[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-168401-en":3,"doc-seo-168401-105":29,"detail-sidebar-cat-1-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":12,"language":21,"language_code":22,"site_id":23,"html_lang":22,"table_of_contents":24,"faqs":25,"seo_title":26,"seo_description":15,"update_tm":27,"read_time":28},168401,7971461741311,"Ophelia","https://ap-avatar.wpscdn.com/avatar/74000253aff267980c6?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779345379180704826",1,17,"Forms","Cybersecurity Plan Template V2","A cybersecurity plan template that provides a policy foundation and structure for protecting organizational data and managing cyber risks. The template explains how to tailor placeholders for the organization, remove color-coded guidance (BLUE/green examples and PURPLE references), and adapt a framework-based plan. It aligns policy sections—Purpose, Scope, Plan Framework, and the Core Functions Identify/Protect/Detect/Respond/Recover—with the NIST Cybersecurity Framework (CSF), emphasizing minimum policy content and leaving procedures for later development.","How to use this document\nThe template beginning on page 2 is incomplete and cannot be used without modifications based on the specifics of your organization. Each section is broken into two or three subsections.\nPrinciples (in BLUE)\nPolicy examples (in GREEN)\nReferences (where available, in PURPLE)\nThe [ORG] references should be replaced with the name or synonym of your organization.\nAll BLUE text should be removed from your final policy. These guidelines are provided to help you think through each section.\nAll GREEN text should be tailored to your organization if you intend to use the example, or removed if you do not.\nPURPLE text should be removed from your final policy. The references are for your use and are not required in each section. However, it may be useful to acknowledge somewhere in your document where you obtained the ideas or text for your policy.\nThis template has eight sections: Purpose, Scope, Plan Framework, and five sections — Identify, Protect, Detect, Respond, and Recover — that align to the Core Functions outlined in the National Institute for Standards and Technology (NIST) Cybersecurity Framework (CSF). You will need to adapt this document to a framework that works for your environment.\nThis document covers only the minimum needed in a cybersecurity policy. It is a starting point for you to frame your thinking and organize your priorities.\nThis document also is not a set of procedures. A policy defines what is important while procedures define how to carry out the policy. All procedures are left for you to develop.\nWe hope this document is helpful as your organization starts down the cybersecurity journey.\nBest of luck,\nMatt Sievers, Matthew Schroeder, Alexander Romero, and Liv Erickson\nFellows, Winter 2020\n[ORG] Cybersecurity Plan\nPurpose\nPrinciple: Publicly state why cybersecurity is important to your organization.\nPolicy Example:\nOur cybersecurity plan is one of the primary mechanisms we have to show our customers and partners that we take protecting their data and our shared business seriously. This plan reviews our operating environment, identifies key roles, and documents our policies for protecting and responding to potential cybersecurity risks.\nScope\nPrinciple: Define how the policy applies to the organization. This includes:\nWho: which personnel?\nWhat: which equipment, networks, or processes?\nWhen: are there any time or status restrictions?\nWhere: which locations?\nExceptions: what are the situations where the policies do not apply?\nPolicy Example:\nThis policy applies to all employees and contractors accessing any [ORG] system, network, and data, at any time, from any location, whether from [ORG’s] or personal devices. There are no exceptions to this policy. Deviations must be approved by [ORG’s] Chief Information Security Officer (CISO).\n(signatures and titles)\nApproved by / Date\t\tLast Modified by / Date\n\u000f\nPlan Framework\nPrinciple: A strong cybersecurity plan should be based on a well-established framework from the expert community. Identify the framework your plan uses and how it is adapted for your business.\nPolicy Example:\nWe are using the NIST Cybersecurity Framework (CSF) as the foundation for this cybersecurity plan. As described in NIST’s document, “Framework for Improving Critical Infrastructure Cybersecurity,” the CSF is an internationally recognized standard that “enables organizations – regardless of size, degree of cybersecurity risk, or cybersecurity sophistication – to apply the principles and best practices of risk management to improving security and resilience.”\nThe CSF categorizes practices into five Core Functions that are divided into categories and subcategories. We have adapted it to our business by focusing on 12 subcategories —spread across five Core Functions — that we believe will have the most impact on our cybersecurity posture. The outline below shows the core functions and associated subcategories. For more information on the NIST CSF, see \u0013 HYPERLINK \"https://www","cbCaihxklYbsUSph","https://ap.wps.com/l/cbCaihxklYbsUSph","docx",1829169,"English","en",105,"# Purpose\n## Principle\n## Policy example\n# Scope\n## Principle\n## Policy example\n# Plan Framework\n## Principle\n## NIST CSF mapping\n# Identify\n## Legal and regulatory requirements\n# Protect\n## Account management and authentication\n## User training and data backups\n## Vulnerability management\n# Detect\n## Vulnerability management execution\n# Respond\n## Incident response plan execution\n# Recover\n## Incident recovery plan execution\n# References","[{\"question\":\"How should an organization customize this cybersecurity plan template?\",\"answer\":\"Replace [ORG] placeholders with the organization name or synonym. Remove BLUE guidance from the final policy, tailor GREEN policy examples to the organization or delete them if not used, and remove PURPLE references unless you want to acknowledge idea sources.\"},{\"question\":\"Which framework does the template align the plan to?\",\"answer\":\"It uses the National Institute for Standards and Technology (NIST) Cybersecurity Framework (CSF) and maps five Core Functions—Identify, Protect, Detect, Respond, Recover—to the plan sections.\"},{\"question\":\"What is the difference between the template’s policy and procedures?\",\"answer\":\"The template is a policy foundation defining what is important. Procedures that describe how to carry out the policy must be developed separately by the organization.\"}]","Cybersecurity Plan Template V2 | DOCX",1788230679,6,{"code":4,"msg":30,"data":31},"ok",{"site_id":23,"language":22,"slug":32,"title":14,"keywords":33,"description":15,"schema_data":34,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":27},"cybersecurity-plan-template-v2","",{"@graph":35,"@context":84},[36,53,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/template/","Template",2,{"item":48,"name":13,"@type":42,"position":49},"https://docshare.wps.com/template/forms/",3,{"item":51,"name":14,"@type":42,"position":52},"https://docshare.wps.com/template/cybersecurity-plan-template-v2/168401/",4,{"url":51,"name":14,"@type":54,"author":55,"headline":14,"publisher":57,"fileFormat":60,"inLanguage":22,"description":15,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-01",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"How should an organization customize this cybersecurity plan template?","Question",{"text":74,"@type":75},"Replace [ORG] placeholders with the organization name or synonym. Remove BLUE guidance from the final policy, tailor GREEN policy examples to the organization or delete them if not used, and remove PURPLE references unless you want to acknowledge idea sources.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"Which framework does the template align the plan to?",{"text":79,"@type":75},"It uses the National Institute for Standards and Technology (NIST) Cybersecurity Framework (CSF) and maps five Core Functions—Identify, Protect, Detect, Respond, Recover—to the plan sections.",{"name":81,"@type":72,"acceptedAnswer":82},"What is the difference between the template’s policy and procedures?",{"text":83,"@type":75},"The template is a policy foundation defining what is important. Procedures that describe how to carry out the policy must be developed separately by the organization.","https://schema.org",{"og:url":51,"og:type":86,"og:title":14,"og:site_name":58,"og:description":15},"article",{"robots":88,"canonical":51},"index,follow",{"doc_id":7,"site_id":23},{"code":4,"msg":5,"data":91},[92,97,102,107,112,117,120,125,130],{"id":93,"doc_module":11,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},11,"Presentations",90,"presentations",{"id":98,"doc_module":11,"doc_module_name":45,"category_name":99,"show_sort_weight":100,"slug":101},12,"Resumes",80,"resumes",{"id":103,"doc_module":11,"doc_module_name":45,"category_name":104,"show_sort_weight":105,"slug":106},14,"Invoices",70,"invoices",{"id":108,"doc_module":11,"doc_module_name":45,"category_name":109,"show_sort_weight":110,"slug":111},15,"Posters",60,"posters",{"id":113,"doc_module":11,"doc_module_name":45,"category_name":114,"show_sort_weight":115,"slug":116},16,"Social Media",50,"social-media",{"id":12,"doc_module":11,"doc_module_name":45,"category_name":13,"show_sort_weight":118,"slug":119},40,"forms",{"id":121,"doc_module":11,"doc_module_name":45,"category_name":122,"show_sort_weight":123,"slug":124},18,"Letters",30,"letters",{"id":126,"doc_module":11,"doc_module_name":45,"category_name":127,"show_sort_weight":128,"slug":129},21,"Paper Templates",5,"papers-templates",{"id":131,"doc_module":11,"doc_module_name":45,"category_name":132,"show_sort_weight":4,"slug":133},158,"General","general-158"]