NIST Cybersecurity Framework


The National Institute of Standards and Technology (NIST) cybersecurity framework is a policy framework to guide users in the private sector to assess and improve their prevention, detection, and response abilities when it comes to cyber-attacks. It is primarily used in the United States, however, it has been translated to many different languages and is used by the Japanese and Israeli governments. The version 1.0 framework was originally published in 2014 to be used by managers and operates of critical infrastructure elements. Now, it is widely used by businesses and organizations to assist with becoming more proactive with risk management. Version 1.1 of the framework was drafted in 2017 and made public on April 16th, 2018. This version included changes regarding self-assessments, interactions with stakeholders, supply chain risk management, and the vulnerability disclosure process.

The core material of the NIST cybersecurity framework is divided into five main categories which are also divided into 23 subcategories. Each subcategory contains “information resources” which references other security documents and standards such as Control Objectives for Information and Related Technologies (COBIT), the Council on Cybersecurity Critical Security Controls, International Organization for Standardization (ISO), and the International Electrotechnical Commission (IEC). These extra documents tend to require a membership or payment to access, which has led Congress to pass bills that have NIST create more accessible framework guides.
The main categories for the NIST framework include; identify, protect, detect, respond, and recover. It's important to note there is not set path for these categories. While there is a recommended workflow, it varies depending upon the situation and the desired end results. With that being said, it is not recommended to skip a category if it is the first time utilizing the framework. Once it has been utilized, it can be easily modified to target specific areas to improve an organization.

The category “identify” is defined as a way to “develop the organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities”. This stage revolves around identifying aspects of the organization such as assets, risks, and possible vulnerabilities. This is made evident when observing its six subcategories, which includes; asset management, business environment, governance, risk assessment, risk management strategy, and supply chain risk management. Assets management is used to identify data, objects, personnel, or systems that are vital to daily operations or to achieve the goals of the organization. Business environment evaluates the organization’s mission, stakeholder involvement, and activity prioritization. Governance involves reviewing business policies and procedures to meet legal and operation requirements. Risk assessment is used to identify possible attacks that could affect the system and its assets, which plays into risk management strategy which is used to evaluate risk tolerance and methods that are currently being used. Supply chain risk management is similar to risk management except it is for supply chain management.

The “protect” category is define as a way to “develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services”. This category includes six subcategories. Access Control is used to limit access to data, facilities, or devices to improve security and track usage and access. Awareness and training is used to evaluate the practices of personnel to determine their level of education and knowledge of cybersecurity practices. Data security evaluates the confidentiality, integrity, and availability of data. Information protection processes and procedures creates security policies and sets the scope, roles, and responsibilities of employees and security managers. Maintenance involves the repair of security controls. Protective technology is used to create preventative measures in order to protect assets and information.

The “detect” category is defined as a way to “develop and implement the appropriate activities to identify the occurrence of a cybersecurity event” and involves three subcategories. Anomalies and events involve monitoring for strange and unusual activity and responding to it in a timely manner. Security continuous monitoring is a discrete way to monitor systems and assets to identify events and to evaluate the effectiveness of security measures. Detection processes is testing and maintaining other detection systems.

The “respond” category is defined as a way to “Develop and implement the appropriate activities to take action regarding a detected cybersecurity event” and contains five subcategories. A response plan should be developed to determine what action should be taken if an event occurs. Communication channels should be developed to create quick response times between involved parties. The analysis subcategory involves evaluating the attack in order to create better recovery plans, which is the next subcategory, mitigation. Finally, improvements are made by evaluating the effectiveness of the response plan.

Finally, the “recover” category is defined as a way to “Develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event” and involves three subcategories. The recovery plan is used to repair and restore systems to resume normal operations. Improvements should be made based on the analysis of the response plan in order to improve the overall response and recovery time. Finally, communication channels should be established to create more a more efficient recovery plan. This subcategory involves communication with external parties such as internet service providers (ISP), victims, or stakeholders to inform them of the effects or to improve recovery time.




Comments