NIST has released version 1.1 of the Cybersecurity Framework. It is fully compatible with version 1.0, so organisations already using the framework can adopt the update without disruption.
What’s new?
- A new section on self-assessing cybersecurity risk and measuring outcomes.
- Expanded guidance on cyber supply chain risk management, including a new category.
- Refined language on identity management, authentication and access control.
- A new subcategory on coordinated vulnerability disclosure.
The CSF continues to gain adoption well beyond US critical infrastructure. It sits comfortably alongside ISO/IEC 27001, with NIST publishing mappings between the two.
Source: Framework for Improving Critical Infrastructure Cybersecurity v1.1 (NIST)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.