Which of the following best describes the purpose of the Identity Management, Authentication, and Access Control (PR.AA) category in the NIST Cybersecurity Framework?
A healthcare provider is enhancing its cybersecurity policies to better protect patient information, particularly by implementing stricter access controls and auditing mechanisms to detect any unauthorized access or data manipulation. This is part of their compliance efforts with health data protection regulations. Which subcategory in the NIST Cybersecurity Framework could best guide the implementation of these stricter access controls and auditing mechanisms?
An aeronautical engineering firm works primarily with the Department of Defense and relies heavily upon semiconductors that are manufactured outside the United States. They are concerned about the risk or attack surface associated with foreign made semiconductors. Which of the following subcategories in the NIST Cybersecurity Framework covers the firm’s concern?