Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
3/2/2018
09:00 AM
Laurence Pitt
Laurence Pitt
Partner Perspectives
Connect Directly
Twitter
RSS
50%
50%

A Sneak Peek at the New NIST Cybersecurity Framework

Key focus areas include supply chain risks, identity management, and cybersecurity risk assessment and measurement.

The National Institute of Standards and Technology's (NIST) updated Cybersecurity Framework, scheduled for release later this year, should provide some welcome new advice for organizations struggling to manage cyber-risk in the current threat environment.

 The key areas where the framework will provide guidance is about supply chain risks, identity management and cybersecurity risk assessment and measurement.  NIST released two draft framework updates containing the changes last year - the second in December 2017. It is currently reviewing public comments and will release a finalized version in the spring. 

A De Facto Standard
First published in Feb 2014, the Cybersecurity Framework was originally developed to help critical infrastructure operators assess cyber risk and implement business-appropriate countermeasures for dealing with those risks. Over the years, the framework has been adopted by critical infrastructure organizations along with other industries of all sizes. It's most important contribution has been to create a common vocabulary for identifying, protecting, detecting, responding and recovering from cyber threats. The guidelines in the framework have become a standard for cyber-risk management for many enterprises and, since last May, a mandated requirement for US federal agencies.

The updates in version 1.1, according to NIST, are designed to amplify the framework's value and make it easier to use. Here are some key features:

Descriptions, Definitions & Processes
The new version of the NIST Cybersecurity Framework will introduce simple descriptions and definitions for identifying all the stakeholders and associated cyber-risks in an organizational supply chain. It will also highlight methods for identifying security gaps within the supply chain itself, and other management processes .

Measuring Risk
Risk-assessment is another area where organizations can expect to find fresh insight. There is now a revised section on measuring and demonstrating cybersecurity effectiveness, along with a new section on self-assessing cyber-risk. The section will highlight how organizations can identify, measure and manage cyber-risk to support their broader business goals and outcomes. The updated framework will also provide a basis for organizations to not only assess their current cybersecurity risk but to convey it in a standard way to suppliers, partners and other stakeholders in order  to reduce the chances of miscommunication.

Identity & Access Control
This section has been revised to provide more clarity around concepts like user authentication, authorization and identity-proofing. The goal is to help organizations identify the best processes for ensuring access in the face of exploding cloud, mobile technologies and other computing paradigms.

The NIST Cybersecurity Framework was, and continues to be, completely voluntary. Except for federal agencies, no organization is required to follow any of the implementation practices contained in the framework. But considering how widely the framework is used these days, smart organizations will want to consider the distinct possibility that someday their security practices will be assessed against it.

 

Laurence Pitt is the Strategic Director for Security with Juniper Networks' marketing organization in EMEA. He has over twenty years' experience of cyber security, having started out in systems design and moved through product management in areas from endpoint security to ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
HackerOne Drops Mobile Voting App Vendor Voatz
Dark Reading Staff 3/30/2020
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5300
PUBLISHED: 2020-04-06
In Hydra (an OAuth2 Server and OpenID Certifiedâ„¢ OpenID Connect Provider written in Go), before version 1.4.0+oryOS.17, when using client authentication method 'private_key_jwt' [1], OpenId specification says the following about assertion `jti`: "A unique identifier for the t...
CVE-2019-19699
PUBLISHED: 2020-04-06
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to system compromise via apache crontab misconfiguration, This allows the apache user to modify an executable file executed by root at 22:30 every day. To e...
CVE-2020-11102
PUBLISHED: 2020-04-06
hw/net/tulip.c in QEMU 4.2.0 has a buffer overflow during the copying of tx/rx buffers because the frame size is not validated against the r/w data length.
CVE-2020-11507
PUBLISHED: 2020-04-06
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.
CVE-2020-11544
PUBLISHED: 2020-04-06
An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for...