ID.BE: Business Environment
Category is withdrawn in the next version of this framework and incorporated into: GV.OC: Organizational Context.
Description
The organization’s mission, objectives, stakeholders, and activities are understood and prioritized; this information is used to inform cybersecurity roles, responsibilities, and risk management decisions.
Framework Subcategories
ID.BE-1: The organization’s role in the supply chain is identified and communicated
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.BE-2: The organization’s place in critical infrastructure and its industry sector is identified and communicated
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.BE-3: Priorities for organizational mission, objectives, and activities are established and communicated
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.BE-4: Dependencies and critical functions for delivery of critical services are established
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.BE-5: Resilience requirements to support delivery of critical services are established for all operating states (e.g. under duress/attack, during recovery, normal operations)
[csf.tools Note: Subcategories do not have detailed descriptions.]