ID.IM-02_idim-02
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
Vulnerabilities in assets are identified, validated, and recorded
Cyber threat intelligence is received from information sharing forums and sources
Internal and external threats to the organization are identified and recorded
Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization
Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
Processes for receiving, analyzing, and responding to vulnerability disclosures are established
The authenticity and integrity of hardware and software are assessed prior to acquisition and use