Overview
The NIST Cybersecurity Framework 2.0 organises cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. It is a risk-based framework an organisation uses to structure its whole security programme, so much of it describes organisational practice rather than product features. A product contributes most to Identify, Protect, Detect, and Recover, and can assist Respond through automated actions, by supplying the technical capabilities those functions rely on. Govern remains an organisational function your team owns.
Key requirements
- Identify
- Maintain an inventory of assets and data and understand the associated risk.
- Protect
- Apply safeguards such as access control, data security, and resilience.
- Detect
- Find anomalies and security-relevant events.
- Recover
- Restore capabilities and data after an incident.
How ControlBird aligns
- Identify
- The hierarchical entity model is a live, typed inventory of every device, point, and asset in the system, which gives the Identify function an accurate picture of what exists and how it is connected.
- Protect
- Identity through native accounts, LDAP and Active Directory, or OAuth 2.0; role- and attribute-based access control enforced in the data layer, granular to the entity, field, and branch level with conditions evaluated at access time; TLS in transit with a built-in Certificate Manager; and multi-node resilience. Encryption at rest and multi-factor authentication sit with your disk encryption and identity provider respectively.
- Detect
- The alarm system surfaces abnormal conditions in real time, and you can configure rule chains and scripts to watch for security-relevant conditions, such as repeated failed logins, account lockouts, or unexpected changes, and raise an alarm when they occur. Every field write is attributed to the authenticated user and can be retained as a queryable record of who changed what and when, with service and protocol logs alongside it. ControlBird is not a packaged SIEM, so for correlation across other systems forward this data to yours.
- Recover
- Point-in-time snapshots, write-ahead-log replay, and full per-node replicas let the system restore state and rejoin after a failure.
- Respond is shared; Govern stays with you
- Govern is organisational: the strategy, roles, and risk decisions belong to your team. Respond is shared. Your incident-response process is yours to run, while rule chains and scripts can carry out automated responses when a condition is met, such as raising an alarm, notifying an operator, or driving a control point. ControlBird supplies the technical capabilities the other functions rely on, and using the framework does not imply certification.
Need this for a tender?
We can provide deployment-specific detail and supporting documentation for procurement and security reviews.