The National Institute of Standards and Technology has released its newest iteration of critical infrastructure cybersecurity framework. Today’s brief includes this document (Version 1.1), two developmental drafts with comments, a summary of a workshop held on the framework, and the first edition (Version 1.0) accompanied by two presentations on the framework. This collection of documents highlights the work of a key contributor to cybersecurity policy that is not considered to be part of the national security apparatus by most of the public.
New Additions
2
Document 01
National Institute of Standards and Technology
This document provides finalized updates to the 2014 critical infrastructure cybersecurity framework.
Document 02
National Institute of Standards and Technology
This framework draft incorporates insights from a public-private workshop held by NIST.
From the Vault
This document summarizes the findings of a May workshop on the draft cybersecurity framework.
This framework draft - which consists of core, profile, and implementation tiers - was developed through collaboration between the government and private sector. It is intended to guide cybersecurity activities and the consideration of cybersecurity risks as part of an organization's risk management process.
This presentation on NIST's framework for improving critical infrastructure cybersecurity includes discussions of, inter alia, the pre-cyber security framework threat landscape, development of the framework, who the framework is intended to provide guidance to, framework components, and industry resources.
This presentation outlines an adaptable framework for cybersecurity that can be tailored to specific critical infrastructure 'profiles'.
This framework was developed in response to President Obama's 2013 executive order on critical infrastructure cybersecurity that called for creation of a voluntary risk-based cybersecurity framework.