Good afternoon, PBI Board members, and thank you for joining us
today at orientation. My name is Autumn Yarbrough, and I have spent
the last 8 weeks as an intern with your company. I am fortunate
enough to be given this opportunity to brief you all on the National
Institute of Standards and Technology, best known as NIST,
Cybersecurity Framework. It will be a short, five-minute overview, so I
created the handouts in front of you to help you follow along. Please
hold all questions until the end. And without further ado, let’s get
started.
c NIST defines the Cybersecurity Framework, or CSF as
commonly referred, as “voluntary guidance, based on existing
standards, guidance, and practices for organizations to better manage
and reduce cybersecurity risk” (2022, p. 9). The core of CSF “provides…
activities to achieve specific cybersecurity outcomes”, which are
divided into functions, and their subsequent categories, subcategories,
and informative references (NIST, 2018, p. 13). As you see on your
handout, these functions are Identify, Protect, Detect, Respond, and
Recover. Identify works to increase organizational awareness on the
“systems, assets, data, and capabilities” that are at risk to cyber threats
(Cybersecurity & Infrastructure Security Agency [CISA], n.d., p. 4). The
outcomes of this function can include asset management, risk
assessment, and risk management (CISA, n.d.). Protect decreases the
effects of future cyber incidents, with outcomes like employee
awareness training, access control, and system maintenance (CISA,
n.d.). Detect outcomes increase the likelihood that malicious activity on
a network will be discovered quickly, with implementations like round-
the-clock network monitoring (CISA, n.d.). Respond works to improve
how an organization combats breaches of security. This can include
response planning, established analysis procedures, and pre-
determined notification and communication methods (CISA, n.d.).
Lastly for the functions is Recover. This is how an organization mends
and improves following a cybersecurity incident, utilizing the lessons
learned and successes to further harden the network (CISA, n.d.).
c The categories that fall under functions are “subdivisions of…
cybersecurity outcomes closely tied to… needs and particular activities”
(NIST, 2018, p. 14). Then it is further divided into subcategories, which
are specific actions that support goal accomplishment. And to round
out the core of CSF, the “informative references are specific sections
of standards, guidelines, and practices… that illustrate a method to
achieve the [desired] outcomes” (NIST, 2018, p. 14).
c The CSF also has established tiers that categorize organizations
based on the establishment and complexity of their cybersecurity
program. The tiers range from Partial at one, which has the most to
improve, to Adaptive at four, which is the most advanced and
progressive. Although it may seem that the tiers, including Risk
Informed at two and Repeatable at three, “represent maturity levels”, it
is important to note that they are established to assist the efforts of
every organization. Not every company can feasibly achieve Adaptive,
based on financial and/or organizational constraints, but CSF is still
encouraged wherever possible (NIST, 2018).
c Lastly, the implementation of the CSF is sectioned out by level
of authority in the organization. At the top, you have the executive
team developing the priorities of the company (and how cybersecurity
fits in), what resources they are willing to allocate for which effort, and
what risks they are prepared to accept (NIST, 2018). In the middle, you
have the Business/Process level, which is where managers and
supervisors reside. This is where the company vision is enforced down
and concerns or issues are communicated up (NIST, 2018). They are
the hand of the executive team but the voice of the employees doing
the work. Transparency and connectedness are imperative with this
group for program success. And the bottom level is for Implementation
and Operations, where employees are doing the work that supports
the vision of the executive team (NIST, 2018). These levels need to
work together efficiently to increase the effectiveness of the
organizational network security.
c The CSF was developed as a collaborative effort between the
U.S. government and the cyber/IT community. It was intended to be
flexible, cost-effective, and give organizations the control to build their
security programs as best that they could (NIST, 2022). And being that
the entire CSF program is open source, it ensures accessibility for even
the smallest of security teams.
This concludes the formal section of CSF training. I would like to open
the floor for any questions or discussion points.
…
Thank you for your time, and congratulations on your new position to
the Board!
c
References
Cybersecurity & Infrastructure Security Agency. (n.d.).
Cybersecurity
Framework
. Cybersecurity & Infrastructure Security Agency.
https://www.cisa.gov/uscert/resources/cybersecurity-framework
National Institute of Standards and Technology. (2018, April 16).
Framework for improving critical infrastructure cybersecurity
. c
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
National Institute of Standards and Technology. (2022, April 14).
Getting started.
Cybersecurity Framework
.
https://www.nist.gov/cyberframework/getting-started