Skip to content

Latest commit

 

History

History
62 lines (44 loc) · 2.49 KB

File metadata and controls

62 lines (44 loc) · 2.49 KB

NIST

NIST Cyber Security Framework CSF

image

NIST CSF Tools

image

Visualize Security Frameworks and Controls (CSF + Privacy)

https://www.youtube.com/watch?v=Xyfd7zetqRw&list=PL54zsqeZFN_SLvBpsAPg0mieo0p37glPk

image

Identify

  • Which data is where?
  • Know Threats
  • Understanding Supply Chain Risk (SCR)

Protect

  • Awareness & Training
  • Red Teaming & Bug Bounty
  • New approaches such as Zero Trust

Detect

  • Continuous Security Monitoring (SOC)
  • Security Operation Center Automation (SOAR)

Respond

  • Computer Security Incident Response Team (CSRIT)
  • Crisis Management & Exercises (TTX)
  • Continuous Improvement (CI)

Recover

  • Communication
  • Service Continuity
  • Business Continuity Management (BCM)
  • Desaster Recovery (DR)

Govern

  • Take Responsibility

NIST Risk Management Framework RMF

image

The NIST Risk Management Framework (RMF) and the NIST Special Publications (SP) 800-53, 800-53A, and 800-53B are interconnected, providing a comprehensive approach to managing security and privacy risks in federal information systems.

Essential activities to prepare the organization to manage security and privacy risks Categorize the system and information processed, stored, and transmitted based on an impact analysis Select the set of NIST SP 800-53 controls to protect the system based on risk assessment(s) Implement the controls and document how controls are deployed Assess to determine if the controls are in place, operating as intended, and producing the desired results Senior official makes a risk-based decision to authorize the system (to operate) Continuously monitor control implementation and risks to the system

image