{"id":2650,"date":"2024-03-01T20:11:46","date_gmt":"2024-03-01T20:11:46","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/nist-cybersecurity-framework-2-0-4-steps-get-started"},"modified":"2024-03-01T20:11:46","modified_gmt":"2024-03-01T20:11:46","slug":"nist-cybersecurity-framework-2-0-4-steps-to-get-started","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/03\/01\/nist-cybersecurity-framework-2-0-4-steps-to-get-started\/","title":{"rendered":"NIST Cybersecurity Framework 2.0: 4 Steps to Get Started"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt49024cdf20c96be9\/65e20438f12559040ab393ac\/nist-cybersecurity-framework-v2.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The US National Institute of Standards and Technology (NIST) has released the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/nist-releases-cybersecurity-framework-2-0\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">latest draft of its well-regarded Cybersecurity Framework (CSF) <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">this week, leaving companies to mull how a few significant changes to the document affects their cybersecurity programs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Between the new &#8220;Govern&#8221; function to incorporate greater executive and board oversight of cybersecurity, and the expansion of the best practices beyond just those for critical industries, cybersecurity teams will have their work cut out for them, says Richard Caralli, senior cybersecurity adviser at Axio, an IT and operational technology (OT) threat management firm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In many cases, this will mean that organizations have to take a hard look at existing assessments, identified gaps, and remediation activities to determine the impact of the framework changes,&#8221; he says, adding that &#8220;new program gaps will emerge that previously may not have been present, especially with respect to cybersecurity governance and supply chain risk management.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The original CSF, last updated 10 years ago, aimed to provide cybersecurity guidance to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cloud-security\/nist-releases-new-cybersecurity-framework-draft\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">industries critical to national and economic security<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.nist.gov\/cyberframework\" target=\"_blank\" rel=\"sponsored noopener\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\">latest version<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> greatly expands that vision to create a framework for any organization intending to improve its cybersecurity maturity and posture. In addition, third-party partners and suppliers are now a significant factor to consider in the CSF 2.0.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations need to look at cybersecurity more systematically to comply with regulations and implement the best practices from the document, Katie Teitler-Santullo, senior cybersecurity strategist for Axonius, said in a statement.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Making this guidance actionable will need to be a self-propelled effort from businesses,&#8221; she said. &#8220;Guidance is just guidance, until it becomes law. The top-performing organizations will take it upon themselves to move toward a more business-centric approach to cyber-risk.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Here are four tips for operationalization of the latest version of the NIST Cybersecurity Framework.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Use All the NIST Resources\">1. Use All the NIST Resources<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The NIST CSF is not just a document but a collection of resources that companies can use to apply the framework to their specific environment and requirements. Organizational and community profiles, for example, provide the foundation for companies to assess \u2014 or reassess \u2014 their cybersecurity requirements, assets, and controls. To make the process easier to start, NIST has also published QuickStart guides for specific industry segments, such as small business, and for specific functions, such as cybersecurity supply chain risk management (C-SCRM).&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The NIST resources can help teams understand the changes, says Nick Puetz, managing director at Protiviti, an IT consulting firm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;These can be highly valuable tools that can help companies of all sizes but are especially useful for smaller organizations,&#8221; he says, adding that teams should &#8220;ensure your senior leadership team \u2014 and even your board of directors \u2014 understand how this will benefit the program [but] could create some maturity scoring [or] benchmarking inconsistencies in the short term.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Discuss Impact of &quot;Govern&quot; Function With Leadership\">2. Discuss Impact of &#8220;Govern&#8221; Function With Leadership<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The NIST CSF 2.0 adds an entirely new core function: Govern. The new function is a recognition that the overall organizational approach to cybersecurity needs to match the strategy of the business, measured by operations, and managed by security executives, including the board of directors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security teams should look to asset discovery and identity management to provide visibility into the critical components of a company&#8217;s business and how workers and workloads interact with those assets. Because of that, the Govern function relies heavily on other aspects of the CSF \u2014 in particular, the &#8220;Identify&#8221; function. And several components, such as &#8220;Business Environment&#8221; and &#8220;Risk Management Strategy,&#8221; will be moved from Identity to Govern, says Axio&#8217;s Caralli.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This new function supports evolving regulatory requirements, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/orgs-face-major-sec-penalties-failing-disclose-breaches\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">the SEC [data-breach disclosure] rules<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which took effect in December 2023, is likely a nod to the potential for additional regulatory actions to come,&#8221; he says. &#8220;And it highlights the fiduciary role that leadership plays in the cybersecurity risk management process.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Consider Your Supply Chain Security\">3. Consider Your Supply Chain Security<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Supply chain risk gains more prominence in the CSF 2.0. Organizations can typically accept risk, avoid it, attempt to mitigate risk, share the risk, or transfer the issue to another organization. Modern manufacturers, for example, typically transfer cyber-risk to their buyers, which means that an outage caused by a cyberattack on a supplier can affect your company as well, says Aloke Chakravarty, partner and co-chair of the investigations, government enforcement, and white-collar protection practice group at law firm Snell &amp; Wilmer.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security teams should create a system to evaluate suppliers cybersecurity posture, identify potentially exploitable weaknesses, and verify that the supplier&#8217;s risk is not being transferred to their buyers, Chakravarty says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Because vendor security is now expressly highlighted, many vendors may market themselves as having conforming practices, but companies will do well to scrutinize and pressure-test these representations,&#8221; he says. &#8220;Seeking additional audit reporting and policies around these cybersecurity representations may become part of this evolving market.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"4. Confirm Your Vendors Support CSF 2.0\">4. Confirm Your Vendors Support CSF 2.0<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Consulting services and cybersecurity posture management products, among others, will likely need to be reevaluated and updated to support the latest CSF. Traditional governance, risk, and compliance (GRC) tools, for example, should be reexamined in light of the increased emphasis placed by NIST on the Govern function, says Axio&#8217;s Caralli.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Moreover, the CSF 2.0 puts additional pressure on supply chain management product and services to better identify and control their third-party risks, Caralli says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He adds: &#8220;It is likely that existing tools and methods will see opportunities in the framework updates to improve their products and service offerings to better align to the expanded practice set.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/nist-cybersecurity-framework-2-0-4-steps-get-started\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The US National Institute of Standards and Technology (NIST) has<\/p>\n","protected":false},"author":12,"featured_media":2651,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2650","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=1048%2C635&ssl=1",1048,635,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=300%2C182&ssl=1",300,182,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=640%2C388&ssl=1",640,388,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=640%2C388&ssl=1",640,388,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=1048%2C635&ssl=1",1048,635,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=1048%2C635&ssl=1",1048,635,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=1024%2C620&ssl=1",1024,620,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/03\/nist-cybersecurity-framework-2-0-4-steps-to-get-started.jpg?fit=1048%2C635&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2650","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2650"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2650\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2651"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2650"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2650"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2650"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}