NIST Releases Baldrige-Based Tool for Cybersecurity Excellence

From: NIST

WASHINGTON, D.C.— The U.S. Commerce Department (link is external)’s National Institute of Standards and Technology (NIST) released today the draft Baldrige Cybersecurity Excellence Builder, a self-assessment tool to help organizations better understand the effectiveness of their cybersecurity risk management efforts.

NIST is requesting public comments on the draft document, which blends the best of two globally recognized and widely used NIST resources: the organizational performance evaluation strategies from the Baldrige Performance Excellence Program and the risk management mechanisms of the Cybersecurity Framework.

Deputy Secretary of Commerce Bruce Andrews announced the release of the draft document today during his remarks at the Internet Security Alliance (link is external)’s 15th Anniversary Conference in Washington, D.C.

“The Baldrige Cybersecurity Excellence Builder answers a call from many organizations to provide a way for them to measure how effectively they are using the Cybersecurity Framework,” Andrews said. “The Builder will strengthen the already powerful Cybersecurity Framework so that organizations can better manage their cybersecurity risks.”

Using the Builder, organizations of all sizes and types can:

  • determine cybersecurity-related activities that are important to business strategy and the delivery of critical services;
  • prioritize investments in managing cybersecurity risk;
  • assess the effectiveness and efficiency in using cybersecurity standards, guidelines and practices;
  • assess their cybersecurity results; and
  • identify priorities for improvement.

The Cybersecurity Framework, released in February 2014, was developed by NIST through a collaborative process involving industry, academia and government agencies. NIST was directed by an executive order (link is external) to create the framework specifically for managing cybersecurity risks related to critical infrastructure, but a broad array of public and private sector organizations now use it. The framework provides a risk-based approach for cybersecurity through five core functions—identify, protect, detect, respond and recovery.

***

A 2011 economic report estimated the benefit-to-cost ratio of the Baldrige Program to the U.S. economy at 820 to 1.

Read Complete Article & Watch Video

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *