36 MAC Pt. 1, R. 1.10
Policy Framework
Cite as 36 Miss. Admin. Code Pt. 1, R. 1.10
Policy Framework
This policy is designed to be in alignment with security requirements recommended by the
National Institute of Standards and Technology (NIST), the National Cybersecurity and
Infrastructure Security Agency (CISA), and the Center for Internet Security (CIS). This policy
addresses the five core functions listed below.
A. Identify – Development of an organizational understanding to manage cybersecurity
risk to systems, assets, data, and capabilities.
B. Protect – Development and implementation of the appropriate safeguards to ensure
the security of SOM assets.
C. Detect – Development and implementation of the appropriate activities to identify the
occurrence of a cybersecurity event.
D. Respond – Develop and implement the appropriate activities to take action regarding
a detected cybersecurity event.
E. Recover - Develop and implement the appropriate activities to maintain plans to
mitigate and to restore critical infrastructure services that were impaired due to a
cybersecurity event.