NIST solicits feedback on cybersecurity framework draft.

PositionEHR

In accordance with an executive order issued by President Barack Obama in February, the National Institute of Standards and Technology (NIST) has been working diligently to develop a cybersecurity framework that will provide a "prioritized, flexible, repeatable, performance-based, and cost-effective approach" to help organizations manage their cybersecurity risk.

The latest draft of the preliminary framework was discussed with industry representatives in a dedicated workshop in September. NIST was expected to release a full preliminary draft in October for public review, followed in February 2015 by the final 1.0 version.

The finished framework will guide organizations on managing cybersecurity risk in a manner similar to financial, safety, and operational risk. It will focus on supporting cybersecurity improvement using industry-known standards and best practices.

According to NIST, "The framework provides a common language and mechanism for organizations to: 1) describe current cybersecurity posture; 2) describe their target state for cybersecurity; 3) identify and prioritize opportunities for improvement within the context of risk management; 4) assess progress toward the target state; 5) foster communications among internal and external stakeholders." It is not intended to replace an existing business or cybersecurity risk management process and cybersecurity program. Instead it provides guidance for improving or for establishing a program, if necessary.

The framework, which closely resembles a maturity model, comprises three parts: the Framework Core, the Framework Implementation Tiers, and the Framework Profile.

[ILLUSTRATION OMITTED]

The Framework Core contains cybersecurity activities and references that are common across critical infrastructure sectors. The core presents standards and best practices in a manner that allows for communication and risk management across the organization...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT