Don’t do SECURITY. Do business SECURELY.

NIST Cybersecurity Framework version 1.1 released

NIST has published version 1.1 of the Cybersecurity Framework, with expanded guidance on supply chain risk, identity management and self-assessment.

NIST has released version 1.1 of the Cybersecurity Framework. It is fully compatible with version 1.0, so organisations already using the framework can adopt the update without disruption.

What’s new?

  • A new section on self-assessing cybersecurity risk and measuring outcomes.
  • Expanded guidance on cyber supply chain risk management, including a new category.
  • Refined language on identity management, authentication and access control.
  • A new subcategory on coordinated vulnerability disclosure.

The CSF continues to gain adoption well beyond US critical infrastructure. It sits comfortably alongside ISO/IEC 27001, with NIST publishing mappings between the two.

Source: Framework for Improving Critical Infrastructure Cybersecurity v1.1 (NIST)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights