NIST has published version 1.0 of the Framework for Improving Critical Infrastructure Cybersecurity, commonly known as the NIST Cybersecurity Framework (CSF).
Developed with industry following a US Executive Order, the CSF is a voluntary, risk-based framework organised around five core functions:
- Identify: understand assets, risks and business context
- Protect: implement safeguards
- Detect: identify cybersecurity events
- Respond: take action on detected incidents
- Recover: restore capabilities and services
The framework uses implementation tiers and profiles to describe current and target states, and references existing standards, including ISO/IEC 27001 and NIST SP 800-53, rather than replacing them.
Although written for US critical infrastructure, the CSF is quickly becoming a common language for describing cyber security capability to boards, customers and insurers worldwide, and complements an ISO/IEC 27001 management system well.
Source: Cybersecurity Framework Version 1.0 (NIST)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.