PR · PROTECT

Schützen

Geeignete Schutzmaßnahmen werden eingesetzt, um Eintrittswahrscheinlichkeit und Auswirkungen von Cybersicherheitsvorfällen zu begrenzen.

5 Kategorien · 22 Ergebnisziele

PR.AA

Identitätsmanagement, Authentifizierung und Zugriffskontrolle (Identity Management, Authentication, and Access Control)

Der Zugriff auf physische und logische Assets wird auf autorisierte Nutzer, Dienste und Hardware beschränkt und risikoangemessen verwaltet.

PR.AA-01

Identitäten und Anmeldedaten für autorisierte Nutzer, Dienste und Hardware werden verwaltet.

Eigenrisiko

NIST-Originalwortlaut: Identities and credentials for authorized users, services, and hardware are managed by the organization

Umsetzungsbeispiele (4)
  • Initiate requests for new access or additional access for employees, contractors, and others, and track, review, and fulfill the requests, with permission from system or data owners when needed
  • Issue, manage, and revoke cryptographic certificates and identity tokens, cryptographic keys (i.e., key management), and other credentials
  • Select a unique identifier for each device from immutable hardware characteristics or an identifier securely provisioned to the device
  • Physically label authorized hardware with an identifier for inventory and servicing purposes
PR.AA-02

Identitäten werden geprüft und kontextabhängig an Anmeldedaten gebunden.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Identities are proofed and bound to credentials based on the context of interactions

Umsetzungsbeispiele (2)
  • Verify a person's claimed identity at enrollment time using government-issued identity credentials (e.g., passport, visa, driver's license)
  • Issue a different credential for each person (i.e., no credential sharing)
PR.AA-03

Nutzer, Dienste und Hardware werden authentifiziert.

Eigenrisiko

NIST-Originalwortlaut: Users, services, and hardware are authenticated

Umsetzungsbeispiele (4)
  • Require multifactor authentication
  • Enforce policies for the minimum strength of passwords, PINs, and similar authenticators
  • Periodically reauthenticate users, services, and hardware based on risk (e.g., in zero trust architectures)
  • Ensure that authorized personnel can access accounts essential for protecting safety under emergency conditions
PR.AA-04

Identitätsaussagen werden geschützt, übermittelt und verifiziert.

Eigenrisiko

NIST-Originalwortlaut: Identity assertions are protected, conveyed, and verified

Umsetzungsbeispiele (3)
  • Protect identity assertions that are used to convey authentication and user information through single sign-on systems
  • Protect identity assertions that are used to convey authentication and user information between federated systems
  • Implement standards-based approaches for identity assertions in all contexts, and follow all guidance for the generation (e.g., data models, metadata), protection (e.g., digital signing, encryption), and verification (e.g., signature validation) of identity assertions
PR.AA-05

Zugriffsrechte und Berechtigungen werden per Richtlinie definiert, verwaltet, durchgesetzt und überprüft – nach den Prinzipien minimaler Rechte und Funktionstrennung.

Eigenrisiko

NIST-Originalwortlaut: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Umsetzungsbeispiele (4)
  • Review logical and physical access privileges periodically and whenever someone changes roles or leaves the organization, and promptly rescind privileges that are no longer needed
  • Take attributes of the requester and the requested resource into account for authorization decisions (e.g., geolocation, day/time, requester endpoint's cyber health)
  • Restrict access and privileges to the minimum necessary (e.g., zero trust architecture)
  • Periodically review the privileges associated with critical business functions to confirm proper separation of duties
PR.AA-06

Der physische Zugang zu Assets wird risikoangemessen verwaltet, überwacht und durchgesetzt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Physical access to assets is managed, monitored, and enforced commensurate with risk

Umsetzungsbeispiele (3)
  • Use security guards, security cameras, locked entrances, alarm systems, and other physical controls to monitor facilities and restrict access
  • Employ additional physical security controls for areas that contain high-risk assets
  • Escort guests, vendors, and other third parties within areas that contain business-critical assets
PR.AT

Sensibilisierung und Schulung (Awareness and Training)

Das Personal erhält Sensibilisierung und Schulung, um seine cybersicherheitsbezogenen Aufgaben wahrnehmen zu können.

PR.AT-01

Das Personal erhält Sensibilisierung und Schulung, um allgemeine Aufgaben mit Blick auf Cybersicherheitsrisiken wahrzunehmen.

Eigenrisiko

NIST-Originalwortlaut: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind

Umsetzungsbeispiele (5)
  • Provide basic cybersecurity awareness and training to employees, contractors, partners, suppliers, and all other users of the organization's non-public resources
  • Train personnel to recognize social engineering attempts and other common attacks, report attacks and suspicious activity, comply with acceptable use policies, and perform basic cyber hygiene tasks (e.g., patching software, choosing passwords, protecting credentials)
  • Explain the consequences of cybersecurity policy violations, both to individual users and the organization as a whole
  • Periodically assess or test users on their understanding of basic cybersecurity practices
  • Require annual refreshers to reinforce existing practices and introduce new practices
PR.AT-02

Personen in spezialisierten Rollen erhalten Sensibilisierung und Schulung für ihre relevanten Aufgaben.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind

Umsetzungsbeispiele (4)
  • Identify the specialized roles within the organization that require additional cybersecurity training, such as physical and cybersecurity personnel, finance personnel, senior leadership, and anyone with access to business-critical data
  • Provide role-based cybersecurity awareness and training to all those in specialized roles, including contractors, partners, suppliers, and other third parties
  • Periodically assess or test users on their understanding of cybersecurity practices for their specialized roles
  • Require annual refreshers to reinforce existing practices and introduce new practices
PR.DS

Datensicherheit (Data Security)

Daten werden gemäß der Risikostrategie verwaltet, um Vertraulichkeit, Integrität und Verfügbarkeit von Informationen zu schützen.

PR.DS-01

Vertraulichkeit, Integrität und Verfügbarkeit ruhender Daten (data-at-rest) werden geschützt.

Eigenrisiko

NIST-Originalwortlaut: The confidentiality, integrity, and availability of data-at-rest are protected

Umsetzungsbeispiele (5)
  • Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of stored data in files, databases, virtual machine disk images, container images, and other resources
  • Use full disk encryption to protect data stored on user endpoints
  • Confirm the integrity of software by validating signatures
  • Restrict the use of removable media to prevent data exfiltration
  • Physically secure removable media containing unencrypted sensitive information, such as within locked offices or file cabinets
PR.DS-02

Vertraulichkeit, Integrität und Verfügbarkeit von Daten während der Übertragung (data-in-transit) werden geschützt.

Eigenrisiko

NIST-Originalwortlaut: The confidentiality, integrity, and availability of data-in-transit are protected

Umsetzungsbeispiele (4)
  • Use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of network communications
  • Automatically encrypt or block outbound emails and other communications that contain sensitive data, depending on the data classification
  • Block access to personal email, file sharing, file storage services, and other personal communications applications and services from organizational systems and networks
  • Prevent reuse of sensitive data from production environments (e.g., customer records) in development, testing, and other non-production environments
PR.DS-10

Vertraulichkeit, Integrität und Verfügbarkeit von Daten während der Verarbeitung (data-in-use) werden geschützt.

Eigenrisiko

NIST-Originalwortlaut: The confidentiality, integrity, and availability of data-in-use are protected

Umsetzungsbeispiele (2)
  • Remove data that must remain confidential (e.g., from processors and memory) as soon as it is no longer needed
  • Protect data in use from access by other users and processes of the same platform
PR.DS-11

Datensicherungen werden erstellt, geschützt, gepflegt und getestet.

Eigenrisiko

NIST-Originalwortlaut: Backups of data are created, protected, maintained, and tested

Umsetzungsbeispiele (4)
  • Continuously back up critical data in near-real-time, and back up other data frequently at agreed-upon schedules
  • Test backups and restores for all types of data sources at least annually
  • Securely store some backups offline and offsite so that an incident or disaster will not damage them
  • Enforce geographic separation and geolocation restrictions for data backup storage
PR.PS

Plattformsicherheit (Platform Security)

Hardware, Software und Dienste physischer und virtueller Plattformen werden gemäß der Risikostrategie verwaltet, um Vertraulichkeit, Integrität und Verfügbarkeit zu schützen.

PR.PS-03

Hardware wird risikoangemessen gewartet, ersetzt und entfernt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Hardware is maintained, replaced, and removed commensurate with risk

Umsetzungsbeispiele (3)
  • Replace hardware when it lacks needed security capabilities or when it cannot support software with needed security capabilities
  • Define and implement plans for hardware end-of-life maintenance support and obsolescence
  • Perform hardware disposal in a secure, responsible, and auditable manner
PR.PS-01

Praktiken des Konfigurationsmanagements werden etabliert und angewendet.

Eigenrisiko

NIST-Originalwortlaut: Configuration management practices are established and applied

Umsetzungsbeispiele (3)
  • Establish, test, deploy, and maintain hardened baselines that enforce the organization's cybersecurity policies and provide only essential capabilities (i.e., principle of least functionality)
  • Review all default configuration settings that may potentially impact cybersecurity when installing or upgrading software
  • Monitor implemented software for deviations from approved baselines
PR.PS-02

Software wird risikoangemessen gewartet, ersetzt und entfernt.

Eigenrisiko

NIST-Originalwortlaut: Software is maintained, replaced, and removed commensurate with risk

Umsetzungsbeispiele (6)
  • Perform routine and emergency patching within the timeframes specified in the vulnerability management plan
  • Update container images, and deploy new container instances to replace rather than update existing instances
  • Replace end-of-life software and service versions with supported, maintained versions
  • Uninstall and remove unauthorized software and services that pose undue risks
  • Uninstall and remove any unnecessary software components (e.g., operating system utilities) that attackers might misuse
  • Define and implement plans for software and service end-of-life maintenance support and obsolescence
PR.PS-04

Protokolldaten werden erzeugt und für die kontinuierliche Überwachung bereitgestellt.

Eigenrisiko

NIST-Originalwortlaut: Log records are generated and made available for continuous monitoring

Umsetzungsbeispiele (3)
  • Configure all operating systems, applications, and services (including cloud-based services) to generate log records
  • Configure log generators to securely share their logs with the organization's logging infrastructure systems and services
  • Configure log generators to record the data needed by zero-trust architectures
PR.PS-05

Installation und Ausführung nicht autorisierter Software werden verhindert.

Eigenrisiko

NIST-Originalwortlaut: Installation and execution of unauthorized software are prevented

Umsetzungsbeispiele (4)
  • When risk warrants it, restrict software execution to permitted products only or deny the execution of prohibited and unauthorized software
  • Verify the source of new software and the software's integrity before installing it
  • Configure platforms to use only approved DNS services that block access to known malicious domains
  • Configure platforms to allow the installation of organization-approved software only
PR.PS-06

Sichere Softwareentwicklung wird integriert und ihre Leistung über den gesamten Entwicklungslebenszyklus überwacht.

Eigenrisiko

NIST-Originalwortlaut: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

Umsetzungsbeispiele (3)
  • Protect all components of organization-developed software from tampering and unauthorized access
  • Secure all software produced by the organization, with minimal vulnerabilities in their releases
  • Maintain the software used in production environments, and securely dispose of software once it is no longer needed
PR.IR

Resilienz der Technologie-Infrastruktur (Technology Infrastructure Resilience)

Sicherheitsarchitekturen werden gemäß der Risikostrategie verwaltet, um Schutz der Assets und organisatorische Resilienz zu gewährleisten.

PR.IR-04

Eine angemessene Ressourcenkapazität zur Sicherstellung der Verfügbarkeit wird vorgehalten.

NIST-Originalwortlaut: Adequate resource capacity to ensure availability is maintained

Umsetzungsbeispiele (2)
  • Monitor usage of storage, power, compute, network bandwidth, and other resources
  • Forecast future needs, and scale resources accordingly
PR.IR-01

Netzwerke und Umgebungen werden vor unbefugtem logischem Zugriff und unbefugter Nutzung geschützt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: Networks and environments are protected from unauthorized logical access and usage

Umsetzungsbeispiele (4)
  • Logically segment organization networks and cloud-based platforms according to trust boundaries and platform types (e.g., IT, IoT, OT, mobile, guests), and permit required communications only between segments
  • Logically segment organization networks from external networks, and permit only necessary communications to enter the organization's networks from the external networks
  • Implement zero trust architectures to restrict network access to each resource to the minimum necessary
  • Check the cyber health of endpoints before allowing them to access and use production resources
PR.IR-02

Die Technologie-Assets der Organisation werden vor Umweltbedrohungen geschützt.

EigenrisikoDrittrisiko

NIST-Originalwortlaut: The organization's technology assets are protected from environmental threats

Umsetzungsbeispiele (2)
  • Protect organizational equipment from known environmental threats, such as flooding, fire, wind, and excessive heat and humidity
  • Include protection from environmental threats and provisions for adequate operating infrastructure in requirements for service providers that operate systems on the organization's behalf
PR.IR-03

Mechanismen zur Erfüllung von Resilienzanforderungen in Normal- und Ausnahmesituationen werden umgesetzt.

Eigenrisiko

NIST-Originalwortlaut: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

Umsetzungsbeispiele (3)
  • Avoid single points of failure in systems and infrastructure
  • Use load balancing to increase capacity and improve reliability
  • Use high-availability components like redundant storage and power supplies to improve system reliability