NIST Definitions
The National Institute of Standards and Technology (NIST) developed the NIST Cybersecurity Framework (CSF), a set of guidelines, best practices, and standards to help organizations manage and reduce cybersecurity risks. The CSF was designed with flexibility in mind to be applicable to organizations of all sizes, sectors, and maturity levels.
| Service | Definition |
|---|---|
| Security Awareness Training | First line of defense. Educates employees on recognizing, preventing, and responding to cybersecurity threats to protect an organization's assets and data. |
| EDR Endpoint AntiVirus | Combines AI driven threat detection and automated responses to protect endpoints from malicious activity. |
| Mail Filtration | Scans and filters incoming and outgoing emails to block inappropriate or malicious content, such as spam, phishing attempts, and malware, before they reach the recipient's inbox. |
| DNS Filtration | Monitors and blocks access to malicious websites by preventing users from reaching harmful or inappropriate content. Encrypts data sent/received through the internet. |
| Password Management | Tool that simplifies the management and use of strong, unique passwords. |
| SaaS Backup | Securely backs up data stored in your M365 accounts to protect against data loss, corruption, or accidental deletion. |
| Updates/Maintenance | Regularly applies software and security updates to operating systems, applications, and drivers to ensure optimal performance, security, and protection against vulnerabilities. |
| Disk encryption | Encrypts the data on a disk, preventing unauthorized access to sensitive information. |
| Conditional Access Controls | Enforce access policies based on specific conditions, such as user location, device health, or authentication strength, to ensure that only authorized users can access sensitive data. |
| Mobile Device Management (MDM) | Enables organizations to manage, monitor, and secure employees' mobile devices (laptops, tablets, phones) by enforcing policies, controlling access, and ensuring data protection. |
| Managed Security Operations Center (SOC) | Service that provides continuous monitoring, detection, analysis, and response to cybersecurity threats, in real-time. |
| Vulnerability Scans | Continuous, automated assessments that identify security weaknesses in systems, networks, or applications to help organizations mitigate potential risks and prevent cyberattacks. |
| MFA/Identity Security | Manage access to sensitive information by multi-factor authentication, identity governance, and secure credential management to prevent unauthorized access. |
| Bi-annual Technology Business Review (TBR) | Assessment or evaluation of an organization's technology strategies, systems, and performance to ensure alignment with business goals and identify areas for improvement or innovation. |
| vCIO Services (Virtual Chief Information Officer) | Provide organizations with strategic IT leadership and guidance, helping them align technology with business goals, manage IT budgets, and implement effective IT initiatives without the need for a full-time CIO. |