{
    "authors": [
        "NC3 Team"
    ],
    "label": "Cyfun Basic [EN]",
    "language": "EN",
    "refs": [
        "https://cyfun.eu/"
    ],
    "uuid": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
    "values": [
        {
            "category": "[Organisational Context] - Legal, regulatory, and contractual requirements regarding cybersecurity are understood and managed.",
            "code": "GV.OC-03.1",
            "label": "Legal and regulatory requirements regarding information and cybersecurity shall be identified and implemented.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "3c9ee958-41fa-4961-b544-ec8a59993f99"
        },
        {
            "category": "[Risk Management Strategy] - Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.",
            "code": "GV.RM-03.1",
            "label": "As part of the organisation-wide risk management strategy, a comprehensive strategy to manage information and cybersecurity risks shall be developed and updated when changes occur.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "e971f385-7644-424d-bad9-40c9c8a6b0dd"
        },
        {
            "category": "[Roles, Responsibilities and Authorities] - Cybersecurity is included in human resources practices.",
            "code": "GV.RR-04.1",
            "label": "Personnel with access to the organisation\u2019s most critical information or technology shall be authenticated.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "857fa1ea-aad2-4423-b990-0c3a68073f95"
        },
        {
            "category": "[Policy] - Policy for managing cybersecurity risks is established based on organisational context, cybersecurity strategy, and priorities and is communicated and enforced.",
            "code": "GV.PO-01.1",
            "label": "Policies and procedures for managing information and cybersecurity shall be established, documented, reviewed, approved, updated when changes occur, communicated and enforced.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "9f613cb8-51be-4554-914b-667b035e249e"
        },
        {
            "category": "[Asset Management] - Inventories of hardware managed by the organisation are maintained.",
            "code": "ID.AM-01.1",
            "label": "An inventory of physical and virtual infrastructure assets\u2014such as hardware, network devices, and cloud-hosted environments\u2014that support information processing shall be documented, reviewed, and updated as changes occur.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "7ba81916-2664-43e8-bc8d-9a1e31251996"
        },
        {
            "category": "[Asset Management] - Inventories of software, services, and systems managed by the organisation are maintained.",
            "code": "ID.AM-02.1",
            "label": "An inventory of software, digital services, and business systems used within the organisation shall be documented, reviewed, and updated as changes occur.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "f53cef22-1562-4dcb-b97c-fe4ea3a74ce2"
        },
        {
            "category": "[Asset Management] - Assets are prioritised based on classification, criticality, resources, and impact on the mission.",
            "code": "ID.AM-05.1",
            "label": "The organisation\u2019s assets shall be prioritised based on classification, criticality, and business value.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "02b75aaf-0a21-4c12-a4af-19bc65226f40"
        },
        {
            "category": "[Asset Management] - Inventories of data and corresponding metadata for designated data types are maintained.",
            "code": "ID.AM-07.1",
            "label": "Data that the organisation stores and uses shall be identified.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "f01f9c35-3005-4cdd-92e2-fceaa3ead7e0"
        },
        {
            "category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their lifecycles.",
            "code": "ID.AM-08.2",
            "label": "Patches and security updates for operating systems and critical system components shall be installed.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "e0632a06-1081-456f-a158-dada059e56c7"
        },
        {
            "category": "[Risk Assessment] - Vulnerabilities in assets are identified, validated, and recorded.",
            "code": "ID.RA-01.1",
            "label": "Threats and vulnerabilities shall be identified in all relevant assets, including software, network and system architectures, and facilities that house critical computing assets.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "f8eca19c-e89a-48e4-8e97-fc84a4599f4a"
        },
        {
            "category": "[Risk Assessment] - Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritisation.",
            "code": "ID.RA-05.1",
            "label": "The organisation shall conduct risk assessments in which risk is determined by threats, vulnerabilities and the impact on business processes and assets.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "e08db00c-758c-4221-93e1-5824567d9849"
        },
        {
            "category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
            "code": "ID.IM-03.1",
            "label": "The organisation shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its cyber-resilience.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "768c8c85-1bb0-436c-87ef-a97de662827b"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Identities and credentials for authorised users, services, and hardware are managed by the organisation.",
            "code": "PR.AA-01.1",
            "label": "Identities and credentials for authorised users, services, and hardware shall be managed.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "63c8629d-384e-41fc-a10f-93baf910d261"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Users, services, and hardware are authenticated.",
            "code": "PR.AA-03.1",
            "label": "All wireless access points used by the organisation, including those providing guest access, shall be securely configured, managed, and monitored to prevent unauthorised access and ensure network integrity.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "28458da0-55aa-4c02-94a3-692f382dce26"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Users, services, and hardware are authenticated.",
            "code": "PR.AA-03.2",
            "label": "Multi-Factor Authentication (MFA) shall be required to access the organisation's networks remotely.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "73ddcce8-65fa-47e1-9d98-f45e3658adc6"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.1",
            "label": "Access permissions, rights, and authorisations shall be defined, managed, enforced and reviewed.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "8bf91112-84c0-47b6-8b3d-0e3089de35e0"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.2",
            "label": "It shall be determined who needs access to the organisation's business-critical information and technology and the means to gain access.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "52e03428-b572-4416-9d62-581516daddcb"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.3",
            "label": "Access rights, privileges and authorisations shall be restricted to the systems and specific information needed to perform the tasks (the principle of Least Privilege).",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "2a17eb3d-3904-4d99-bd1e-97f9c8d4476d"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
            "code": "PR.AA-05.4",
            "label": "No-one shall have administrative privileges for routine day-to-day tasks.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "04bc90b8-6649-4a72-9a5b-69767e5a64d9"
        },
        {
            "category": "[Identity Management, Authentication, and Access Control] - Physical access to assets is managed, monitored, and enforced commensurate with risk",
            "code": "PR.AA-06.1",
            "label": "Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "14e6b73b-54b9-4321-930d-4ee7f90e4f1e"
        },
        {
            "category": "[Awareness and Training] - Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.",
            "code": "PR.AT-01.1",
            "label": "The organisation shall establish and maintain a cybersecurity awareness and training programme to ensure that all personnel understand how to perform their tasks securely and responsibly.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "4f015d31-3aad-443b-8c38-008f763891e5"
        },
        {
            "category": "[Data Security] - The confidentiality, integrity, and availability of data-at-rest are protected.",
            "code": "PR.DS-01.9",
            "label": "Enterprise assets shall be disposed of safely.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "d57c9eb5-9d2d-4e6c-9800-0d89ba5c0dc0"
        },
        {
            "category": "[Data Security] - Backups of data are created, protected, maintained, and tested.",
            "code": "PR.DS-11.1",
            "label": "Backups for the organisation's business-critical data shall be performed and stored on a different system from the device on which the original data resides.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "81b65e17-4c29-47e9-9278-c578febc5f4e"
        },
        {
            "category": "[Platform Security] - Log records are generated and made available for continuous monitoring.",
            "code": "PR.PS-04.1",
            "label": "Logs shall be maintained, documented, and monitored.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "b74d9720-026c-42d7-b4bc-6ab728dfd79c"
        },
        {
            "category": "[Platform Security] - Installation and execution of unauthorised software are prevented.",
            "code": "PR.PS-05.1",
            "label": "Web and e-mail filters shall be installed and used.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "7c123245-f622-47f1-8100-96ac8fc4b9c2"
        },
        {
            "category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage .",
            "code": "PR.IR-01.1",
            "label": "Firewalls shall be installed, configured, and actively maintained on all networks used by the organisation to protect against unauthorised access and cyber threats.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "db18b56e-269a-4f58-a3d3-e677ef93849c"
        },
        {
            "category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage .",
            "code": "PR.IR-01.2",
            "label": "To safeguard critical systems, organisations shall implement network segmentation and segregation aligned with trust boundaries and asset criticality, thereby limiting threat propagation and enforcing strict access control.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "ce71fb57-1c40-493d-9950-ff4e0b5e2a7a"
        },
        {
            "category": "[Continuous Monitoring] - Networks and network services are monitored to find potentially adverse events.",
            "code": "DE.CM-01.1",
            "label": "Firewalls shall be installed and operated at the network boundaries, including endpoint firewalls.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "2532df48-ab83-4a14-8a5a-464037935c3f"
        },
        {
            "category": "[Continuous Monitoring] - Networks and network services are monitored to find potentially adverse events.",
            "code": "DE.CM-01.2",
            "label": "Anti-virus, -spyware, and other -malware programs shall be installed and updated.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "26c6b019-cd57-4db2-b9a9-83b263dcfe96"
        },
        {
            "category": "[Continuous Monitoring] - Personnel activity and technology usage are monitored to find potentially adverse events.",
            "code": "DE.CM-03.1",
            "label": "End point and network protection tools to monitor end-user behaviour for dangerous activity shall be implemented.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "b3135e43-3306-4b7b-bb11-8566b4d8a156"
        },
        {
            "category": "[Adverse Event Analysis] - Information is correlated from multiple sources.",
            "code": "DE.AE-03.1",
            "label": "The logging functionality of protection and detection tools shall be enabled. Logs shall be backed up and kept for a predefined period, and regularly reviewed to identify unusual or potentially harmful activity.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "bf2963f1-0bf2-4c1d-989f-41f83e39b947"
        },
        {
            "category": "[Incident Management] - The incident response plan is executed in coordination with relevant third parties once an incident is declared.",
            "code": "RS.MA-01.1",
            "label": "An incident response plan, including defined roles, responsibilities, and authorities, shall be executed during or after a cybersecurity event affecting the organisation's critical systems.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "27b6f889-fa82-400f-a132-ea16a7dacf9a"
        },
        {
            "category": "[Incident Response Reporting and Communication] - Internal and external stakeholders are notified of incidents",
            "code": "RS.CO-02.1",
            "label": "Information about cybersecurity incidents shall be communicated to employees in a way that is clear and easy to understand.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "53bfb96f-aa7f-412f-a9b4-d1706b9f4543"
        },
        {
            "category": "[Incident Recovery Plan Execution] - The recovery portion of the incident response plan is executed once initiated from the incident response process.",
            "code": "RC.RP-01.1",
            "label": "A recovery process for disasters and information/cybersecurity incidents shall be developed and executed.",
            "referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
            "referential_label": "Cyfun Basic [EN]",
            "uuid": "3e484245-30ba-4104-a885-868dd40e6d0d"
        }
    ],
    "version": 1,
    "version_ext": "CyFun\u00ae2025"
}