NIST Cybersecurity Framework
The National Institute of Standards and Technology (NIST)
cybersecurity framework is a policy framework to guide users in the private
sector to assess and improve their prevention, detection, and response
abilities when it comes to cyber-attacks. It is primarily used in the United
States, however, it has been translated to many different languages and is used
by the Japanese and Israeli governments. The version 1.0 framework was
originally published in 2014 to be used by managers and operates of critical
infrastructure elements. Now, it is widely used by businesses and organizations
to assist with becoming more proactive with risk management. Version 1.1 of the
framework was drafted in 2017 and made public on April 16th, 2018.
This version included changes regarding self-assessments, interactions with
stakeholders, supply chain risk management, and the vulnerability disclosure
process.
The core material of the NIST cybersecurity framework is
divided into five main categories which are also divided into 23 subcategories.
Each subcategory contains “information resources” which references other security
documents and standards such as Control Objectives for Information and Related
Technologies (COBIT), the Council on Cybersecurity Critical Security Controls,
International Organization for Standardization (ISO), and the International
Electrotechnical Commission (IEC). These extra documents tend to require a
membership or payment to access, which has led Congress to pass bills that have
NIST create more accessible framework guides.
The main categories for the NIST framework include;
identify, protect, detect, respond, and recover. It's important to note there is
not set path for these categories. While there is a recommended workflow, it
varies depending upon the situation and the desired end results. With that
being said, it is not recommended to skip a category if it is the first time
utilizing the framework. Once it has been utilized, it can be easily modified
to target specific areas to improve an organization.
The category “identify” is defined as a way to “develop the
organizational understanding to manage cybersecurity risk to systems, assets,
data, and capabilities”. This stage revolves around identifying aspects of the
organization such as assets, risks, and possible vulnerabilities. This is made
evident when observing its six subcategories, which includes; asset management,
business environment, governance, risk assessment, risk management strategy,
and supply chain risk management. Assets management is used to identify data,
objects, personnel, or systems that are vital to daily operations or to achieve
the goals of the organization. Business environment evaluates the organization’s
mission, stakeholder involvement, and activity prioritization. Governance
involves reviewing business policies and procedures to meet legal and operation
requirements. Risk assessment is used to identify possible attacks that could
affect the system and its assets, which plays into risk management strategy
which is used to evaluate risk tolerance and methods that are currently being
used. Supply chain risk management is similar to risk management except it is
for supply chain management.
The “protect” category is define as a way to “develop and
implement the appropriate safeguards to ensure delivery of critical
infrastructure services”. This category includes six subcategories. Access
Control is used to limit access to data, facilities, or devices to improve
security and track usage and access. Awareness and training is used to evaluate
the practices of personnel to determine their level of education and knowledge
of cybersecurity practices. Data security evaluates the confidentiality,
integrity, and availability of data. Information protection processes and
procedures creates security policies and sets the scope, roles, and
responsibilities of employees and security managers. Maintenance involves the
repair of security controls. Protective technology is used to create
preventative measures in order to protect assets and information.
The “detect” category is defined as a way to “develop and
implement the appropriate activities to identify the occurrence of a cybersecurity
event” and involves three subcategories. Anomalies and events involve
monitoring for strange and unusual activity and responding to it in a timely
manner. Security continuous monitoring is a discrete way to monitor systems and
assets to identify events and to evaluate the effectiveness of security measures.
Detection processes is testing and maintaining other detection systems.
The “respond” category is defined as a way to “Develop and
implement the appropriate activities to take action regarding a detected
cybersecurity event” and contains five subcategories. A response plan should be
developed to determine what action should be taken if an event occurs.
Communication channels should be developed to create quick response times
between involved parties. The analysis subcategory involves evaluating the
attack in order to create better recovery plans, which is the next subcategory,
mitigation. Finally, improvements are made by evaluating the effectiveness of the
response plan.
Finally, the “recover” category is defined as a way to “Develop
and implement the appropriate activities to maintain plans for resilience and
to restore any capabilities or services that were impaired due to a
cybersecurity event” and involves three subcategories. The recovery plan is
used to repair and restore systems to resume normal operations. Improvements
should be made based on the analysis of the response plan in order to improve
the overall response and recovery time. Finally, communication channels should
be established to create more a more efficient recovery plan. This subcategory
involves communication with external parties such as internet service providers
(ISP), victims, or stakeholders to inform them of the effects or to improve
recovery time.
Comments
Post a Comment