News: 1709059514

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NIST updates Cybersecurity Framework after a decade of lessons

(2024/02/27)


After ten years operating under the original model, and two years working to revise it, the National Institute of Standards and Technology (NIST) has released version 2.0 of its Cybersecurity Framework (CSF).

Unlike the original, which was designed with critical infrastructure sectors in mind, CSF 2.0's scope has been expanded to suitable security tips for organizations in any sector and of any size "regardless of their degree of cybersecurity sophistication," NIST [1]said .

For those unfamiliar with the CSF, it's a set of best practices and recommendations from NIST to help organizations improve their cybersecurity posture and raise organizational awareness of how to operate safely.

[2]

Along with broadening its scope, [3]the new CSF [PDF] goes beyond being a best practices recommendation document, said NIST director Laurie Locascio.

[4]

[5]

CSF 2.0 "is about a suite of resources that can be customized and used individually or in combination over time as an organization's cybersecurity needs change and its capabilities evolve," Locascio said. According to NIST, CSF 2.0 was written with President Biden's National Cybersecurity Strategy, adopted in [6]early 2023 , in mind.

New resources in CSF 2.0 include [7]quick-start guides for different types of organizations and use cases (e.g. enterprises, SMBs, cyber supply chain risk management etc.), implementation examples, a mapping [8]catalog where companies can plug in data to see how well they're already conforming with the CSF, [9]reference tools , and [10]more .

[11]

Kevin Stine, NIST's applied cybersecurity division chief, said the new tools were introduced after [12]several years of work with stakeholders, as well as incorporating lessons learned from a decade of security challenges.

"This update aims to make the framework even more relevant to a wider swath of users in the United States and abroad," Stine said. The CSF is used widely outside the US, and has been translated into 13 languages through the efforts of volunteers. NIST said it expects CSF 2.0 to similarly be translated for use in non-English speaking countries.

The biggest change is a new core risk management function

Those who've perused or used the original (and 1.1 version) of NIST's CSF are likely familiar with its five core functions of identify, protect, detect, respond, and recover, named for high-level summaries of what each function should contribute to a good security posture.

What's been missing from that group of five is the new sixth function – govern – which has been added in CSF 2.0.

According to NIST, an organization properly implementing the governance function is one whose "cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored."

[13]

In other words, governance is all about elevating the other five functions beyond the security team and into the broader structure of an organization.

[14]We're just shouting into the void, says US watchdog offering cybersecurity advice

[15]Biden asks Coast Guard to create an infosec port in a stormy sea of cyber threats

[16]Uncle Sam tells hospitals: Meet security standards or no federal dollars for you

[17]IT suppliers hacked off with Uncle Sam's demands in aftermath of cyberattacks

"The govern function provides outcomes to inform what an organization may do to achieve and prioritize the outcomes of the other five functions in the context of its mission and stakeholder expectations," NIST's CSF 2.0 document states. "Governance activities are critical for incorporating cybersecurity into an organization's broader enterprise risk management strategy."

That doesn't mean governance comes before the rest of the functions – NIST makes clear that all six "should be addressed concurrently."

"Actions that support govern, identify, protect, and detect should all happen continuously, and actions that support respond and recover should be ready at all times and happen when cybersecurity incidents occur," NIST said.

NIST said it views CSF 2.0 as a living document, and it plans to continue upping available resources to make the framework more useful. That said, NIST won't be able to do that without feedback from the security community, and is inviting people to contact them in the name of better cybersecurity.

"As users customize the CSF, we hope they will share their examples and successes, because that will allow us to amplify their experiences and help others," Stine said. "That will help organizations, sectors and even entire nations better understand and manage their cybersecurity risk." ®

Get our [18]Tech Resources



[1] https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zd5pmKkj@KBlRikOhxI85AAAAQQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.nist.gov/cyberframework

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zd5pmKkj@KBlRikOhxI85AAAAQQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zd5pmKkj@KBlRikOhxI85AAAAQQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/03/03/us_national_cybersecurity_strategy/

[7] https://www.nist.gov/quick-start-guides

[8] https://csrc.nist.gov/projects/olir/informative-reference-catalog#/

[9] https://csrc.nist.gov/Projects/Cybersecurity-Framework/Filters#/csf/filters

[10] https://csrc.nist.gov/News/2024/the-nist-csf-20-is-here

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zd5pmKkj@KBlRikOhxI85AAAAQQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://www.nist.gov/cyberframework/updating-nist-cybersecurity-framework-journey-csf-20

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zd5pmKkj@KBlRikOhxI85AAAAQQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/2023/01/24/gao_cybersecurity_recommendations/

[15] https://www.theregister.com/2024/02/21/uscg_cybersecurity_powers/

[16] https://www.theregister.com/2024/01/10/us_hospitals_security_rules/

[17] https://www.theregister.com/2024/02/08/us_tech_industry_changes/

[18] https://whitepapers.theregister.com/



Finally, they've twigged

Mike 137

" What's been missing from that group of five is the new sixth function – govern – which has been added in CSF 2.0. "

It should have been obvious all this time that unless 'security' is an integral part of corporate governance it's bound to fail, if for no other reason that that it will not be considered a high priority by the executive. So it will remain a disregarded and under-resourced afterthought -- what I have for years called "stick-on security". This has widely been the fate of ISO/IEC 27001. It's actually quite an good standard, but in most certified organisations I've attended getting the cert is the priority (as it opens the door to lucrative contracts). The cert however commonly signifies nothing except that a convincing paper trial has been established. It very seldom informs operational security to any significant degree.

I feel better already /s

Anonymous Coward

“ [1]The CSF fosters bidirectional information flow .. between executives .. and managers who manage specific cybersecurity risks that could affect the achievement of those priorities .. The left side of the figure indicates the importance of practitioners sharing their updates, insights, and concerns with managers and executives. ”

[1] https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf

Brief History Of Linux (#21)
The GNU Project

Meet Richard M. Stallman, an MIT hacker who would found the GNU Project
and create Emacs, the operating-system-disguised-as-a-text-editor. RMS,
the first member of the Three Initials Club (joined by ESR and JWZ),
experienced such frustration with software wrapped in arcane license
agreements that he embarked on the GNU Project to produce free software.

His journey began when he noticed this fine print for a printer driver:

You do not own this software. You own a license to use one copy of this
software, a license that we can revoke at any time for any reason
whatsoever without a refund. You may not copy, distribute, alter,
disassemble, or hack the software. The source code is locked away in a
vault in Cleveland. If you say anything negative about this software
you will be in violation of this license and required to forfeit your
soul and/or first born child to us.

The harsh wording of the license shocked RMS. The computer industry was in
it's infancy, which could only mean it was going to get much, much worse.