Good afternoon,
Today’s topic is about IT security frameworks, specifically the NIST
Cybersecurity Framework. This framework was developed by the
National Institute of Standards and Technology, an organization
operating under the Department of Commerce (NIST, 2022). This
framework was primarily designed with “critical infrastructure” in mind
(NIST, 2018), as opposed to commercial industry, but the principles
found within the framework can help to improve the Cybersecurity
posture of Padgett-Beale. Because this framework is developed to
harden and defend such infrastructure that is critical to the United
States, it is a reliable framework to build off of in the case of Padgett-
Beale.
The Framework consists of three parts, the Framework Core, the
Framework Implementation Tiers, and the Framework Profile. The
Framework core consists of five “high level” (NIST, 2021) strategic
functions that include Identify, Protect, Detect, Respond, and Recover.
Within each function there are a number of categories that further
break down the five functions. For example within the Detect
function, there are categories for “Anomalies and Events” and
“Detection Processes” (NIST, 2021). This core provides the basis for
building a comprehensive Cybersecurity plan from the identification of
business processes and assets to the procedures necessary to recover
from a Cybersecurity event.
The next major part of the Framework are the Implementation Tiers.
The Implementation Tiers act as a sort of “rating system” for how an
organization values different aspects of Cybersecurity. The tiers can
be used to help set priorities and establish the overall “tone” (NIST,
2018) for the company’s Cybersecurity posture. There are four tiers:
Partial, Risk Informed, Repeatable and Adaptive. Partial (Tier 1) is the
lowest tier while Adaptive (Tier 4) is the highest. Partial, in general
terms, means that the organization is informal towards, or unaware of,
the Cybersecurity risks rated as such. Adaptive means the organization
is continually
adapting
to the ever evolving Cybersecurity risks it faces.
The last piece of the Framework is the Framework Profile. The Profile
takes data from the previous parts of the Framework and helps the
organization to develop a comprehensive plan based off of the
information, tailored to the organization. The Profile helps the
organization to develop a plan to further Cybersecurity.
When it comes to Padgett-Beale operations, it is important to
understand how implementing a Framework needs to mesh with the in
place business processes. Communication needs to be free flowing
from the senior executive level, to the business level, to the
operations level (NIST, 2018). The Framework affects all levels of the
business process and open communication is key to securing Padgett-
Beale as a whole. By implementing the Framework, Padgett-Beale will
be able to further it’s Cybersecurity goals by providing a structured
plan to developing and improving the Cybersecurity posture of the
company.
Source:
NIST. (2022, January 11). About NIST. NIST. Retrieved May 8, 2022,
from https://www.nist.gov/about-nist
NIST. (2021, May, 14).An Introduction to the Components of the
Framework. NIST. Retrieved May 8, 2022, from
https://www.nist.gov/cyberframework/online-learning/components-
framework
NIST. (2018, April 16). Framework for improving critical infrastructure
cybersecurity ... - NIST. Retrieved May 8, 2022, from
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf