Improvement (ID.IM)

The cybersecurity risk to the organization, assets, and individuals is understood by the organization

Subcategories

ID.IM-01

Improvements are identified from evaluations

ID.IM-02

Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

ID.IM-03

Improvements are identified from execution of operational processes, procedures, and activities

ID.IM-04

Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved