Views: 9
Framework basis: CyberFundamentals (CyFUN) — aligned with NIST CSF and NIS2 objectives
Duration: ~9–12 months initial cycle (Depends on Organizations)
Approach: Risk-based, phased rollout with evidence collection from day one
🔹 Phase 1 — Initiation & Scoping
| Objective | Key Tasks | Deliverables | Owner |
|---|---|---|---|
| Leadership commitment | • Present CyFUN overview to management • Define goals: compliance (NIS2), resilience, audit readiness | Management buy-in memo | CISO / Security Manager |
| Governance setup | • Assign CyFUN implementation sponsor • Create Cyber Governance Committee (IT, HR, Legal, Ops) • Define reporting cadence (monthly) | Governance charter | CISO / PMO |
| Scope definition | • Define business units, systems, and suppliers within scope • Identify critical assets & processes (e.g., customer portal, NOC systems, ERP, email) | Scope document, asset inventory draft | IT + Business |
| Regulatory mapping | • Map NIS2, GDPR, sector laws • Identify overlaps with ISO 27001, CIS Controls | Compliance matrix | Risk Officer / Compliance |
🔹 Phase 2 — Assurance Level & Risk Assessment
| Objective | Key Tasks | Deliverables | Owner |
|---|---|---|---|
| Determine assurance level | • Use CyFUN Selection Tool (from CCB toolbox) • Evaluate sector, criticality, impact, threat landscape | Selected level: Basic / Important / Essential | Security Lead |
| Baseline risk assessment | • Identify threats, vulnerabilities, likelihood, and impact • Apply simple risk matrix (5×5) • Include supply-chain dependencies | Initial Risk Register | Risk Officer |
| Management validation | • Review & approve level and assumptions • Record rationale for chosen level | Risk Review Meeting Minutes | Management Board |
🔹 Phase 3 — Gap Assessment & Planning
| Objective | Key Tasks | Deliverables | Owner |
|---|---|---|---|
| Self-assessment | • Complete CyFUN Self-Assessment Excel Tool for chosen level • Score each function (Govern, Identify, Protect, Detect, Respond, Recover) | Self-assessment report (scores, graphs) | Security Team |
| Gap analysis | • Map missing controls to existing frameworks (ISO, CIS, NIST) • Rank by risk, cost, feasibility | Gap register | Security Manager |
| Roadmap planning | • Define projects for each major function • Assign owners, budgets, milestones | CyFUN Roadmap v1.0 | PMO / Management |
🔹 Phase 4 — Policy & Process Development
| Function | Key Controls to Implement | Deliverables |
|---|---|---|
| Govern / Identify | • Cyber Policy & Roles • Asset classification policy • Supplier security checklist | Policy set v1, asset register |
| Protect | • Access control & MFA • Endpoint & patch management • Backup strategy | IAM policy, patch reports, backup test logs |
| Detect | • Centralized logging (SIEM) • Baseline monitoring rules | SIEM deployment plan |
| Respond | • Incident Response (IR) plan • Roles & escalation matrix • IR training | IR playbook |
| Recover | • DR plan • Recovery testing schedule | DR test results, recovery RTO/RPO metrics |
💡 Tip: Use CyFUN Toolbox templates from Safeonweb@Work to speed up documentation.
🔹 Phase 5 — Implementation & Awareness
| Objective | Key Tasks | Deliverables | Owner |
|---|---|---|---|
| Technical rollout | • Deploy MFA, patch automation, EDR, SIEM, encrypted backups | Control implementation logs | IT Security |
| Employee awareness | • Conduct phishing simulation & security awareness training • Update onboarding materials | Training records, campaign metrics | HR + Security |
| Supplier engagement | • Send security questionnaire to key vendors • Add CyFUN clauses in contracts | Vendor compliance tracker | Procurement |
| Incident management | • Conduct IR tabletop exercise • Record metrics (MTTD/MTTR) | IR test report | SOC / Security Lead |
🔹 Phase 6 — Internal Audit & Certification Prep
| Objective | Key Tasks | Deliverables |
|---|---|---|
| Internal audit | • Audit all CyFUN domains using toolbox checklist • Collect evidence (logs, configs, meeting minutes, reports) | Internal audit report |
| Remediation | • Address non-conformities • Update documentation and control evidence | Updated gap register |
| Certification prep | • Engage a Conformity Assessment Body (CAB) • Pre-audit briefing, document submission | CAB engagement letter |
🔹 Phase 7 — Certification & Continuous Improvement
| Objective | Key Tasks | Deliverables |
|---|---|---|
| External assessment | • Undergo CAB audit for selected level • Provide all evidence sets | Audit report, CyFUN label |
| Continuous improvement | • Establish quarterly risk reviews • Set KPIs: % systems patched, MFA coverage, phishing success rate • Plan next-level upgrade (e.g. Important → Essential) | KPI dashboard, CyFUN Maturity Plan 2.0 |
🧩 Supporting Artifacts Checklist
✅ CyFUN Selection Tool (Excel)
✅ CyFUN Self-Assessment Tool
✅ Cybersecurity Policy (aligned with functions)
✅ Risk Register
✅ Governance Charter & Roles Matrix
✅ Asset Inventory & Classification
✅ Incident Response Plan
✅ Backup & Recovery Plan
✅ Internal Audit Report
✅ Evidence Pack for CAB

