Skip to Main Content

NIST Functions for Information Security Initiatives

The future state security initiatives are designed to address major technical and nontechnical challenges that hinder UCLA's overall cybersecurity maturity.

UCLA's information security initiatives are designed to address technical and nontechnical challenges that affect the University's cybersecurity risk and maturity. The initiatives are aligned with the six Functions of the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0: Identify, Protect, Detect, Respond, Recover, and Govern.

The CSF provides a flexible, risk-based approach for understanding, assessing, prioritizing, and communicating cybersecurity outcomes. Aligning UCLA's information security initiatives with the framework helps the University manage cybersecurity risk in support of its mission, regulatory obligations, business needs, and risk management priorities.

Effective cybersecurity risk management requires leadership oversight and collaboration across UCLA. The six CSF Functions work together continuously to help UCLA govern cybersecurity risk, understand its current risks, implement safeguards, identify and analyze potential cybersecurity events, respond to incidents, and restore affected assets and operations.

magnifying glass icon

Identify

The Identify Function focuses on understanding UCLA's current cybersecurity risks. This includes identifying and managing assets, assessing cybersecurity risks and vulnerabilities, understanding threats and potential impacts, and identifying improvements to cybersecurity risk management processes and activities.

shield icon

Protect

The Protect Function focuses on implementing safeguards to manage UCLA's cybersecurity risks. This includes identity and access management, security awareness and training, data security, platform security, and technology infrastructure resilience.

exclamation point icon

Detect

The Detect Function focuses on finding and analyzing possible cybersecurity attacks and compromises. UCLA continuously monitors assets and services for anomalies and indicators of potentially adverse events and analyzes those events to characterize and detect cybersecurity incidents.

gear icon

Respond

The Respond Function focuses on taking actions regarding a detected cybersecurity incident. This includes managing incidents, analyzing their scope and impact, coordinating response activities and communications, containing incidents, and mitigating their effects.

wrench icon

Recover

The Recover Function focuses on restoring assets and operations affected by a cybersecurity incident. This includes executing recovery plans, verifying restoration activities, communicating recovery status, and supporting the timely restoration of normal operations.

g6

Govern

The Govern Function establishes and monitors the organization’s cybersecurity risk management strategy, expectations, and policy. It addresses organizational context, risk management strategy, roles and responsibilities, policy, oversight, and cybersecurity supply chain risk management.