Activity-in-Diagram: Define Security Capabilities
CreatorTim Ramey
Description
Define security capabilities that align with the system performance capabilities. One way of accomplishing this is to understand how a cyber-attack could impact the mission objectives if the data required to execute the mission objectives became altered, unavailable, or exploited in advance of mission execurtion. Examples of security capabilities are data security and system resilience and survivability.
Define the technical measures or attributes associated with each of the security capabilities, such as prevent, mitigate, and recover. Prevent actions protect the system's functions from the most likely and greatest risk of cyber threats. Mitigate actions detect and respond to cyber-attacks, enabling system cyber survivability and operational resilience. Recover actions ensure minimum cybersecurity capability available to recover from cyber-attack and enable the system to resore full functionality quickly.
Owning Diagram A121: Develop the Initial DEF
Input
MBCRA (attack surface)
Output
security capabilities
Control
system performance capabilities
Notes
Muddled