Expel-self-scoring-tool-for-NIST-CSF-1803-withCCBYSA.xlsx

README

Self-scoring: Rank yourself on a score of 0 to 5
About Expel
Expel provides transparent managed security. It’s the antidote for companies trapped in failed relationships with their managed security service provider (MSSP) and those looking to avoid the frustration of working with one in the first place. To learn more, check us out at https://www.expel.io
License
The Expel CSF self-scoring tool for the NIST CSF is licensed under Creative Commons Attribution (CC-BY-SA). See https://creativecommons.org/licenses/by/4.0/ for more details. Ultimately, we want people to use, modify, and generally make a CSF assessment process that helps make organizations more secure and better able to manage cyber risk. The Attribution license is the most open of the Creative Common Licenses and we hope that others will feel free to build on the work here.

The Expel self-scoring tool for NIST CSF version 1.0 How to use this spreadsheet At the bottom of this spreadsheet you'll see tabs for seven other sheets in addition to this one. Summary When you're done inputing all your data, this sheet will contain the roll-up graph that shows where you are today and where you'd like to be from a CSF perspective. You don't need to edit anything here. This is a useful chart for communicating with business stakeholders and the board. Identify/Protect/Detect/Recover/Respond These sheets contain all the categories and subcategories in the corresponding functional area. We provide more detailed guidance on how to fill these out in our blog post (https://expel.io/blog/get-started-with-the-nist-csf/). Fill in all the numbers that are shaded in light green. The roll up data at the top will update automatically as you fill in the data below. The top of each page has graphs that correspond to your as-is and to-be states for each functional area. Scratch Don't touch this one. It's just a place where some intermediate calculations are being made. If you have any comments on this workbook or find any bugs, please let us know at [email protected] Additional resources: Blog post A quick tour and show-and-tell of exactly how Expel can positively affect your NIST CSF ratings — both now ... and over the long term. https://expel.io/blog/get-started-with-the-nist-csf/ PDF The PDF version of our tour and show-and-tell of exactly how Expel can positively affect your NIST CSF ratings — both now ... and over the long term. https://expel.io/wp-content/uploads/2018/03/WP-Getting-started-NIST-1803.pdf

Summary

Summary chart summarizing "As Is" and "To Be" security posture based on the NIST Cybersecurity Framework
This chart automatically updates based on scores entered on other sheets in this workbook

Cyber Security Framework

Asset Mgmt Bus. Environment Governance Risk Assessment Risk Mgmt. Strategy Supply Chain RM Protect Identity Mgt Awareness and Training Data Security Info Protection Maintence Protective Tech Detect Anomalies and Events Continuous Monitoring Detection Processes Respond Response Planning Communications Analysis Mitigation Improvements Recover Recovery Planning Improvements Communications Identify 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 Asset Mgmt Bus. Environment Governance Risk Assessment Risk Mgmt. Strategy Supply Chain RM Protect Identity Mgt Awareness and Training Data Security Info Protection Maintence Protective Tech Detect Anomalies and Events Continuous Monitoring Detection Processes Respond Response Planning Communications Analysis Mitigation Improvements Recover Recovery Planning Improvements Communications Identify 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4 4

Identify

Identify: Functional Area summary (note: this table will update automatically based on the "as is" and "to be" scores you enter on rows 37 to 70 below)
Category Name As Is To Be
Asset Management (ID.AM) Average Asset Mgmt 2 4
Business Environment (ID.BE) Average Bus. Environment 2 4
Governance (ID.GV) Average Governance 2 4
Risk Assessment (ID.RA) Average Risk Assessment 2 4
Risk Management Strategy (ID.RM) Average Risk Mgmt. Strategy 2 4
Supply Chain Risk Management (ID.SC) Average Supply Chain RM 2 4
Identify: Self-scoring worksheet (note: enter an "as is" and "to be" score, from 0 to 5, in column D and E for all of the cells that are shaded light green)
Asset Management As Is To Be
ID.AM-1: Physical devices and systems within the organization are inventoried ID.AM-1 2 4
ID.AM-2: Software platforms and applications within the organization are inventoried ID.AM-2 2 4
ID.AM-3: Organizational communication and data flows are mapped ID.AM-3 2 4
ID.AM-4: External information systems are catalogued ID.AM-4 2 4
ID.AM-5: Resources (e.g., hardware, devices, data, time, and software) are prioritized based on their classification, criticality, and business value ID.AM-5 2 4
ID.AM-6: Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established ID.AM-6 2 4
Business Environment As Is To Be
ID.BE-1: The organization’s role in the supply chain is identified and communicated ID.BE-1 2 4
ID.BE-2: The organization’s place in critical infrastructure and its industry sector is identified and communicated ID.BE-2 2 4
ID.BE-3: Priorities for organizational mission, objectives, and activities are established and communicated ID.BE-3 2 4
ID.BE-4: Dependencies and critical functions for delivery of critical services are established ID.BE-4 2 4
ID.BE-5: Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations) ID.BE-5 2 4
Governance As Is To Be
ID.GV-1: Organizational information security policy is established ID.GV-1 2 4
ID.GV-2: Information security roles & responsibilities are coordinated and aligned with internal roles and external partners ID.GV-2 2 4
ID.GV-3: Legal and regulatory requirements regarding cybersecurity, including privacy and civil liberties obligations, are understood and managed ID.GV-3 2 4
ID.GV-4: Governance and risk management processes address cybersecurity risks ID.GV-4 2 4
Risk Assessment As Is To Be
ID.RA-1: Asset vulnerabilities are identified and documented ID.RA-1 2 4
ID.RA-2: Cyber threat intelligence is received from information sharing forums and sources ID.RA-2 2 4
ID.RA-3: Threats, both internal and external, are identified and documented ID.RA-3 2 4
ID.RA-4: Potential business impacts and likelihoods are identified ID.RA-4 2 4
ID.RA-5: Threats, vulnerabilities, likelihoods, and impacts are used to determine risk ID.RA-5 2 4
ID.RA-6: Risk responses are identified and prioritized ID.RA-6 2 4
Risk Management Strategy As Is To Be
ID.RM-1: Risk management processes are established, managed, and agreed to by organizational stakeholders ID.RM-1 2 4
ID.RM-2: Organizational risk tolerance is determined and clearly expressed ID.RM-2 2 4
ID.RM-3: The organization’s determination of risk tolerance is informed by its role in critical infrastructure and sector specific risk analysis ID.RM-3 2 4
Supply Chain Management As Is To Be
ID.SC-1: Cyber supply chain risk management processes are identified, established, assessed, managed, and agreed to by organizational stakeholders ID.SC-1 2 4
ID.SC-2: Identify, prioritize and assess suppliers and third-party partners of information systems, components and services using a cyber supply chain risk assessment process ID.SC-2 2 4
ID.SC-3: Suppliers and 3rd-party partners are required by contract to implement appropriate measures designed to meet the objectives of the Information Security program or Cyber Supply Chain Risk Management Plan ID.SC-3 2 4
ID.SC-4: Suppliers and 3rd-party partners are routinely assessed to confirm that they are meeting their contractual obligations. Reviews of audits, summaries of test results, or other equivalent evaluations of suppliers/providers are conducted ID-SC.4 2 4
ID.SC-5: Response and recovery planning and testing are conducted with suppliers and third-party providers ID-SC.5 2 4

IDENTIFY

ID.AM-1 ID.AM-2 ID.AM-3 ID.AM-4 ID.AM-5 ID.AM-6 ID.BE-1 ID.BE-2 ID.BE-3 ID.BE-4 ID.BE-5 ID.GV-1 ID.GV-2 ID.GV-3 ID.GV-4 ID.RA-1 ID.RA-2 ID.RA-3 ID.RA-4 ID.RA-5 ID.RA-6 ID.RM-1 ID.RM-2 ID.RM-3 ID.SC-1 ID.SC-2 ID.SC-3 ID-SC.4 ID-SC.5 2 2 2 2 2 2 0 2 2 2 2 2 0 2 2 2 2 0 2 2 2 2 2 2 0 2 2 2 0 2 2 2 2 2 ID.AM-1 ID.AM-2 ID.AM-3 ID.AM-4 ID.AM-5 ID.AM-6 ID.BE-1 ID.BE-2 ID.BE-3 ID.BE-4 ID.BE-5 ID.GV-1 ID.GV-2 ID.GV-3 ID.GV-4 ID.RA-1 ID.RA-2 ID.RA-3 ID.RA-4 ID.RA-5 ID.RA-6 ID.RM-1 ID.RM-2 ID.RM-3 ID.SC-1 ID.SC-2 ID.SC-3 ID-SC.4 ID-SC.5 4 4 4 4 4 4 0 4 4 4 4 4 0 4 4 4 4 0 4 4 4 4 4 4 0 4 4 4 0 4 4 4 4 4

Protect

Protect: Functional Area summary (note: this table will update automatically based on the "as is" and "to be" scores you enter on rows 37 to 80 below)
Category Name As Is To Be
Identity Management, Authentication and Access Control (PR.AC) - Average Identity Mgt 2 4
Awareness and Training (PR.AT) - Average Awareness and Training 2 4
Data Security (PR.DS) - Average Data Security 2 4
Information Protection Processes and Procedures (PR.IP) - Average Info Protection 2 4
Maintenance (PR.MA) - Average Maintence 2 4
Protective Technology (PR.PT) - Average Protective Tech 2 4
Protect: Self-scoring worksheet (note: enter an "as is" and "to be" score, from 0 to 5, in column D and E for all of the cells that are shaded light green)
Identity Management As Is To Be
PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes PR.AC-1 2 4
PR.AC-2: Physical access to assets is managed and protected PR.AC-2 2 4
PR.AC-3: Remote access is managed PR.AC-3 2 4
PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties PR.AC-4 2 4
PR.AC-5: Network integrity is protected, incorporating network segregation where appropriate PR.AC-5 2 4
PR.AC-6: Identities are proofed and bound to credentials, and asserted in interactions when appropriate PR.AC-6 2 4
PR.AC-7: Users, devices, and other assets are authenticated (e.g., single-factor, multi-factor) commensurate with the risk of the transaction (e.g., individuals’ security and privacy risks and other organizational risks) PR.AC-7 2 4
Awareness and Training As Is To Be
PR.AT-1: All users are informed and trained PR.AT-1 2 4
PR.AT-2: Privileged users understand roles and responsibilities PR.AT-2 2 4
PR.AT-3: Third-party stakeholders (e.g., suppliers, customers, partners) understand roles and responsibilities PR.AT-3 2 4
PR.AT-4: Senior executives understand roles and responsibilities PR.AT-4 2 4
PR.AT-5: Physical and information security personnel understand roles and responsibilities PR.AT-5 2 4
Data Security As Is To Be
PR.DS-1: Data-at-rest is protected PR-DS.1 2 4
PR.DS-2: Data-in-transit is protected PR-DS.2 2 4
PR.DS-3: Assets are formally managed throughout removal, transfers, and disposition PR-DS.3 2 4
PR.DS-4: Adequate capacity to ensure availability is maintained PR-DS.4 2 4
PR.DS-5: Protections against data leaks are implemented PR-DS.5 2 4
PR.DS-6: Integrity checking mechanisms are used to verify software, firmware, and information integrity PR-DS.6 2 4
PR.DS-7: The development and testing environment(s) are separate from the production environment PR-DS.7 2 4
PR.DS-8: Integrity checking mechanisms are used to verify hardware integrity PR-DS.8 2 4
Info Protection As Is To Be
PR.IP-1: A baseline configuration of information technology/industrial control systems is created and maintained incorporating appropriate security principles (e.g. concept of least functionality) PR.IP-1 2 4
PR.IP-2: A System Development Life Cycle to manage systems is implemented PR.IP-2 2 4
PR.IP-3: Configuration change control processes are in place PR.IP-3 2 4
PR.IP-4: Backups of information are conducted, maintained, and tested periodically PR.IP-4 2 4
PR.IP-5: Policy and regulations regarding the physical operating environment for organizational assets are met PR.IP-5 2 4
PR.IP-6: Data is destroyed according to policy PR.IP-6 2 4
PR.IP-7: Protection processes are continuously improved PR.IP-7 2 4
PR.IP-8: Effectiveness of protection technologies is shared with appropriate parties PR.IP-8 2 4
PR.IP-9: Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed PR.IP-9 2 4
PR.IP-10: Response and recovery plans are tested PR.IP-10 2 4
PR.IP-11: Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening) PR.IP-11 2 4
PR.IP-12: A vulnerability management plan is developed and implemented PR.IP-12 2 4
Maintenance As Is To Be
PR.MA-1: Maintenance and repair of organizational assets are performed and logged in a timely manner, with approved and controlled tools PR.MA-1 2 4
PR.MA-2: Remote maintenance of organizational assets are approved, logged, and performed in a manner that prevents unauthorized access PR.MA-2 2 4
Protective Tech As Is To Be
PR.PT-1: Audit/log records are determined, documented, implemented, and reviewed in accordance with policy PR.PT-1 2 4
PR.PT-2: Removable media is protected and its use restricted according to policy PR.PT-2 2 4
PR.PT-3: The principle of least functionality is incorporated by configuring systems to provide only essential capabilities PR.PT-3 2 4
PR.PT-4: Communications and control networks are protected PR.PT-4 2 4
PR.PT-5: Systems operate in pre-defined functional states to achieve availability (e.g. under duress, under attack, during recovery, normal operations) PR.PT-5 2 4

PROTECT

PR.AC-1 PR.AC-2 PR.AC-3 PR.AC-4 PR.AC-5 PR.AC-6 PR.AC-7 PR.AT-1 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 PR-DS.1 PR-DS.2 PR-DS.3 PR-DS.4 PR-DS.5 PR-DS.6 PR-DS.7 PR-DS.8 PR.IP-1 PR.IP-2 PR.IP-3 PR.IP-4 PR.IP-5 PR.IP-6 PR.IP-7 PR.IP-8 PR.IP-9 PR.IP-10 PR.IP-11 PR.IP-12 PR.MA-1 PR.MA-2 PR.PT-1 PR.PT-2 PR.PT-3 PR.PT-4 PR.PT-5 2 2 2 2 2 2 2 0 2 2 2 2 2 0 2 2 2 2 2 2 2 2 0 2 2 2 2 2 2 2 2 2 2 2 2 0 2 2 0 2 2 2 2 2 PR.AC-1 PR.AC-2 PR.AC-3 PR.AC-4 PR.AC-5 PR.AC-6 PR.AC-7 PR.AT-1 PR.AT-2 PR.AT-3 PR.AT-4 PR.AT-5 PR-DS.1 PR-DS.2 PR-DS.3 PR-DS.4 PR-DS.5 PR-DS.6 PR-DS.7 PR-DS.8 PR.IP-1 PR.IP-2 PR.IP-3 PR.IP-4 PR.IP-5 PR.IP-6 PR.IP-7 PR.IP-8 PR.IP-9 PR.IP-10 PR.IP-11 PR.IP-12 PR.MA-1 PR.MA-2 PR.PT-1 PR.PT-2 PR.PT-3 PR.PT-4 PR.PT-5 4 4 4 4 4 4 4 0 4 4 4 4 4 0 4 4 4 4 4 4 4 4 0 4 4 4 4 4 4 4 4 4 4 4 4 0 4 4 0 4 4 4 4 4

Detect

Detect: Functional Area summary (note: this table will update automatically based on the "as is" and "to be" scores you enter on rows 34 to 53 below)
Category Name As Is To Be
Anomalies and Events (DE.AE) - Average Anomalies and Events 2 4
Security Continuous Monitoring (DE.CM) - Average Continuous Monitoring 2 4
Detection Processes (DE.DP) - Average Detection Processes 2 4
Detect: Self-scoring worksheet (note: enter an "as is" and "to be" score, from 0 to 5, in column D and E for all of the cells that are shaded light green)
Anomalies and Events As Is To Be
DE.AE-1: A baseline of network operations and expected data flows for users and systems is established and managed DE.AE-1 2 4
DE.AE-2: Detected events are analyzed to understand attack targets and methods DE.AE-2 2 4
DE.AE-3: Event data are collected and correlated from multiple sources and sensors DE.AE-3 2 4
DE.AE-4: Impact of events is determined DE.AE-4 2 4
DE.AE-5: Incident alert thresholds are established DE.AE-5 2 4
Continous Monitoring As Is To Be
DE.CM-1: The network is monitored to detect potential cybersecurity events DE.CM-1 2 4
DE.CM-2: The physical environment is monitored to detect potential cybersecurity events DE.CM-2 2 4
DE.CM-3: Personnel activity is monitored to detect potential cybersecurity events DE.CM-3 2 4
DE.CM-4: Malicious code is detected DE.CM-4 2 4
DE.CM-5: Unauthorized mobile code is detected DE.CM-5 2 4
DE.CM-6: External service provider activity is monitored to detect potential cybersecurity events DE.CM-6 2 4
DE.CM-7: Monitoring for unauthorized personnel, connections, devices, and software is performed DE.CM-7 2 4
DE.CM-8: Vulnerability scans are performed DE.CM-8 2 4
Detection Process As Is To Be
DE.DP-1: Roles and responsibilities for detection are well defined to ensure accountability DE.DP-1 2 4
DE.DP-2: Detection activities comply with all applicable requirements DE.DP-2 2 4
DE.DP-3: Detection processes are tested DE.DP-3 2 4
DE.DP-4: Event detection information is communicated to appropriate parties DE.DP-4 2 4
DE.DP-5: Detection processes are continuously improved DE.DP-5 2 4

DETECT

DE.AE-1 DE.AE-2 DE.AE-3 DE.AE-4 DE.AE-5 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7 DE.CM-8 DE.DP-1 DE.DP-2 DE.DP-3 DE.DP-4 DE.DP-5 2 2 2 2 2 0 2 2 2 2 2 2 2 2 0 2 2 2 2 2 DE.AE-1 DE.AE-2 DE.AE-3 DE.AE-4 DE.AE-5 DE.CM-1 DE.CM-2 DE.CM-3 DE.CM-4 DE.CM-5 DE.CM-6 DE.CM-7 DE.CM-8 DE.DP-1 DE.DP-2 DE.DP-3 DE.DP-4 DE.DP-5 4 4 4 4 4 0 4 4 4 4 4 4 4 4 0 4 4 4 4 4

Recover

Recover: Functional Area summary (note: this table will update automatically based on the "as is" and "to be" scores you enter on rows 33 to 40 below)
Category Name As Is To Be
Recovery Planning (RC.RP) - Average Recovery Planning 2 4
Improvements (RC.IM) - Average Improvements 2 4
Communications (RC.CO) - Average Communications 2 4
Recover: Self-scoring worksheet (note: enter an "as is" and "to be" score, from 0 to 5, in column D and E for all of the cells that are shaded light green)
Recovery Planning As Is To Be
RC.RP-1: Recovery plan is executed during or after a cybersecurity incident RC.RP-1 2 4
Improvements As Is To Be
RC.IM-1: Recovery plans incorporate lessons learned RC.IM-1 2 4
RC.IM-2: Recovery strategies are updated RC.IM-2 2 4
Communications As Is To Be
RC.CO-1: Public relations are managed RC.CO-1 2 4
RC.CO-2: Reputation after an event is repaired RC.CO-2 2 4
RC.CO-3: Recovery activities are communicated to internal stakeholders and executive and management teams RC.CO-3 2 4

RECOVER

RC.RP-1 RC.IM-1 RC.IM-2 RC.CO-1 RC.CO-2 RC.CO-3 2 0 2 2 0 2 2 2 RC.RP-1 RC.IM-1 RC.IM-2 RC.CO-1 RC.CO-2 RC.CO-3 4 0 4 4 0 4 4 4

Respond

Respond: Functional Area summary (note: this table will update automatically based on the "as is" and "to be" scores you enter on rows 36 to 55 below)
Category Name As Is To Be
Response Planning (RS.RP) - Average Response Planning 2 4
Communications (RS.CO) - Average Communications 2 4
Analysis (RS.AN) - Average Analysis 2 4
Mitigation (RS.MI) - Average Mitigation 2 4
Improvements (RS.IM) - Average Improvements 2 4
Respond: Self-scoring worksheet (note: enter an "as is" and "to be" score, from 0 to 5, in column D and E for all of the cells that are shaded light green)
Response Planning As Is To Be
RS.RP-1: Response plan is executed during or after an incident RS.RP-1 2 4
Communications As Is To Be
RS.CO-1: Personnel know their roles and order of operations when a response is needed RS.CO-1 2 4
RS.CO-2: Incidents are reported consistent with established criteria RS.CO-2 2 4
RS.CO-3: Information is shared consistent with response plans RS.CO-3 2 4
RS.CO-4: Coordination with stakeholders occurs consistent with response plans RS.CO-4 2 4
RS.CO-5: Voluntary information sharing occurs with external stakeholders to achieve broader cybersecurity situational awareness RS.CO-5 2 4
Analysis As Is To Be
RS.AN-1: Notifications from detection systems are investigated  RS.AN-1 2 4
RS.AN-2: The impact of the incident is understood RS.AN-2 2 4
RS.AN-3: Forensics are performed RS.AN-3 2 4
RS.AN-4: Incidents are categorized consistent with response plans RS.AN-4 2 4
RS.AN-5: Processes are established to receive, analyze and respond to vulnerabilities disclosed to the organization from internal and external sources (e.g. internal testing, security bulletins, or security researchers) RS.AN-5 2 4
Mitigation As Is To Be
RS.MI-1: Incidents are contained RS.MI-1 2 4
RS.MI-2: Incidents are mitigated RS.MI-2 2 4
RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks RS.MI-3 2 4
Improvements As Is To Be
RS.IM-1: Response plans incorporate lessons learned RS.IM-1 2 4
RS.IM-2: Response strategies are updated RS.IM-2 2 4

RESPOND

RS.RP-1 RS.CO-1 RS.CO-2 RS.CO-3 RS.CO-4 RS.CO-5 RS.AN-1 RS.AN-2 RS.AN-3 RS.AN-4 RS.AN-5 RS.MI-1 RS.MI-2 RS.MI-3 RS.IM-1 RS.IM-2 2 0 2 2 2 2 2 0 2 2 2 2 2 0 2 2 2 0 2 2 RS.RP-1 RS.CO-1 RS.CO-2 RS.CO-3 RS.CO-4 RS.CO-5 RS.AN-1 RS.AN-2 RS.AN-3 RS.AN-4 RS.AN-5 RS.MI-1 RS.MI-2 RS.MI-3 RS.IM-1 RS.IM-2 4 0 4 4 4 4 4 0 4 4 4 4 4 0 4 4 4 0 4 4

Scratch (do not use)

As-Is To-Be Q1 Q2 Q3 Q4
Identify
Asset Mgmt 2 4
Bus. Environment 2 4
Governance 2 4
Risk Assessment 2 4
Risk Mgmt. Strategy 2 4
Supply Chain RM 2 4
Protect
Identity Mgt 2 4
Awareness and Training 2 4
Data Security 2 4
Info Protection 2 4
Maintence 2 4
Protective Tech 2 4
Detect
Anomalies and Events 2 4
Continuous Monitoring 2 4
Detection Processes 2 4
Respond
Response Planning 2 4
Communications 2 4
Analysis 2 4
Mitigation 2 4
Improvements 2 4
Recover
Recovery Planning 2 4
Improvements 2 4
Communications 2 4
Identify