From: BankInfoSecurity

Experts Gather in Dallas to Refine Best Practices Guide

By Eric Chabrow

More than 500 industry and government representatives are gathering in Dallas this week to help shape the cybersecurity framework President Obama wants implemented by February. They’re tackling a wide range of topics, including the role of cyber-insurance and how to apply the framework to a diverse range of industries.

This is the fourth and final workshop sponsored by the National Institute of Standards and Technology to help determine what should be incorporated into the framework, a compendium of IT security best practices that operators of the nation’s critical infrastructure could voluntarily adopt. A preliminary draft of the framework will be issued in October, with the final version to be published in February, a year after Obama signed an executive order calling for it (see Obama Issues Cybersecurity Executive Order).

Because the government can’t force the mostly privately owned critical infrastructure operators to adopt the framework, its drafters – who include industry and government experts – seek incentives to get buy-in from infrastructure operators.

Defining Incentives

Incentives, in cybersecurity framework parlance, are a wide range of offerings or conditions that promote adoption of the framework. Obama’s executive order says incentives could include technical and public policy measures that improve cybersecurity without creating barriers to innovation, economic growth and the free flow of information.

One of the incentives expected to be included in the framework is cyber-insurance; it’s seen as a way for infrastructure owners to mitigate risk. This week’s workshop at the University of Texas at Dallas features an insurance panel with representatives from insurance carriers and brokers.

Obama, in his executive order, called on the departments of Commerce, Homeland Security and Treasury to recommend incentives to drive infrastructure operators to adopt the framework, and all three agencies saw a role for the insurance industry (see Cyber-Insurance: Not One-Size-Fits-All).

Adam Sedgewick,  the NIST senior IT policy adviser who’s coordinating the effort to create the framework, says the insurance industry provides a unique perspective on cybersecurity risk
and how infrastructure operators could manage it. “The information they provide [could] make sure that the framework is something that can be picked up and used,” Sedgewick says.

Read Complete Article