Cybersecurity Program
What is Cybersecurity Program?
A comprehensive set of policies, procedures, technologies, and personnel dedicated to protecting an organization's digital assets and managing cyber risk.
Terms that appear alongside cybersecurity program
Each of these is named in at least one of the same controls as cybersecurity program. The number is how many controls name both.
- cybersecurity 12 shared controls
- governance 4 shared controls
- information security 3 shared controls
- ciso 2 shared controls
- incident response 2 shared controls
- program governance 2 shared controls
- cisa 2 shared controls
- glba 2 shared controls
Frameworks that govern cybersecurity program
What the standards actually require on cybersecurity program
Requirements naming cybersecurity program across 6 standards, quoted from the control text.
Maintain a written cybersecurity program based on the Risk Assessment that performs the core functions: identify, protect, detect, respond, recover, and fulfill reporting obligations.
§500.2 · Cybersecurity Program →Review the cybersecurity program annually and after material incidents to update controls and priorities.
AWWA-G430-21 · Cybersecurity Program Review →PROGRAM domain. Establish and maintain an enterprise cybersecurity program with governance, sponsorship, resourcing and periodic management review, and an information-sharing capability.
PROGRAM-1 · Establish and Maintain the Cybersecurity Program →Continued airworthiness for cybersecurity addresses the ongoing-maintenance phase of an aircraft's lifecycle. The framework is articulated through: (a) RTCA DO-355A 'Information Security Guidance for Continuing Airworthiness';
FAA-CSA-AC23-XX · Continued Airworthiness for Cybersecurity (AC 23-XX / DO-355A / AC 119-1) →GLBA enforcement status. FTC enforcement actions (recent): (a) DRIZLY (2022) - alcohol delivery; security failures including no Information Security Program + no MFA + no audit + no vendor-management; consent order; (b) TaxSlayer (2017) - tax preparation;
GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement · GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions →Establish an Operational Technology (OT) security program per NIST SP 800-82 Rev 3 Chapter 3 (OT Cybersecurity Program Development) and Chapter 4 (Risk Management).
NISTSP82-1 · OT Security Program Governance, Policy, Roles, and Safety-Security Integration →Questions people ask about cybersecurity program
What is Cybersecurity Program?
Why is Cybersecurity Program important for compliance?
Which compliance frameworks address Cybersecurity Program?
Where can I learn more about Cybersecurity Program?
See how Cybersecurity Program applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.