How the NIST cybersecurity framework can help secure the enterprise

The NIST cybersecurity framework can set expectations for the appropriate level of security

Now that the US National Institute of Standards and Technology has finalized the much-discussed cybersecurity framework, organizations can use it as the guideline for measuring how well their systems are secured.

One year ago, President Barack Obama directed NIST to develop a security framework that could be used as a guide to secure the country's cyberinfrastructure of basic vital services such as banking, transportation and telecommunications. Although the White House directed the development of the framework chiefly for measuring and mitigating risk in the country's cyberinfrastructure to protect airlines, roads and other vital aspects of the U.S. economy and well-being, it can be used by any organization.

Certainly, retailers that have been hit by cyberattacks, such as Target, could benefit from the framework.

To develop the framework, NIST consulted hundreds of experts in industry and reviewed feedback from thousands of additional contributors culled from multiple draft releases that were posted for review. In its final form, the framework offers a core set of activities to anticipate and mitigate against attacks on systems. It provides a set of measurements to assess to what degree an organization has implemented these core activities, which can be used as a gauge to assess how prepared the organization's systems are, in terms of being secured against an attack.

While some have criticized the 41-page framework as too vague to be of much value, it can offer a road map for organizations, some say.

The framework was written preliminarily for the higher levels of management, such as a boards of directors, chief security officers, audit committees, senior executives and others "working inside an organization who are responsible for different aspects of security and privacy," said Harriet Pearson, a partner in the Washington, D.C., office of Hogan Lovells, who was involved in the shaping of the framework.

It is a valuable indicator of what a standard of care should be, Pearson said: "A CSO might be wondering 'How do I know if I've done enough?'" The document provides a standard measure that organizations can agree on in terms of assessing risk assessment.

"While not technology specific, it points to the governance and action," Pearson said. "You don't have to use every part of the framework. It's more of the thought process."

"The framework does a really nice job of laying how organizations should apply a risk-based approach to improve security," said Andrew Wild, chief security officer of IT security firm Qualys.

Other frameworks do this as well, he pointed out, but the NIST's document is valuable in its brevity. "Someone can get a high level understanding of what is required," Wild said.

The document also includes references to other, more in-depth documents that provide more detailed instruction, such as the widely referenced Council on Cybersecurity's Critical Security Controls.

Nonetheless, Wild cautioned that the framework will not be a panacea for security issues. Most security officers already have a solid understanding of how their systems need to be secured. What they too often lack, Wild said, are the adequate resources.

Overall, cyber-infrastructure security won't be significantly improved until executive boards in organizations commit to providing more resources for risk management cybersecurity, Wild said. "How can the framework make an improvement if resources aren't provided?"

Joab Jackson covers enterprise software and general technology breaking news for The IDG News Service. Follow Joab on Twitter at @Joab_Jackson. Joab's e-mail address is Joab_Jackson@idg.com

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags National Institute of Standards and Technologysecurity

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Joab Jackson

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?