• Skip to main content
  • Skip to primary sidebar
  • Home
TechTidBit – Tips and advice for small business computing – Tech Experts™ – Monroe Michigan

TechTidBit - Tips and advice for small business computing - Tech Experts™ - Monroe Michigan

Brought to you by Tech Experts™

The Five Broad Categories Of The Cybersecurity Framework

March 27, 2020

Thomas Fox is president of Tech Experts, southeast Michigan’s leading small business computer support company.

One of the key methods that the NIST recommends businesses do on a continual basis is focus on these five categories as you assess your cybersecurity framework. These should be done regularly, and proactively, in order to be the most effective.

The categories are broad and cover a wide array of tools that businesses can use to build a cybersecurity framework that best supports their business security needs. They are: identify, protect, detect, respond and recover.

The first step you should take is to identify who should and should not have access to your business’s privileged information, and then maintain strict physical access rules for those personnel who don’t need that access.

NIST recommends that you do not allow cleaning and maintenance staff unsupervised access to rooms that contain computers or other technology that stores sensitive information.

Further recommendations include performing extensive background checks on all prospective employees, setting systems to lock down after several minutes of inactivity and maintaining separate accounts for each user.

The second category NIST mentions is to protect, which focuses on the ability to limit or contain the effects of a cybersecurity event.

Key recommendations include: limiting access to every part of the business information and systems, utilizing surge protector and uninterruptible power supplies, assigning a specific day of the month to perform patches for all software and regularly updating the firmware and operating systems for every system in your group.

Firewalls, securing your WiFi, and training your employees on security best practices round up the extensive list in this category.

A key requirement to any cybersecurity framework is the proactive detection of a cyber event. Anti-virus, spyware or other malware programs can and should be installed on each of your systems.

NIST recommends that you install two different programs from two different vendors for maximum security. You can even take it a step further and include Remote Monitoring and Management (RMM) Services as a part of your security protocol. RMM is an even bigger added layer of security in your ability to detect threats before they cause damage to your systems.

NIST recommends business develop a plan for the immediate response needed in the event of a natural disaster, fire or other event – the same applies to cyberattacks. Businesses should develop a cyber attack response plan that includes details on the roles and responsibilities of certain employees, what to do with information systems in the event of an incident, who to call, and what constitutes a cyber event.

Furthermore, NIST recommends you do this at an employee level, letting each employee know what his or her role will be in the event of a disaster.

The last category NIST defines is recover. NIST has 4 recommendations as to a process to use to help your business recover with minimal damage should an attack occur. They are:

Make full backups of all business data monthly either on an external hard drive (stored in a different location), or online cloud storage

Make automatic incremental backups of important data, and store them in three different ways: removable media such as an external hard drive, a separate isolated server, and cloud backup and online storage from a cloud provider.

Utilize Cyber Insurance – cyber, like health, auto, or business insurance, can help your business recover both physically and financially if a cyber event were to occur.

Some cyber insurance providers even offer cybersecurity experts who can further help you identify where, what and how you are vulnerable and give suggestions on how to fix those insecurities.

Conduct regular assessments of processes, procedures and technologies and make corrections or improvements as necessary.

Cyber attacks are a real and present danger to your business, but you can mitigate the risks by following the above suggestions.

Filed Under: Security Tagged With: cybersecurity

Primary Sidebar

Browse past issues

  • 2025 Issues
  • 2024 Issues
  • 2023 issues
  • 2022 Issues
  • 2021 Issues
  • 2020 Issues
  • 2019 Issues
  • 2018 Issues
  • 2017 Issues
  • 2016 Issues
  • 2015 Issues
  • 2014 Issues
  • 2013 Issues
  • 2012 Issues
  • 2011 Issues
  • 2010 Issues
  • 2009 Issues
  • 2008 Issues
  • 2007 Issues
  • 2006 Issues

More to See

Five Reasons To Be Wary Of AI

May 19, 2025

Don’t Trust The Cloud Alone: Backup Your Cloud Data

May 19, 2025

Seven New And Tricky Types Of Malware To Watch Out For

May 19, 2025

Are You Leaving Your Office Door Open?

April 14, 2025

Tags

Antivirus backups Cloud Computing Cloud Storage COVID-19 cyberattacks cybersecurity Data Management Disaster Planning Disaster Recovery E-Mail Facebook Firewalls Hard Drives Internet Laptops Maintenance Malware Managed Services Marketing Microsoft Network online security Passwords password security Phishing planning Productivity Ransomware remote work Security Servers smart phones Social Media Tech Tips Upgrading Viruses VOIP vulnerabilities Websites Windows Windows 7 Windows 10 Windows Updates work from home

Copyright © 2025 Tech Experts™ · Tech Experts™ is a registered trademark of Tech Support Inc.