Govern (GV)
Establish, communicate and monitor the cybersecurity risk-management strategy, expectations and policy.
A risk-based framework structured around six functions - Govern, Identify, Protect, Detect, Respond and Recover.
The NIST CSF is a voluntary, outcome-based framework used worldwide to describe and manage cybersecurity risk. v2.0 introduced the Govern function alongside the original five, bringing board-level accountability, risk management and supply-chain risk into the core. The CSF is one of the permitted cybersecurity frameworks under the Australian CIRMP Rules, and is commonly used as a common language between security teams, auditors and executives.
Any organisation. Often adopted as a governance backbone by Australian regulated entities who need a common structure across ISM, Essential Eight, ISO 27001 and PCI DSS.
Establish, communicate and monitor the cybersecurity risk-management strategy, expectations and policy.
Determine current cybersecurity risk to the organisation, including assets, risks and governance context.
Safeguards to manage cybersecurity risks through access control, awareness and data security.
Find and analyse possible cybersecurity attacks and compromises through continuous monitoring.
Take action regarding a detected cybersecurity incident through containment, communications and analysis.
Restore assets and operations impacted by a cybersecurity incident through recovery planning and improvement.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.