ISMS Compliance
CyFun BasicProtect

Protect

Safeguards to mitigate cybersecurity risk

Overview

The Protect function focuses on developing and implementing safeguards necessary to mitigate or contain a cyber risk.

Categories

Identity Management & Access Control (PR.AC) — 5 controls

ControlDescriptionKey MeasureStatusMaturity
PR.AC-1Identities and credentials managedYesPartialL2
PR.AC-2Physical access managedNoPartialL1
PR.AC-3Remote access managedYesPartialL2
PR.AC-4Access permissions managedYesPartialL2
PR.AC-5Network integrity protectedYesImplementedL2

Awareness & Training (PR.AT) — 1 control

ControlDescriptionKey MeasureStatusMaturity
PR.AT-1Users informed and trainedYesPlannedL1

Data Security (PR.DS) — 4 controls

ControlDescriptionKey MeasureStatusMaturity
PR.DS-1Data-at-rest protectedNoImplementedL2
PR.DS-2Data-in-transit protectedNoImplementedL2
PR.DS-3Asset disposal managedNoPartialL1
PR.DS-7Dev/test separate from productionNoImplementedL2

Information Protection (PR.IP) — 2 controls

ControlDescriptionKey MeasureStatusMaturity
PR.IP-4Backups conducted and testedYesImplementedL2
PR.IP-11HR cybersecurity practicesNoPlannedL1

Maintenance (PR.MA) — 1 control

ControlDescriptionKey MeasureStatusMaturity
PR.MA-1Maintenance performed and loggedYesPartialL2

Protective Technology (PR.PT) — 2 controls

ControlDescriptionKey MeasureStatusMaturity
PR.PT-1Audit/log records managedYesPartialL2
PR.PT-4Communications networks protectedNoPartialL2

On this page