cyber risks and improve your defenses for all types and sized companies. The Framework is based on existing standards, guidelines, and practices for organizations to better manage and reduce cybersecurity risk. In addition, it was designed to foster risk and cybersecurity management communications amongst both internal and external organizational stakeholders. - [Govern (GV)](https://cybersecuritycenter.shantuapps.com/category/nist-csf/gv/) - Establish and monitor the organization’s cybersecurity risk management strategy, expectations, and policy. The GOVERN Function is cross-cutting and provides outcomes to inform how an organization will achieve and prioritize the outcomes of the other five Functions in the context of its mission and stakeholder expectations. Governance activities are critical for incorporating cybersecurity into an organization’s broader enterprise risk management strategy. GOVERN directs an understanding of organizational context; the establishment of cybersecurity strategy and cybersecurity supply chain risk management; roles, responsibilities, and authorities; policies, processes, and procedures; and the oversight of cybersecurity strategy. - [Organizational Context (GV.OC)](https://cybersecuritycenter.shantuapps.com/category/nist-csf/gv/gv-oc/) - The circumstances — mission, stakeholder expectations, and legal, regulatory, and contractual requirements — surrounding the organization’s cybersecurity risk management decisions are understood. - [Risk Management Strategy (GV.RM)](https://cybersecuritycenter.shantuapps.com/category/nist-csf/gv/gv-rm/) - The organization’s priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions. ## Tags - [Password](https://cybersecuritycenter.shantuapps.com/tag/password/) - [Artificial intelligence (AI)](https://cybersecuritycenter.shantuapps.com/tag/artificial-intelligence-ai/) - [Multi Factor Authentication (MFA)](https://cybersecuritycenter.shantuapps.com/tag/multi-factor-authentication-mfa/) - [Authentication](https://cybersecuritycenter.shantuapps.com/tag/authentication/) - [Authorization](https://cybersecuritycenter.shantuapps.com/tag/authorization/) - [Unauthorized Access](https://cybersecuritycenter.shantuapps.com/tag/unauthorized-access/) - [Least Privilege](https://cybersecuritycenter.shantuapps.com/tag/least-privilege/) - [Zero Trust](https://cybersecuritycenter.shantuapps.com/tag/zero-trust/) - [Social Media](https://cybersecuritycenter.shantuapps.com/tag/social-media/)