Design For Cyber Resiliency

LOW MODERATE HIGH
0 Overlays 65 Related Controls
Graph
Export ▾

Requirements NIST SOURCE

    1. 1.Defining the following cyber resiliency goals: [cyber resiliency goals].
    2. 2.Defining the following cyber resiliency objectives: [cyber resiliency objectives].
    3. 3.Defining the following cyber resiliency techniques: [cyber resiliency techniques].
    4. 4.Defining the following cyber resiliency implementation approaches: [cyber resiliency implementation approaches].
    5. 5.Defining the following cyber resiliency design principles: [cyber resiliency design principles].
Discussion (NIST Supplemental Guidance)

Cyber resiliency is critical to ensuring the survivability of mission critical systems and high value assets. Cyber resiliency focuses on limiting the damage from adversity or the conditions that can cause a loss of assets. Damage can affect: (1) organizations (e.g., loss of reputation, increased existential risk); (2) missions or business functions (e.g., decreased capability to complete current missions and to accomplish future missions); (3) security (e.g., decreased capability to achieve security objectives or to prevent, detect, and respond to cyber incidents); (4) systems (e.g., unauthorized use of system resources or decreased capability to meet system requirements); or (5) specific system elements (e.g., physical destruction; corruption, modification, or fabrication of information). Cyber resiliency goals are intended to help organizations maintain a state of informed preparedness for adversity, continue essential mission or business functions despite adversity, restore mission or business functions during and after adversity, and modify mission or business functions and their supporting capabilities in response to predicted changes in technical, operational, or threat environments. NIST SP 800-160, Volume 2 provides additional information on the Cyber Resiliency Engineering Framework to include detailed descriptions of cyber resiliency goals, objectives, techniques, implementation approaches, and design principles. NIST SP 800-160, Vol 1 provides additional information on achieving cyber resiliency as an emergent property of an engineered system.

Implementation Guidance

Engineering Interpretation

Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.

No engineering interpretation has been authored for SA-24 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.

Assessment

No SP 800-53A assessment procedure is recorded for this item in the loaded catalog.

STIGs & CCIs

No STIG checks or CCI mappings are currently loaded for SA-24. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.

Learn more about STIG/CCI integration →

Evidence

No SP 800-53A assessment artifacts are available to derive a potential-evidence view from.