From: NIST
NIST is accepting public comments and suggestions for the Baldrige Cybersecurity Excellence Builder via e-mail at baldrigecybersecurity@nist.gov (link sends e-mail) through December 15, 2016.
About the Baldrige Cybersecurity Excellence Builder
On September 15, 2016, NIST released a draft of the Baldrige Cybersecurity Excellence Builder (BCEB). The BCEB is a voluntary self-assessment tool that enables organizations to better understand the effectiveness of their cybersecurity risk management efforts. BCEB is based on the time-tested business process of the Baldrige Performance Excellence Program and the core concepts of the Cybersecurity Framework. BCEB was designed to help leaders of organizations identify opportunities for improvement based on their cybersecurity needs and objectives, as well as their larger organizational needs, objectives, and outcomes. Using this self-assessment, organizations can:
- determine cybersecurity-related activities that are important to your business strategy and critical service delivery;
- prioritize investments in managing cybersecurity risk;
- determine how best to enable your workforce, customers, suppliers, partners, and collaborators to be risk conscious and security aware, and to fulfill their cybersecurity roles and responsibilities;
- assess the effectiveness and efficiency of your use of cybersecurity standards, guidelines, and practices;
- assess the cybersecurity results you achieve; and
- identify priorities for improvement.
Like the Framework for Improving Critical Infrastructure Cybersecurity, the BCEB is not a one-size-fits-all approach. It is adaptable and scalable to your organization’s needs, goals, capabilities, and environment. It does not prescribe how you should structure your organization’s cybersecurity policies and operations, but through interrelated sets of open-ended questions, encourages you to use the approaches that best fit your organization.
While NIST invites comments on BCEB at any time, feedback received at baldrigecybersecurity@nist.gov before December 15, 2016 will be adjudicated for inclusion in the final publication of BCEB version 1.
NIST cannot be trusted as a source for info on Internet security. As I showed in the study linked to, like the CIA on WMDs and the supposed Russian hack, NIST got CyberSecurity wrong in its report on Internet voting security. https://www.academia.edu/4430228/How_NIST_has_Misled_Congress_and_the_American_People_about_Internet_Voting_Insecurity
William J. Kelleher, Ph.D.