And does it apply to you?
NIST is the National Institute of Standards and Technology at the U.S. Department of Commerce. The NIST Cybersecurity Framework helps businesses of all sizes better understand, manage, and reduce their cybersecurity risk and protect their networks and data. The Framework is voluntary. It gives your business an outline of best practices to help you decide where to focus your time and money for cybersecurity protection.
You can put the NIST Cybersecurity Framework to work in your business in these five areas: Identify, Protect, Detect, Respond, and Recover.
Make a list of all equipment, software, and data you use, including laptops, smartphones, tablets, and point-of-sale devices.
Create and share a company cybersecurity policy that covers:
Roles and responsibilities for employees, vendors, and anyone else with access to sensitive data.
Steps to take to protect against an attack and limit the damage if one occurs.
Monitor your computers for unauthorized personnel access, devices (like USB drives), and software.
Investigate any unusual activities on your network or by your staff.
Check your network for unauthorized users or connections.
Repair and restore the equipment and parts of your network that were affected.
Keep employees and customers informed of your response and recovery activities.
For more information on the NIST Cybersecurity Framework and resources for small businesses, go to NIST.gov/CyberFramework and NIST.gov/Programs-Projects/Small-Business-Corner-SBC