Don’t do SECURITY. Do business SECURELY.

NIST releases Cybersecurity Framework 1.0

The US National Institute of Standards and Technology has published version 1.0 of its Framework for Improving Critical Infrastructure Cybersecurity.

NIST has published version 1.0 of the Framework for Improving Critical Infrastructure Cybersecurity, commonly known as the NIST Cybersecurity Framework (CSF).

Developed with industry following a US Executive Order, the CSF is a voluntary, risk-based framework organised around five core functions:

  • Identify: understand assets, risks and business context
  • Protect: implement safeguards
  • Detect: identify cybersecurity events
  • Respond: take action on detected incidents
  • Recover: restore capabilities and services

The framework uses implementation tiers and profiles to describe current and target states, and references existing standards, including ISO/IEC 27001 and NIST SP 800-53, rather than replacing them.

Although written for US critical infrastructure, the CSF is quickly becoming a common language for describing cyber security capability to boards, customers and insurers worldwide, and complements an ISO/IEC 27001 management system well.

Source: Cybersecurity Framework Version 1.0 (NIST)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights