data.gift
  • Datasets

http://cyfun.data.gift/data/requirement_ID_IM_03_9

http://cyfun.data.gift/data/requirement_ID_IM_03_9
Concept

  • http://cyfun.data.gift/data/CyFun2025

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ManagementAspects

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

    • External link
    • Internal link
  • http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

    • External link
    • Internal link

  • http://cyfun.data.gift/data/subcategory_ID.IM-03

    • External link
    • Internal link

Properties and relations

Direct links from the subject.

Property Value

type

The subject is an instance of a class.

  • External link
  • Internal link

http://cyfun.data.gift/ontology#Requirement

  • External link
  • Internal link

type

The subject is an instance of a class.

  • External link
  • Internal link

Concept

An idea or notion; a unit of thought.

  • External link
  • Internal link

label

A human-readable name for the subject.

  • External link
  • Internal link

ID.IM-03.9: The organisation shall conduct specialised assessments including in-depth monitoring, vulnerability scanning, malicious user testing, insider threat assessment, performance/ load testing, and verification and validation testing on the organisation's critical systems.

http://cyfun.data.gift/ontology#requirementId

  • External link
  • Internal link

ID.IM-03.9

http://cyfun.data.gift/ontology#foundIn

  • External link
  • Internal link

http://cyfun.data.gift/data/loc_CyFun2025_Booklet_ESSENTIAL_E_p79

  • External link
  • Internal link

has broader

Relates a concept to a concept that is more general in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_ID.IM-03

  • External link
  • Internal link

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to strengthen the security posture of critical systems by conducting specialised assessments that uncover vulnerabilities, evaluate performance, and test defences against insider and external threats. In Operational Technology (OT) environments, these assessments help validate protections and support continuous improvement. To achieve this goal, the organisation should: - Conduct Specialised Assessments Assessments should include in-depth monitoring,vulnerabilityscanning, malicious usertesting, insiderthreat assessments, performance/load testing, and verification and validation testing. - Outsource to Accredited Providers Specialised assessments may be outsourced, preferably to accredited organisations. Accreditation should follow recognised standards such as: - CREST for penetration testing and vulnerability assessments - ISO/IEC 17025 for testing laboratories Accreditation should be granted by recognised bodies such as CREST, national accreditation authorities (e.g. BELAC), or industry-specific bodies (e.g. PCI Security Standards Council). This ensures assessments are conducted with technical competence, impartiality, and in line with best practices. - Integrate Findings into Remediation Vulnerabilities identified during assessments should be addressed through established remediation processes, as outlined in control ID.IM-03.3. - Support Readiness and Maturity Evaluation Assessment results should inform organisational readiness and performance levels (e.g. CyFun® maturity), guiding targeted improvements.

note

A general note, for any purpose.

  • External link
  • Internal link

<div><p>The goal of this control is to strengthen the security posture of critical systems by conducting specialised assessments that uncover vulnerabilities, evaluate performance, and test defences against insider and external threats. In Operational Technology (OT) environments, these assessments help validate protections and support continuous improvement. To achieve this goal, the organisation should:</p><ul><li>Conduct Specialised Assessments Assessments should include in-depth monitoring,vulnerabilityscanning, malicious usertesting, insiderthreat assessments, performance/load testing, and verification and validation testing.</li><li>Outsource to Accredited Providers Specialised assessments may be outsourced, preferably to accredited organisations. Accreditation should follow recognised standards such as:<ul><li>CREST for penetration testing and vulnerability assessments</li><li>ISO/IEC 17025 for testing laboratories Accreditation should be granted by recognised bodies such as CREST, national accreditation authorities (e.g. BELAC), or industry-specific bodies (e.g. PCI Security Standards Council). This ensures assessments are conducted with technical competence, impartiality, and in line with best practices.</li></ul></li><li>Integrate Findings into Remediation Vulnerabilities identified during assessments should be addressed through established remediation processes, as outlined in control ID.IM-03.3.</li><li>Support Readiness and Maturity Evaluation Assessment results should inform organisational readiness and performance levels (e.g. CyFun® maturity), guiding targeted improvements.</li></ul></div>

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to strengthen the security posture of critical systems by conducting specialised assessments that uncover vulnerabilities, evaluate performance, and test defences against insider and external threats. In Operational Technology (OT) environments, these assessments help validate protections and support continuous improvement. To achieve this goal, the organisation should: • Conduct Specialised Assessments Assessments should include in-depth monitoring,vulnerabilityscanning, malicious usertesting, insiderthreat assessments, performance/load testing, and verification and validation testing. • Outsource to Accredited Providers Specialised assessments may be outsourced, preferably to accredited organisations. Accreditation should follow recognised standards such as: o CREST for penetration testing and vulnerability assessments o ISO/IEC 17025 for testing laboratories Accreditation should be granted by recognised bodies such as CREST, national accreditation authorities (e.g. BELAC), or industry-specific bodies (e.g. PCI Security Standards Council). This ensures assessments are conducted with technical competence, impartiality, and in line with best practices. • Integrate Findings into Remediation Vulnerabilities identified during assessments should be addressed through established remediation processes, as outlined in control ID.IM-03.3. • Support Readiness and Maturity Evaluation Assessment results should inform organisational readiness and performance levels (e.g. CyFun® maturity), guiding targeted improvements.

note

A general note, for any purpose.

  • External link
  • Internal link

The goal of this control is to strengthen the security posture of critical systems by conducting specialised assessments that uncover vulnerabilities, evaluate performance, and test defences against insider and external threats. In Operational Technology (OT) environments, these assessments help validate protections and support continuous improvement. To achieve this goal, the organisation should: - Conduct Specialised Assessments Assessments should include in-depth monitoring,vulnerabilityscanning, malicious usertesting, insiderthreat assessments, performance/load testing, and verification and validation testing. - Outsource to Accredited Providers Specialised assessments may be outsourced, preferably to accredited organisations. Accreditation should follow recognised standards such as: - CREST for penetration testing and vulnerability assessments - ISO/IEC 17025 for testing laboratories Accreditation should be granted by recognised bodies such as CREST, national accreditation authorities (e.g. BELAC), or industry-specific bodies (e.g. PCI Security Standards Council). This ensures assessments are conducted with technical competence, impartiality, and in line with best practices. - Integrate Findings into Remediation Vulnerabilities identified during assessments should be addressed through established remediation processes, as outlined in control ID.IM-03.3. - Support Readiness and Maturity Evaluation Assessment results should inform organisational readiness and performance levels (e.g. CyFun® maturity), guiding targeted improvements.

notation

A notation, also known as classification code, is a string of characters such as "T58.5" or "303.4833" used to uniquely identify a concept within the scope of a given concept scheme.

  • External link
  • Internal link

ID.IM-03.9

alternative label

skos:prefLabel, skos:altLabel and skos:hiddenLabel are pairwise disjoint properties.

  • External link
  • Internal link

Specialised security assessments

preferred label

A resource has no more than one value of skos:prefLabel per language tag, and no more than one value of skos:prefLabel without language tag.

  • External link
  • Internal link

The organisation shall conduct specialised assessments including in-depth monitoring, vulnerability scanning, malicious user testing, insider threat assessment, performance/ load testing, and verification and validation testing on the organisation's critical systems.

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ManagementAspects

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_delta_IMPORTANT_to_ESSENTIAL

  • External link
  • Internal link

is in scheme

Relates a resource (for example a concept) to a concept scheme in which it is included.

  • External link
  • Internal link

http://cyfun.data.gift/data/CyFun2025_ESSENTIAL

  • External link
  • Internal link

http://cyfun.data.gift/ontology#level

  • External link
  • Internal link

http://cyfun.data.gift/data/level_ESSENTIAL

  • External link
  • Internal link

triple count

The number of triples associated with the subject.

  • External link
  • Internal link

18

in dataset

Specifies the dataset the subject is part of.

  • External link
  • Internal link

http://data.gift/d/datasets/69E8863AA6CE46D9ACD13109

  • External link
  • Internal link

Resultaten 1 - 20 of 20

References

Inverse links to the subject.

Property Subject

http://cyfun.data.gift/ontology#hasRequirement

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_ID.IM-03

  • External link
  • Internal link

has narrower

Relates a concept to a concept that is more specific in meaning.

  • External link
  • Internal link

http://cyfun.data.gift/data/subcategory_ID.IM-03

  • External link
  • Internal link

Resultaten 1 - 1 of 1

© 2024 redpencil.io. All rights reserved.