PM-16 Threat Awareness Program

Program Management

Description

Implement a threat awareness program that includes a cross-organization information-sharing capability that can influence the development of the system and security architectures, selection of security solutions, monitoring, threat intelligence, and impact of threats on the risk to organizational operations and assets, individuals, other organizations, and the Nation.

Supplemental Guidance

Because of the constantly changing and increasing sophistication of adversaries, especially the advanced persistent threat (APT), it may be more likely that adversaries can successfully breach or compromise organizational systems. One of the best techniques to address this concern is for organizations to share threat information, including threat events (i.e., tactics, techniques, and procedures) that organizations have experienced, mitigations that organizations have found are effective against certain types of threats, and threat intelligence (i.e., indications and warnings about threats). Threat information sharing may be bilateral or multilateral.

Changes from Rev 4

Cross-organization information-sharing capability added. Discussion expanded for APT awareness.

Compliance Mappings

ISO 27001:2022

7.2A.5.6A.5.7

ISO 27002:2022

5.65.7

NIST CSF 2.0

DE.AE-07GV.RM-05ID.RA-02ID.RA-03RS.CO-03

CSA CCM v4

GRC-08

CSA AICM v1

GRC-08GRC-15

NIS2 Directive

Art. 29

MAS TRM

12

EU DORA

Art.13(1)Art.45(1)

BIO2

5.65.7

RBI CSF

Annex1.13

HKMA TM-E-1

TME1.7.4TME1.7.5

MLPS 2.0

8.1.7.2

DNB Good Practice

DNB.3.1

EU CRA

CRA.II.5

SWIFT CSCF

SWIFT.7.4A

SAMA CSF

3.6

NCA ECC

1-102-13

CBB TM

TM-11TM-12TM-13TM-3

CBUAE

CR-3

CBE CSF

CD-1CTO-9

SA JS2

JS2-7.3JS2-7.6

CBN CSF

Part3.5Part4

BoG CISD

CISD-VII

BoM CTRM

2.14.15.3

IOSCO Cyber Resilience

DET-3ID-3LE-3RR-5SA-1SA-2

BCBS 239

Principle 14

CPMI-IOSCO PFMI

CG.DECG.SACG.TE

FFIEC IS

I.CII.AII.A.1III.A

NYDFS 500

500.10500.9

ECB CROE

CROE.2.4CROE.2.6.2CROE.2.7.1CROE.2.7.2CROE.2.8.2

SEBI CSCRF

DE.DPID.RARS.COSOC

BOT Cyber Resilience

Ch3.1Ch4.1Ch7.1Ch8.1

DOE C2M2 v2.1

THREAT

CBEST

CBEST.2

TIBER-EU

TIBER.GTLTIBER.TTI

Lloyd's Minimum Standards

CRM.2

NAIC Insurance Data Security

4A

FDA Cybersecurity Guidance

MON-1MON-3TM-1

NHS DSPT

NDG-6.3NDG-9.8

Basel SCO60

SCO60.73SCO60.84