Article

New U.S. Cybersecurity Framework Aims to Help Organizations Manage Risks

Jan 01, 0001

April 2014 By Mark Scott, J.D., CFE On February 12, 2014, the National Institute of Standards and Technology (NIST) released the “Framework for Improving Critical Infrastructure Cybersecurity” (Cybersecurity Framework), a tool designed to establish a baseline of security best practices that organizations can use to measure and mitigate cybersecurity risks.

April 2014

By Mark Scott, J.D., CFE

 

On February 12, 2014, the National Institute of Standards and Technology (NIST) released the “Framework for Improving Critical Infrastructure Cybersecurity” (Cybersecurity Framework), a tool designed to establish a baseline of security best practices that organizations can use to measure and mitigate cybersecurity risks.


The Cybersecurity Framework was written primarily for individuals in management who are responsible for the security of their organizations’ information assets, but because Certified Fraud Examiners (CFEs) are uniquely qualified to assist organizations in the prevention and detection of fraud, they should be familiar with the provisions presented in the framework.


Background

In response to growing concerns about the security of information and communications technology, U.S. President Barack Obama in February of last year issued Executive Order 13636, which directed NIST, a non-regulatory technology agency within the U.S. Department of Commerce, to develop a framework for protecting critical infrastructure from cybersecurity risks.


To develop the framework, NIST worked over the course of a year with more than 3,000 individuals and organizations from the public and private sectors.


The resulting Cybersecurity Framework “allows organizations — regardless of size, degree of cyber risk or cybersecurity sophistication — to apply the principles and best practices of risk management” to improve cybersecurity across all industries, according to NIST.


Application and Effect

The Cybersecurity Framework is voluntary and limited in its application, yet it will likely have a far-reaching effect on organizations across industries and national boundaries.


The Cybersecurity Framework only applies to organizations operating in the U.S. critical infrastructure, but the definition of critical infrastructure is broad and encompasses a large number of sectors — it refers to assets that are vital for a functioning society and economy, and includes, among other sectors, banking and finance, chemicals, communications, energy, food and agriculture, health care, information technology, transportation, materials and waste, and water.


The Cybersecurity Framework’s application to organizations outside of critical infrastructure sectors is uncertain. Experts, however, warn that the framework could become the de facto standard that courts and regulators use to determine what cybersecurity practices are reasonable. Thus, organizations outside of critical infrastructure sectors might face pressure to conform to the Cybersecurity Framework.


Despite its applicability limits, the Cybersecurity Framework provides a universal taxonomy of security standards, guidelines and practices that is not industry or country specific, and therefore, any organization, regardless of size, industry or location, can use the Cybersecurity Framework to strengthen its cybersecurity efforts.


Further, the NIST has stressed that the Cybersecurity Framework has the potential for international application. It can foster international cooperation aimed at strengthening critical infrastructure cybersecurity, and it can contribute to the development of internationally accepted cybersecurity standards.


Summary of the Cybersecurity Framework

In short, the Cybersecurity Framework provides organizational management with guidance on assessing existing cybersecurity practices, setting cybersecurity goals that align with the business needs, and instituting plans to improve or sustain the cybersecurity policies and programs. It proceeds to do this via three primary components:

 

The Framework Core

The Framework Implementation Tiers

The Framework Profile

 

The Framework Core

The Framework Core provides activities and standardized criteria that management can use to address cybersecurity risks, and it organizes those activities and standards around five basic security functions:

 

Identifying cybersecurity risks and vulnerabilities

Using appropriate safeguards to protect assets from cybersecurity threats

Detecting the occurrence of cybersecurity events

Taking action in response to cybersecurity events

Recovering from any damages resulting from cybersecurity events

 

The core functions are subdivided into categories and subcategories, and each subcategory references specific standards, guidelines, and best practices that provide additional, more detailed guidance for specific cybersecurity activities.


The Framework Implementation Tiers

The Framework Implementation Tiers categorize cybersecurity practices into four levels of risk management sophistication, ranging from informal and reactive to formal, agile and risk-informed. These tiers provide a way for organizations to assess the efficacy of their cybersecurity practices.


The Framework Profile

The Framework Profile provides guidance to management teams trying to determine what actions are needed to improve their cybersecurity practices. It recommends that each organization develop a Current Profile, reflecting its current state of cybersecurity practices, and a Target Profile, reflecting a desired future state that satisfies its business needs. Once an organization has developed its Current and Target Profiles, it can compare them to identify the actions needed to reach its desired future state of cybersecurity practices. 


A Flexible, Living Document

The Cybersecurity Framework is a flexible, living document that will be modified and updated periodically, particularly to reflect industry feedback and to accommodate technological change over time. The framework “is expected to be a first step in a continuous process to improve the nation's cybersecurity,” NIST wrote.


Conclusion

The Cybersecurity Framework provides a standardized approach to cybersecurity that any organization, regardless of size, industry or location, can use as guidance when addressing concerns about information security. And as a result of its standardized approach, the Cybersecurity Framework has the potential for broad impact. Accordingly, CFEs and other professionals concerned with cybersecurity should familiarize themselves with the Framework and stay abreast of any regulatory and industry efforts to implement its provisions.


For more information about the Cybersecurity Framework or to download a copy, visit the NIST website.