The Cyber Crystal Ball: What’s in Store for Community Financial Institutions in 2025?
“2024 was rough; why should 2025 be any different?” This is the mantra heard in many community banks and credit unions as they brace for the next...
The NIST Cybersecurity Framework (CSF) was initially developed in 2014 and was intended to be a living document, dependent on feedback from stakeholders. It was initially developed for critical infrastructure, such as hospitals and banking. It has had an update in 2018, largely addressing supply chain risk, and is evolving yet again. Here are five thoughts as I browsed the proposed update, located here: https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-20/ipd.
On August 8, 2023, NIST announced some key updates to the CSF. It aims to address some of the biggest criticisms of the framework I have heard. These have included:
The new framework is scheduled to be published in early 2024. NIST is asking for feedback by November 4, 2023.
For community financial institutions (FIs), I am still shy of anyone making a full declaration of compliance with the CSF. FFIEC guidance largely follows NIST, tailored for FIs, also FFIEC is the basis for examinations, so the safest bet is to follow FFIEC as closely as possible. I personally have found NIST to give clearer examples of how to implement controls, so I will reference those when FFIEC is unclear.
I do applaud NIST for giving the spotlight on governance and risk management, while it was baked into its five categories previously, it wasn’t regarded as its own discipline. This hopefully will open the pathway for success and more consistency across the board….and a better understanding among cybersecurity professionals and management.
If you have any questions on this framework or risk management, we would love to help. Contact us at support@bedelsecurity.com!
“2024 was rough; why should 2025 be any different?” This is the mantra heard in many community banks and credit unions as they brace for the next...
The National Institute for Standards and Technology released an update to its Cybersecurity Framework (CSF) late February. The CSF was originally...
Wow, how much technology has changed in the past 15 years? I remember when “vendor” reviews were uncommon, technology was hosted in-house in 95% of...