The security status of an organisation’s networks, information, and systems based on cyber security resources (e.g., people, hardware, software, policies) and capabilities in place to manage the defence of the organisation and to react as the situation changes.