Description
CyberFundamentals Framework 2025 - Basic [English]
Owning organization
Validating JSON schema
Security referentials (provided by Various contributors)
Creator
License
Creative Commons Zero v1.0 Universal
Related objects
Definition of the object
{
"authors": [
"NC3 Team"
],
"label": "Cyfun Basic [EN]",
"language": "EN",
"refs": [
"https://cyfun.eu/"
],
"uuid": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"values": [
{
"category": "[Organisational Context] - Legal, regulatory, and contractual requirements regarding cybersecurity are understood and managed.",
"code": "GV.OC-03.1",
"label": "Legal and regulatory requirements regarding information and cybersecurity shall be identified and implemented.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "3c9ee958-41fa-4961-b544-ec8a59993f99"
},
{
"category": "[Risk Management Strategy] - Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.",
"code": "GV.RM-03.1",
"label": "As part of the organisation-wide risk management strategy, a comprehensive strategy to manage information and cybersecurity risks shall be developed and updated when changes occur.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "e971f385-7644-424d-bad9-40c9c8a6b0dd"
},
{
"category": "[Roles, Responsibilities and Authorities] - Cybersecurity is included in human resources practices.",
"code": "GV.RR-04.1",
"label": "Personnel with access to the organisation’s most critical information or technology shall be authenticated.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "857fa1ea-aad2-4423-b990-0c3a68073f95"
},
{
"category": "[Policy] - Policy for managing cybersecurity risks is established based on organisational context, cybersecurity strategy, and priorities and is communicated and enforced.",
"code": "GV.PO-01.1",
"label": "Policies and procedures for managing information and cybersecurity shall be established, documented, reviewed, approved, updated when changes occur, communicated and enforced.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "9f613cb8-51be-4554-914b-667b035e249e"
},
{
"category": "[Asset Management] - Inventories of hardware managed by the organisation are maintained.",
"code": "ID.AM-01.1",
"label": "An inventory of physical and virtual infrastructure assets—such as hardware, network devices, and cloud-hosted environments—that support information processing shall be documented, reviewed, and updated as changes occur.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "7ba81916-2664-43e8-bc8d-9a1e31251996"
},
{
"category": "[Asset Management] - Inventories of software, services, and systems managed by the organisation are maintained.",
"code": "ID.AM-02.1",
"label": "An inventory of software, digital services, and business systems used within the organisation shall be documented, reviewed, and updated as changes occur.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "f53cef22-1562-4dcb-b97c-fe4ea3a74ce2"
},
{
"category": "[Asset Management] - Assets are prioritised based on classification, criticality, resources, and impact on the mission.",
"code": "ID.AM-05.1",
"label": "The organisation’s assets shall be prioritised based on classification, criticality, and business value.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "02b75aaf-0a21-4c12-a4af-19bc65226f40"
},
{
"category": "[Asset Management] - Inventories of data and corresponding metadata for designated data types are maintained.",
"code": "ID.AM-07.1",
"label": "Data that the organisation stores and uses shall be identified.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "f01f9c35-3005-4cdd-92e2-fceaa3ead7e0"
},
{
"category": "[Asset Management] - Systems, hardware, software, services, and data are managed throughout their lifecycles.",
"code": "ID.AM-08.2",
"label": "Patches and security updates for operating systems and critical system components shall be installed.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "e0632a06-1081-456f-a158-dada059e56c7"
},
{
"category": "[Risk Assessment] - Vulnerabilities in assets are identified, validated, and recorded.",
"code": "ID.RA-01.1",
"label": "Threats and vulnerabilities shall be identified in all relevant assets, including software, network and system architectures, and facilities that house critical computing assets.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "f8eca19c-e89a-48e4-8e97-fc84a4599f4a"
},
{
"category": "[Risk Assessment] - Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritisation.",
"code": "ID.RA-05.1",
"label": "The organisation shall conduct risk assessments in which risk is determined by threats, vulnerabilities and the impact on business processes and assets.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "e08db00c-758c-4221-93e1-5824567d9849"
},
{
"category": "[Improvement] - Improvements are identified from execution of operational processes, procedures, and activities.",
"code": "ID.IM-03.1",
"label": "The organisation shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its cyber-resilience.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "768c8c85-1bb0-436c-87ef-a97de662827b"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Identities and credentials for authorised users, services, and hardware are managed by the organisation.",
"code": "PR.AA-01.1",
"label": "Identities and credentials for authorised users, services, and hardware shall be managed.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "63c8629d-384e-41fc-a10f-93baf910d261"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Users, services, and hardware are authenticated.",
"code": "PR.AA-03.1",
"label": "All wireless access points used by the organisation, including those providing guest access, shall be securely configured, managed, and monitored to prevent unauthorised access and ensure network integrity.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "28458da0-55aa-4c02-94a3-692f382dce26"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Users, services, and hardware are authenticated.",
"code": "PR.AA-03.2",
"label": "Multi-Factor Authentication (MFA) shall be required to access the organisation's networks remotely.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "73ddcce8-65fa-47e1-9d98-f45e3658adc6"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
"code": "PR.AA-05.1",
"label": "Access permissions, rights, and authorisations shall be defined, managed, enforced and reviewed.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "8bf91112-84c0-47b6-8b3d-0e3089de35e0"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
"code": "PR.AA-05.2",
"label": "It shall be determined who needs access to the organisation's business-critical information and technology and the means to gain access.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "52e03428-b572-4416-9d62-581516daddcb"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
"code": "PR.AA-05.3",
"label": "Access rights, privileges and authorisations shall be restricted to the systems and specific information needed to perform the tasks (the principle of Least Privilege).",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "2a17eb3d-3904-4d99-bd1e-97f9c8d4476d"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Access permissions, entitlements, and authorisations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties.",
"code": "PR.AA-05.4",
"label": "No-one shall have administrative privileges for routine day-to-day tasks.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "04bc90b8-6649-4a72-9a5b-69767e5a64d9"
},
{
"category": "[Identity Management, Authentication, and Access Control] - Physical access to assets is managed, monitored, and enforced commensurate with risk",
"code": "PR.AA-06.1",
"label": "Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "14e6b73b-54b9-4321-930d-4ee7f90e4f1e"
},
{
"category": "[Awareness and Training] - Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.",
"code": "PR.AT-01.1",
"label": "The organisation shall establish and maintain a cybersecurity awareness and training programme to ensure that all personnel understand how to perform their tasks securely and responsibly.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "4f015d31-3aad-443b-8c38-008f763891e5"
},
{
"category": "[Data Security] - The confidentiality, integrity, and availability of data-at-rest are protected.",
"code": "PR.DS-01.9",
"label": "Enterprise assets shall be disposed of safely.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "d57c9eb5-9d2d-4e6c-9800-0d89ba5c0dc0"
},
{
"category": "[Data Security] - Backups of data are created, protected, maintained, and tested.",
"code": "PR.DS-11.1",
"label": "Backups for the organisation's business-critical data shall be performed and stored on a different system from the device on which the original data resides.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "81b65e17-4c29-47e9-9278-c578febc5f4e"
},
{
"category": "[Platform Security] - Log records are generated and made available for continuous monitoring.",
"code": "PR.PS-04.1",
"label": "Logs shall be maintained, documented, and monitored.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "b74d9720-026c-42d7-b4bc-6ab728dfd79c"
},
{
"category": "[Platform Security] - Installation and execution of unauthorised software are prevented.",
"code": "PR.PS-05.1",
"label": "Web and e-mail filters shall be installed and used.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "7c123245-f622-47f1-8100-96ac8fc4b9c2"
},
{
"category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage .",
"code": "PR.IR-01.1",
"label": "Firewalls shall be installed, configured, and actively maintained on all networks used by the organisation to protect against unauthorised access and cyber threats.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "db18b56e-269a-4f58-a3d3-e677ef93849c"
},
{
"category": "[Technology Infrastructure Resilience] - Networks and environments are protected from unauthorised logical access and usage .",
"code": "PR.IR-01.2",
"label": "To safeguard critical systems, organisations shall implement network segmentation and segregation aligned with trust boundaries and asset criticality, thereby limiting threat propagation and enforcing strict access control.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "ce71fb57-1c40-493d-9950-ff4e0b5e2a7a"
},
{
"category": "[Continuous Monitoring] - Networks and network services are monitored to find potentially adverse events.",
"code": "DE.CM-01.1",
"label": "Firewalls shall be installed and operated at the network boundaries, including endpoint firewalls.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "2532df48-ab83-4a14-8a5a-464037935c3f"
},
{
"category": "[Continuous Monitoring] - Networks and network services are monitored to find potentially adverse events.",
"code": "DE.CM-01.2",
"label": "Anti-virus, -spyware, and other -malware programs shall be installed and updated.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "26c6b019-cd57-4db2-b9a9-83b263dcfe96"
},
{
"category": "[Continuous Monitoring] - Personnel activity and technology usage are monitored to find potentially adverse events.",
"code": "DE.CM-03.1",
"label": "End point and network protection tools to monitor end-user behaviour for dangerous activity shall be implemented.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "b3135e43-3306-4b7b-bb11-8566b4d8a156"
},
{
"category": "[Adverse Event Analysis] - Information is correlated from multiple sources.",
"code": "DE.AE-03.1",
"label": "The logging functionality of protection and detection tools shall be enabled. Logs shall be backed up and kept for a predefined period, and regularly reviewed to identify unusual or potentially harmful activity.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "bf2963f1-0bf2-4c1d-989f-41f83e39b947"
},
{
"category": "[Incident Management] - The incident response plan is executed in coordination with relevant third parties once an incident is declared.",
"code": "RS.MA-01.1",
"label": "An incident response plan, including defined roles, responsibilities, and authorities, shall be executed during or after a cybersecurity event affecting the organisation's critical systems.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "27b6f889-fa82-400f-a132-ea16a7dacf9a"
},
{
"category": "[Incident Response Reporting and Communication] - Internal and external stakeholders are notified of incidents",
"code": "RS.CO-02.1",
"label": "Information about cybersecurity incidents shall be communicated to employees in a way that is clear and easy to understand.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "53bfb96f-aa7f-412f-a9b4-d1706b9f4543"
},
{
"category": "[Incident Recovery Plan Execution] - The recovery portion of the incident response plan is executed once initiated from the incident response process.",
"code": "RC.RP-01.1",
"label": "A recovery process for disasters and information/cybersecurity incidents shall be developed and executed.",
"referential": "a3845909-c5a0-4db6-9f6d-f765c9d7699d",
"referential_label": "Cyfun Basic [EN]",
"uuid": "3e484245-30ba-4104-a885-868dd40e6d0d"
}
],
"version": 1,
"version_ext": "CyFun®2025"
}