FR

KSI · Key Security Indicators

Key Security Indicators

Outcome-based security objectives a provider must be able to demonstrate. Each indicator maps to the NIST SP 800-53 controls that substantiate it.

KSI-CED

Cybersecurity Education

1 indicators

Reviewing All Training

KSI-CED-RAT

The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.

KSI-CMT

Change Management

4 indicators
KSI-CNA

Cloud Native Architecture

8 indicators

Defining Functionality and Privileges

KSI-CNA-DFP

The functionality and privileges for infrastructure and services are strictly defined.

NIST 800-53 controls

KSI-IAM

Identity and Access Management

6 indicators
KSI-INR

Incident Response

3 indicators

Generating After Action Reports

KSI-INR-AAR

Incident after action reports are generated and lessons learned are persistently incorporated.

NIST 800-53 controls

KSI-MLA

Monitoring, Logging, and Auditing

5 indicators
KSI-PIY

Policy and Inventory

5 indicators

Reviewing Executive Support

KSI-PIY-RES

Executive support for achieving the provider's security goals is persistently reviewed and demonstrated.

Reviewing Vulnerability Disclosures

KSI-PIY-RVD

The effectiveness of the provider's vulnerability disclosure program is persistently reviewed.

NIST 800-53 controls

KSI-RPL

Recovery Planning

4 indicators

Reviewing Recovery Objectives

KSI-RPL-RRO

The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities.

NIST 800-53 controls

KSI-SCR

Supply Chain Risk

2 indicators
KSI-SVC

Service Configuration

8 indicators