CyFUN Implementation: A Practical Roadmap

CyFUN Implementation: A Practical Roadmap

Views: 9

Framework basis: CyberFundamentals (CyFUN) — aligned with NIST CSF and NIS2 objectives
Duration: ~9–12 months initial cycle (Depends on Organizations)
Approach: Risk-based, phased rollout with evidence collection from day one


🔹 Phase 1 — Initiation & Scoping

ObjectiveKey TasksDeliverablesOwner
Leadership commitment• Present CyFUN overview to management
• Define goals: compliance (NIS2), resilience, audit readiness
Management buy-in memoCISO / Security Manager
Governance setup• Assign CyFUN implementation sponsor
• Create Cyber Governance Committee (IT, HR, Legal, Ops)
• Define reporting cadence (monthly)
Governance charterCISO / PMO
Scope definition• Define business units, systems, and suppliers within scope
• Identify critical assets & processes (e.g., customer portal, NOC systems, ERP, email)
Scope document, asset inventory draftIT + Business
Regulatory mapping• Map NIS2, GDPR, sector laws
• Identify overlaps with ISO 27001, CIS Controls
Compliance matrixRisk Officer / Compliance

🔹 Phase 2 — Assurance Level & Risk Assessment

ObjectiveKey TasksDeliverablesOwner
Determine assurance level• Use CyFUN Selection Tool (from CCB toolbox)
• Evaluate sector, criticality, impact, threat landscape
Selected level: Basic / Important / EssentialSecurity Lead
Baseline risk assessment• Identify threats, vulnerabilities, likelihood, and impact
• Apply simple risk matrix (5×5)
• Include supply-chain dependencies
Initial Risk RegisterRisk Officer
Management validation• Review & approve level and assumptions
• Record rationale for chosen level
Risk Review Meeting MinutesManagement Board

🔹 Phase 3 — Gap Assessment & Planning

ObjectiveKey TasksDeliverablesOwner
Self-assessment• Complete CyFUN Self-Assessment Excel Tool for chosen level
• Score each function (Govern, Identify, Protect, Detect, Respond, Recover)
Self-assessment report (scores, graphs)Security Team
Gap analysis• Map missing controls to existing frameworks (ISO, CIS, NIST)
• Rank by risk, cost, feasibility
Gap registerSecurity Manager
Roadmap planning• Define projects for each major function
• Assign owners, budgets, milestones
CyFUN Roadmap v1.0PMO / Management

🔹 Phase 4 — Policy & Process Development

FunctionKey Controls to ImplementDeliverables
Govern / Identify• Cyber Policy & Roles
• Asset classification policy
• Supplier security checklist
Policy set v1, asset register
Protect• Access control & MFA
• Endpoint & patch management
• Backup strategy
IAM policy, patch reports, backup test logs
Detect• Centralized logging (SIEM)
• Baseline monitoring rules
SIEM deployment plan
Respond• Incident Response (IR) plan
• Roles & escalation matrix
• IR training
IR playbook
Recover• DR plan
• Recovery testing schedule
DR test results, recovery RTO/RPO metrics

💡 Tip: Use CyFUN Toolbox templates from Safeonweb@Work to speed up documentation.


🔹 Phase 5 — Implementation & Awareness

ObjectiveKey TasksDeliverablesOwner
Technical rollout• Deploy MFA, patch automation, EDR, SIEM, encrypted backupsControl implementation logsIT Security
Employee awareness• Conduct phishing simulation & security awareness training
• Update onboarding materials
Training records, campaign metricsHR + Security
Supplier engagement• Send security questionnaire to key vendors
• Add CyFUN clauses in contracts
Vendor compliance trackerProcurement
Incident management• Conduct IR tabletop exercise
• Record metrics (MTTD/MTTR)
IR test reportSOC / Security Lead

🔹 Phase 6 — Internal Audit & Certification Prep

ObjectiveKey TasksDeliverables
Internal audit• Audit all CyFUN domains using toolbox checklist
• Collect evidence (logs, configs, meeting minutes, reports)
Internal audit report
Remediation• Address non-conformities
• Update documentation and control evidence
Updated gap register
Certification prep• Engage a Conformity Assessment Body (CAB)
• Pre-audit briefing, document submission
CAB engagement letter

🔹 Phase 7 — Certification & Continuous Improvement

ObjectiveKey TasksDeliverables
External assessment• Undergo CAB audit for selected level
• Provide all evidence sets
Audit report, CyFUN label
Continuous improvement• Establish quarterly risk reviews
• Set KPIs: % systems patched, MFA coverage, phishing success rate
• Plan next-level upgrade (e.g. Important → Essential)
KPI dashboard, CyFUN Maturity Plan 2.0

🧩 Supporting Artifacts Checklist

✅ CyFUN Selection Tool (Excel)
✅ CyFUN Self-Assessment Tool
✅ Cybersecurity Policy (aligned with functions)
✅ Risk Register
✅ Governance Charter & Roles Matrix
✅ Asset Inventory & Classification
✅ Incident Response Plan
✅ Backup & Recovery Plan
✅ Internal Audit Report
✅ Evidence Pack for CAB