Today I will be providing you with a brief overview of the NIST
Cybersecurity Framework for consideration as part of the Padgett-Beale
operational construct for cybersecurity risk management. c The NIST
Cybersecurity Framework is designed to assist in establishing a baseline risk
management matrix with regards to our current cybersecurity posture, our
desired cybersecurity end state, identifying opportunities for improvements,
asses our progress, and communicate cybersecurity risk with all
stakeholders. This framework was created to reinforce the organizational
risk management process and cybersecurity program from a risk-based
approach. c I will briefly discuss the three parts of the framework, their
definitions, and subcategories to assist in developing an understanding of
the overarching concept. Please see the handout you have been provided
for specifics on each section of the framework being discussed (Framework
for improving critical infrastructure cybersecurity ... – NIST, 2018).
c c c c The first part of the NIST Cybersecurity Framework is the
Framework Core. c The Core provides guidance on specific cybersecurity
outcomes based on the activities that need to be accomplished to manage
risk. The elements of the Core are functions, categories, subcategories, and
informative references. The functions of the Core are broken down into five
elements to assist in how we identify, protect, detect, respond, and recover
with regards cybersecurity incidents. The categories and subcategories
elements subdivide the functions from the overarching concepts such as
Asset Management down to the management activities that need to be
conducted to achieve specific outcomes while the informative references
assist in providing standards, guidelines, and practices an illustrative
definition of each subcategory (Frayssinet Delgado et al., 2021).
c c c c The second part of the NIST Cybersecurity framework is the
Framework Implementation Tiers. c The Tiers address the sophistication of
the companies posture regarding cybersecurity risk and the processes that
mitigate risks. The Tiers range from one to four with Tier 1 being Partial
where risk mitigation is not formalized and more reactive in nature. Tier 2 is
risk informed where risk is being managed but is not part of the
organizational policy. Tier 3 is designated as repeatable and considered to
be fully integrated throughout the organization while maintaining currency
in respect to the ever-changing threat landscape and business
requirements. Tier 4 is adaptive and fully functional integrating past,
present, and possible future cybersecurity activities providing active
response to emerging threats(Framework for improving critical
infrastructure cybersecurity ... – NIST, 2018).
c c c c The third and final part of the NIST Cybersecurity framework is
the Framework Profile. The Profile serves as a culmination of the
Framework Core elements aligned against requirements, risk tolerance and
resources of the organization. These considerations help to visualize the
organizations current risk management strategy against a possible future
risk management profile with path of how to achieve the desired end state.
c c c c Members of the board, as I conclude this briefing, I would like to
summarize the points covered during this overview brief. The key take
away is that cybersecurity risk management can be a difficult task in and of
itself. It can become a costly venture if not embraced in a steady and
methodical manner. We can improve our cybersecurity risk management
posture by employing the NIST Cybersecurity Framework construct
throughout our organization. c Implementing the Framework Core elements,
Framework Tiers, and Framework Profiles can assist in defining how we
mitigate risk while considering the people, processes, and technology that
must be identified, managed, and maintained to protect the resources of
Padgett-Beale Inc. Thank you for your time, I hope this briefing sparked
your interest in implementing the NIST Cybersecurity Framework as a long-
term solution for risk management.
Framework for improving critical infrastructure cybersecurity ... - NIST.
(2018, April 16). Retrieved May 7, 2022, from
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
Frayssinet Delgado, M., Esenarro, D., Juárez Regalado, F. F., & Díaz
Reátegui, M. (2021). Methodology Based on the Nist Cybersecurity
Framework as a Proposal for Cybersecurity Management in Government
Organizations. 3C TIC, 10(2), 123–141. https://doi-
org.ezproxy.umgc.edu/10.17993/3ctic.2021.102.123-141