NIST Releases Cybersecurity Framework 2.0
The National Institute for Standards and Technology released an update to its Cybersecurity Framework (CSF) late February. The CSF was originally...
The NIST Cybersecurity Framework (CSF) was initially developed in 2014 and was intended to be a living document, dependent on feedback from stakeholders. It was initially developed for critical infrastructure, such as hospitals and banking. It has had an update in 2018, largely addressing supply chain risk, and is evolving yet again. Here are five thoughts as I browsed the proposed update, located here: https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-20/ipd.
On August 8, 2023, NIST announced some key updates to the CSF. It aims to address some of the biggest criticisms of the framework I have heard. These have included:
The new framework is scheduled to be published in early 2024. NIST is asking for feedback by November 4, 2023.
For community financial institutions (FIs), I am still shy of anyone making a full declaration of compliance with the CSF. FFIEC guidance largely follows NIST, tailored for FIs, also FFIEC is the basis for examinations, so the safest bet is to follow FFIEC as closely as possible. I personally have found NIST to give clearer examples of how to implement controls, so I will reference those when FFIEC is unclear.
I do applaud NIST for giving the spotlight on governance and risk management, while it was baked into its five categories previously, it wasn’t regarded as its own discipline. This hopefully will open the pathway for success and more consistency across the board….and a better understanding among cybersecurity professionals and management.
If you have any questions on this framework or risk management, we would love to help. Contact us at support@bedelsecurity.com!
The National Institute for Standards and Technology released an update to its Cybersecurity Framework (CSF) late February. The CSF was originally...
It is a good practice to identify a cybersecurity framework as part of an institution’s Information Security Program. A framework helps to identify...
Last week, we saw the Federal Financial Institutions Council (FFIEC) announce an update to its Cybersecurity Resource Guide. It was originally...