Capability Index
OCDF
Every capability in the framework, with the document that defines it and the
lowest implementation tier that should adopt it. The framework
addresses capabilities by ID throughout, so this is the page to come back to
whenever a reference like PR-7 or DE-4 appears and you want the detail.
Tier column: E Essential, S Standard, A Advanced. Higher tiers include everything below them, so an S-tier CDC adopts the E rows too. On the website, filter by function or by your tier to see just what applies to you.
| ID | Capability | Function | Tier |
|---|---|---|---|
| GV-1 | CDC charter & mandate | GOVERN | E |
| GV-2 | Risk management integration | GOVERN | S |
| GV-3 | Policy framework | GOVERN | E |
| GV-4 | Roles & accountability | GOVERN | E |
| GV-5 | Budget & resourcing governance | GOVERN | S |
| GV-6 | Supply chain risk governance | GOVERN | S |
| GV-7 | Oversight & reporting | GOVERN | E |
| ID-1 | Asset inventory | IDENTIFY | E |
| ID-2 | Data classification | IDENTIFY | S |
| ID-3 | Crown-jewel analysis | IDENTIFY | E |
| ID-4 | Vulnerability identification | IDENTIFY | E |
| ID-5 | Threat landscape & intelligence | IDENTIFY | S |
| ID-6 | Risk assessment | IDENTIFY | S |
| ID-7 | Improvement identification | IDENTIFY | S |
| PR-1 | Identity & access management | PROTECT | E |
| PR-2 | Awareness & training | PROTECT | E |
| PR-3 | Data security | PROTECT | S |
| PR-4 | Platform hardening & secure configuration | PROTECT | S |
| PR-5 | Vulnerability remediation & patching | PROTECT | E |
| PR-6 | Network security & segmentation | PROTECT | S |
| PR-7 | Resilient technology infrastructure | PROTECT | E |
| PR-8 | Secure development & change | PROTECT | A |
| PR-9 | Email & web protections | PROTECT | E |
| DE-1 | Log collection & management | DETECT | E |
| DE-2 | Detection engineering | DETECT | S |
| DE-3 | Alert triage & analysis | DETECT | E |
| DE-4 | Coverage assessment | DETECT | S |
| DE-5 | Threat hunting | DETECT | A |
| DE-6 | Detection validation | DETECT | A |
| DE-7 | Anomaly & integrity monitoring | DETECT | S |
| RS-1 | Incident response plan | RESPOND | E |
| RS-2 | Playbooks | RESPOND | E |
| RS-3 | Incident analysis & forensics | RESPOND | S |
| RS-4 | Containment & eradication | RESPOND | S |
| RS-5 | Incident reporting & communication | RESPOND | E |
| RS-6 | Crisis management interface | RESPOND | A |
| RS-7 | Exercises | RESPOND | S |
| RC-1 | Recovery planning | RECOVER | E |
| RC-2 | Trusted restoration | RECOVER | S |
| RC-3 | Recovery execution & verification | RECOVER | S |
| RC-4 | Recovery communication | RECOVER | E |
| RC-5 | Lessons learned & improvement loop | RECOVER | E |
| RC-6 | Business continuity integration | RECOVER | S |
Related indexes
- Reading guide for the order the documents are meant to be read in.
- Implementation tiers for what E, S and A mean and how to pick yours.
- Maturity model for how well you run the capabilities you have adopted.
- CIS Controls crosswalk to map these capabilities onto CIS Controls v8.1.
Open CDC Framework, licensed CC BY 4.0. Generated from the capability tables in the six function documents (Govern through Recover).