There are 7 steps in this [[National Institute of Standards and Technology|NIST]] [[Security Frameworks|framework]]:
- **Prepare** - Activities that are necessary to manage security and privacy risks before a breach occurs. Analysts monitor for risks and identify controls that can be used to reduce those risks
- **Categorise** - Used to develop risk management processes and tasks. Security professionals then use those processes and develop tasks by thinking about how the confidentiality, integrity, and availability of systems and information can be impacted by risk
- **Select** - Choose, customise, and capture documentation of the controls that protect an organisation. An example of the select step would be keeping a playbook up-to-date or helping to manage other documentation that allows you and your team to address issues more efficiently.
- **Implement** - Implement security and privacy plans for the organisation. Having good plans in place is essential for minimising the impact of ongoing security risks.
- **Assess** - Determine if established controls are implemented correctly. An organisation always wants to operate as efficiently as possible. So it's essential to take the time to analyse whether the implemented protocols, procedures, and controls that are in place are meeting organisational needs.
- **Authorise** - Being accountable for the security and privacy risks that may exist in an organisation. The authorisation step could involve generating reports, developing plans of action, and establishing project milestones that are aligned to your organisation's security goals.
- **Monitor** - Be aware of how systems are operating. Assessing and maintaining technical operations are tasks that analysts complete daily. Part of maintaining a low level of risk for an organisation is knowing how the current systems support the organisation's security goals.
[[Risk Management]]