More rigorous cybersecurity controls are implemented for higher priority assets
Context and Guidance: Assets designated as higher priority through the prioritisation process in ASSET-1c likely pose a greater risk to the function or process sensitive data and should be subject to more rigorous cybersecurity controls. ARCHITECTURE-1c notes that a cybersecurity architecture would be in alignment with additional security objectives for higher priority assets. Examples of more rigorous cybersecurity controls include enhanced monitoring of access, additional authentication factors, or a change management process with additional testing and approvals.
Related Practices • Input From: Implementing ASSET-1c provides input that may be useful for implementing this practice. • Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: ARCHITECTURE-3a, ARCHITECTURE-3b, ARCHITECTURE-3c, ARCHITECTURE-3d, ARCHITECTURE-3h, ARCHITECTURE-3k.