NIST begins Cyber security initiative under White House plan
From: Government Security News
By: Mark Rockwell
The National Institute of Standards and Technology (NIST) on Feb. 13 began its work to help establish the common, voluntary framework that will support critical infrastructure’s Cyber security under president Obama’s new executive order.
NIST said it will issue a Request for Information from critical infrastructure owners and operators, federal agencies, state, local, territorial and tribal governments, standards-setting organizations, other members of industry, consumers, solution providers and other stakeholders.
The agency said it would use that input to identify existing consensus standards, practices and procedures that have been effective and that can be adopted by industry to protect its digital information and infrastructure from the full range of Cyber security threats. The framework, it said, won’t dictate “one-size-fits-all” solutions, but will provide technology-neutral guidance recognizing the different needs and challenges within and among critical infrastructure sectors.
“As we move forward with the Cyber security Framework, NIST will be collecting input from a wide variety of stakeholders to come up with an effective set of voluntary standards that will safeguard our nation’s most critical infrastructure from Cyber security threats,” said Deputy Secretary of Commerce Rebecca Blank.
In its official Request for Information, to be published in the Federal Register, NIST said it would ask organizations to share their current risk management practices; use of frameworks, standards, guidelines and best practices; and other industry practices. The agency also plans to hold workshops over the next several months to collect additional input and will complete the framework within one year.
“The process for developing the framework reflects a core component of NIST’s work, bringing together various stakeholders to address a technical challenge,” said Under Secretary of Commerce for Standards and Technology and NIST Director Patrick Gallagher. “By collaborating with industry to develop the framework, we will better protect our nation from the Cyber security threat while enhancing America’s ability to innovate and compete in a global market.”
The RFI, it said, will request additional information on a number of core practices NIST views as applicable across industry, for example:
- Encryption and key management—With multiple encryption tools in use at any given organization, how does one protect, store and organize encryption keys?
- Asset identification and management—How does an organization determine which assets need protection and their value?
- Security engineering practices—How does an organization design its systems to meet security needs?
NIST said the framework will consist of a roadmap and structure for future efforts, including a recommended process for how the standards within each sector will be reviewed by each stakeholder community.
The agency said the framework would include metrics, methods and procedures that can be used to continuously assess and monitor the effectiveness of deployed security controls as well as the effectiveness of framework standards, guidelines and best practices. The framework, it said, will provide a menu of management, operational and technical security controls, including policies and processes; and will lay a foundation for the development of effective conformity assessment based on NIST’s guidelines.
| Print article |