ID.IM: Improvement
Category is new to this version of the framework and incorporates the following items from the previous version: PR.IP-7: Protection processes are improved, DE.DP-5: Detection processes are continuously improved, RS.IM: Improvements, RC.IM: Improvements.
Description
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
Framework Subcategories
ID.IM-01: Improvements are identified from evaluations
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.IM-02: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.IM-03: Improvements are identified from execution of operational processes, procedures, and activities
[csf.tools Note: Subcategories do not have detailed descriptions.]
ID.IM-04: Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved
[csf.tools Note: Subcategories do not have detailed descriptions.]