NIST CSF Functions: Protect (PR), Identify (ID)
To establish ethical standards for handling information, technology resources, and business relationships in accordance with cybersecurity best practices.
Applies to all employees, contractors, and business partners with access to company information and systems.
- Maintain accuracy and completeness of business information
- Report data quality issues and security vulnerabilities promptly
- Do not deliberately alter, delete, or misrepresent information
- Protect intellectual property and proprietary information
- Respect confidentiality of customer, employee, and business information
- Access information only as required for job responsibilities
- Protect privacy rights and comply with data protection regulations
- Report privacy breaches or unauthorized access immediately
- Disclose potential conflicts that could affect cybersecurity decisions
- Avoid situations where personal interests conflict with company security
- Do not use company information for personal gain
- Report suspected insider threats or security policy violations
- Ensure vendors meet company cybersecurity standards
- Protect company information when shared with authorized third parties
- Report vendor security incidents or policy violations
- Maintain professional relationships that support security objectives
- Use technology resources efficiently and responsibly
- Respect intellectual property rights and software licensing
- Report security vulnerabilities through appropriate channels
- Maintain professional competence in cybersecurity awareness
- Do not engage in deceptive practices to obtain information or access
- Report attempts by others to manipulate or coerce information disclosure
- Verify identity before providing sensitive information or access
- Educate colleagues about social engineering tactics
- Report ethical violations and security incidents promptly
- Use established reporting channels and procedures
- Cooperate with investigations while protecting sensitive information
- Support a culture of transparency and continuous improvement
- Participate in required ethics and cybersecurity training
- Stay informed about evolving security threats and best practices
- Share knowledge and support colleagues' security awareness
- Lead by example in demonstrating ethical behavior
Violations of this policy — including misuse of confidential information, undisclosed conflicts of interest, engaging in prohibited activities, or failure to report known violations — may result in disciplinary action up to and including termination and potential legal action. All violations must be reported to [Security Officer].
- NIST CSF 2.0: GV.PO (Governance), PR.AA (Access Control), PR.AT (Awareness and Training), PR.DS (Data Security)
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | [Date] | [Security Officer] | Initial release |