{"id":4117,"date":"2024-06-20T09:00:00","date_gmt":"2024-06-20T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/catching-up-on-innovation-with-nist-csf-2-0"},"modified":"2024-06-20T09:00:00","modified_gmt":"2024-06-20T14:00:00","slug":"catching-up-on-innovation-with-nist-csf-2-0","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/20\/catching-up-on-innovation-with-nist-csf-2-0\/","title":{"rendered":"Catching Up on Innovation With NIST CSF 2.0"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltc384fb330170a607\/66743c4612042a0656239aad\/Cybersecurity_symbols%281800%29_Skorzewiak_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The National Institute of Standards and Technology&#8217;s Cybersecurity Framework 2.0 (NIST CSF 2.0) could not have come at a better time.&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/fast-growing-ra-ransomware-group-goes-global\" rel=\"noopener\">Ransomware attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> have already built up a devastating track record&nbsp;on businesses and institutions across all industries in the past year: 58% of respondents to a&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/hop.extrahop.com\/resources\/papers\/global-cyber-confidence-index-2024\/\" rel=\"noopener\">recent survey<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;experienced six or more ransomware attacks in the past 12 months. This comes among other concerns, including <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\" rel=\"noopener\">data breaches<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/saudi-aramco-ceo-warns-of-new-threat-of-generative-ai\" rel=\"noopener\">generative AI threats<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, insider threats, and more, proving that cybersecurity needs to be more accessible than ever.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Historically, industry guidance to prevent these attacks was aimed at critical infrastructure or larger enterprises in high-risk industries. But cybersecurity is an &#8220;everyone&#8221; problem, and many organizations are beginning to catch on to the idea that cyber-risks are just as important as all other business risks. The same survey found that the average incident downtime is 56 hours, and considering that&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/new.abb.com\/news\/detail\/107660\/abb-survey-reveals-unplanned-downtime-costs-125000-per-hour\" rel=\"noopener\">a survey conducted by ABB<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;in 2023 puts the median cost of downtime at nearly $125,000 per hour, this downtime would cost $7 million \u2014 per incident.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/nist-releases-cybersecurity-framework-2-0\" rel=\"noopener\">NIST&#8217;s CSF 2.0, released this February<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, provides an important resource for organizations of all sizes to avoid these far-reaching costs by reexamining their security initiatives, fending off evolving threats, and preparing to meet today&#8217;s innovations with a more guided approach. While just a framework, it can be used to inform three critical changes all organizations should make in the year ahead.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Three Critical Changes Everyone Should Make in the Coming Year\">Three Critical Changes Everyone Should Make in the Coming Year<\/h2>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"1. Building a New Approach to Securing Infrastructure\">1. Building a New Approach to Securing Infrastructure<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The path to securing infrastructure may seem like an obvious route: Get the right tools to detect, defend, and respond to security incidents. But one area organizations often miss, and one of the most significant additions to NIST CSF 2.0, is governance.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A strong governance strategy establishes all people, process, and organizational concerns for cybersecurity. This includes the development of a cybersecurity strategy and policies, oversight for the strategy and policies, controls for supply chain, and more.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is especially important for smaller companies with plans to continue scaling. Having a set plan in place to quickly and efficiently react to a potential security breach can alleviate the capital losses that come with the territory: Net income, quarterly earnings, and stock prices all drop significantly after data breaches. An effective plan can possibly reduce those effects.<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Investing to Fit Specific Business Needs\">2. Investing to Fit Specific Business Needs<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An organization may choose to handle risk in one or more ways, and this all depends on its specific business needs. NIST CSF 2.0 can help determine areas and levels of risk, and from there, organizations can decide on the right solutions. This can feel overwhelming for many organizations, especially as solution providers are continuously innovating and developing new tools.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One universal truth in the industry is that security operations center (SOC) analysts are overwhelmed and resource strapped. AI- and ML-based solutions have arisen as a helpful bridge in combating this industry burnout to effectively manage risk and build business resilience against threats. Additionally, tools that enhance visibility are essential in further securing the attack surface. Despite investments in vulnerability management, endpoint detection and response (EDR), and security information and event management (SIEM) tools, there are many blind spots in the network, cloud, and more that organizations need to address as well.<\/span><\/p>\n<h3 class=\"ContentText ContentText_variant_h3 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Developing an Organizationwide Approach to Security Hygiene\">3. Developing an Organizationwide Approach to Security Hygiene<\/h3>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While the right tools are essential, a critical part of NIST CSF 2.0&#8217;s &#8220;Protect&#8221; focuses on awareness, training, and identity and access management as critical safeguards to managing risk. While the framework calls out a great number of risk factors, overall cyber hygiene is a critically undervalued part of cybersecurity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is an age-old method that works for attackers time and time again, and the costs add up. Luckily, for smaller organizations, they typically perform best on the cyber hygiene bell curve, with midsize organizations lagging behind. But one successful attack can be all it takes to financially destabilize a small organization, as respondents paid an average of nearly $2.5 million in ransom in 2023, and generative AI has only made social engineering attacks easier.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Taking Advantage of Industry Resources\">Taking Advantage of Industry Resources<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though it provides essential guidelines, keep in mind that NIST&#8217;s CSF 2.0 is meant to be used in conjunction with other frameworks and guidance, and is not a catch-all solution.&nbsp;It&#8217;s also designed to be customized as an organization grows and evolves.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, the framework is an equalizer for smaller organizations to meet the industry at its breakneck pace of innovation now that it is designed for organizations of all sizes. This includes understanding how threat actors are advancing and the new tools to defend against them, both of which are essential to building business resilience in the long run.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/catching-up-on-innovation-with-nist-csf-2-0\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY The National Institute of Standards and Technology&#8217;s Cybersecurity Framework<\/p>\n","protected":false},"author":12,"featured_media":4118,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4117","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=1820%2C1024&ssl=1",1820,1024,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=1820%2C1024&ssl=1",1820,1024,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/catching-up-on-innovation-with-nist-csf-2-0.jpg?fit=1820%2C1024&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4117"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4117\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4118"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4117"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4117"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}