The National Institute of Standards and Technology (NIST) today announced the first step in the development of a Cybersecurity Framework, which will be a set of voluntary standards and best practices to guide industry in reducing cyber risks to the networks and computers that are vital to the nation’s economy, security and daily life.
President Obama called for the Cybersecurity Framework in his Improving Critical Infrastructure Cybersecurity Executive Order. In accordance with the Executive Order, the Secretary of Commerce has directed the Director of NIST to lead the development of a framework to reduce cyber risks to critical infrastructure, such as power plants and financial, transportation and communications systems. NIST will issue a Request for Information from critical infrastructure owners and operators, federal agencies, state, local, territorial and tribal governments, standards-setting organizations, other members of industry, consumers, solution providers and other stakeholders.
NIST will use the input gathered to identify existing consensus standards, practices and procedures that have been effective and that can be adopted by industry to protect its digital information and infrastructure from the full range of cybersecurity threats. The framework will not dictate “one-size-fits-all” solutions, but will instead enable innovation by providing guidance that is technology neutral and recognizes the different needs and challenges within and among critical infrastructure sectors.
It will include metrics, methods and procedures that can be used to continuously assess and monitor the effectiveness of deployed security controls as well as the effectiveness of framework standards, guidelines and best practices. The framework will provide a menu of management, operational and technical security controls, including policies and processes; and will lay a foundation for the development of effective conformity assessment based on NIST’s guidelines.
More information on the Cybersecurity Framework can be found at www.nist.gov/itl/cyberframework.cfm.
More information on the president’s Improving Critical Infrastructure Executive Order can be found at: http://www.whitehouse.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity.
Source: U.S. Department of Commerce