NIST Cybersecurity Framework
Identify, protect, detect, respond, recover — this is an approach many people recognise and use to address systematic IT security work. Here we go through what the framework involves and what it makes possible.
Background
The work began in 2013, when U.S. President Barack Obama directed the National Institute of Standards and Technology (NIST) to develop a framework, the NIST Cybersecurity Framework (NIST CSF), to increase cybersecurity and resilience across the country's critical infrastructure and information systems.
The framework was also meant to provide guidance on how security should be maintained over time. A number of government agencies, companies from various industries in the public and private sectors, and the U.S. education system took part in developing it, and continue to help ensure the framework meets the requirements placed on it.
- Identify security standards and guidelines applied within critical infrastructure and information system sectors.
- Ensure the framework's application is flexible, repeatable, supports prioritisation, can be monitored, and promotes cost-effectiveness.
- Help those responsible for critical infrastructure and information systems identify, assess, and manage risk.
- Facilitate technical innovation and take into account the circumstances of different stakeholders.
- Provide guidance that is technology-neutral and enables responsible stakeholders to benefit from a competitive market for products and services.
- Include guidance for measuring the outcome of implementing the NIST CSF.
The NIST CSF is free and vendor-neutral. It builds on and refers to existing standards such as ISO 27001. There is no certification process for the NIST CSF.
Functions, categories and subcategories
The NIST CSF describes a number of security measures intended to help an organisation map its current and desired level of cybersecurity. The descriptions are easy to understand and use non-technical language, which makes communication easier between different professional groups and roles.
The NIST CSF consists of five functions covering 23 categories with 108 subcategories.
Functions — there are five functions whose purpose is to give the organisation an overview of security measures and good examples of how security risks can be managed.
- Identify: Which assets and processes need to be protected?
- Protect: What security measures are in place?
- Detect: What capability exists to detect security incidents?
- Respond: What capability exists to handle security incidents that have occurred?
- Recover: What capability exists to restore affected infrastructure and IT systems?
Categories — Each function includes a number of categories, for example access control, data security, monitoring, and security incident management. There are 23 categories in total.
Subcategories — Each category includes a number of subcategories in the form of more concrete security measures. There are 108 subcategories in total. Each subcategory includes references to other, more technically detailed descriptions.
Implementation at four levels
The NIST CSF uses four levels of application, called tiers, which reflect how an organisation manages security risk, for example how well that management is adapted to current business needs and operational requirements, and how integrated it is into overall risk management.
Choosing an implementation tier should not be seen as defining a level of security maturity, but rather as a desired state for the organisation to work toward, thereby facilitating decision-making and resource allocation to reduce security risk.
In brief, the implementation tiers can be described as follows.
Tier 1: Partial — The organisation does not have a structured approach to managing security risk; activities are carried out occasionally and are often reactive. Management has limited awareness of security risk, and the organisation does not share information with external parties on, for example, threats and new technologies. The organisation generally has low awareness of security risk in the supply chain for the products or services it provides or uses.
Tier 2: Risk Informed — The organisation has methods for reducing the risk from the most common threats and attack methods, but lacks a coordinated strategy and common rules across the whole organisation. The organisation is aware of the threats to its assets and supply chains but has limited capacity to lead the work needed to manage them.
Tier 3: Repeatable — The organisation actively works on analyzing threats, security risks and vulnerabilities. Management is involved in this work. The organisation collaborates with other players in the industry and also keeps up to date on how competitors manage security risk.
Tier 4: Adaptive — The highest tier includes heavily regulated organisations with high security requirements, such as banking, healthcare and organisations providing services essential to society. Security measures are continuously evaluated, and ongoing improvements are made to strengthen protection or respond to new threats. The assessment of security risk is integrated into management's broader risk management. The organisation plays an active role in both receiving and sharing information as threats and security technology evolve.
Profiles: Gap analysis to meet your own security requirements
Profiles are used to compare the organisation's current state with a desired state regarding security. It is up to the organisation itself to decide what level of security should be achieved. The framework itself contains no "right" or "wrong" answers.
By reviewing the subcategories and assessing them against the organisation's security requirements, business objectives and available resources, a target profile can be developed that sets out the security measures the organisation needs to meet. In parallel, a current profile is developed that documents which security measures the organisation already meets. The difference between the two profiles defines the gap, and based on that analysis a plan and budget can be drawn up to improve security.