Industry Highlights NIST Cybersecurity Framework's Value As NIST Weighs A Potential Update

WR
Wiley Rein

Contributor

Wiley is a preeminent law firm wired into Washington. We advise Fortune 500 corporations, trade associations, and individuals in all industries on legal matters converging at the intersection of government, business, and technological innovation. Our attorneys and public policy advisors are respected and have nuanced insights into the mindsets of agencies, regulators, and lawmakers. We are the best-kept secret in DC for many of the most innovative and transformational companies, business groups, and nonprofit organizations. From autonomous vehicles to blockchain technologies, we combine our focused industry knowledge and unmatched understanding of Washington to anticipate challenges, craft policies, and formulate solutions for emerging innovators and industries.
Public comments in an ongoing cybersecurity proceeding at the National Institute of Standards and Technology (NIST) highlight the utility of a foundational cybersecurity document...
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Public comments in an ongoing cybersecurity proceeding at the National Institute of Standards and Technology (NIST) highlight the utility of a foundational cybersecurity document while also providing suggestions for its improvement. NIST has begun to evaluate the 130 comments it received in response to its Request for Information (RFI) related to evaluating and improving its flagship cybersecurity guidance document, the Framework for Improving Critical Infrastructure Cybersecurity (CSF). NIST is seeking to determine whether and how to update the CSF, which is used widely across the globe by organizations of all sizes. The RFI also sought comment on NIST's National Initiative for Improving Cybersecurity in Supply Chains (NIICS) – a new public-private partnership that will seek to address cybersecurity supply chain risk management (C-SCRM) issues – as well NIST's other C-SCRM efforts.

Commenters and Consensus

The record reflects a diverse group of participants, including trade associations, industry coalitions, individual companies, standards organizations, and security vendors. Several federal agencies also submitted comments, including the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Aviation Administration (FAA), and the U.S. Department of Energy.

The record reflects a general consensus that the CSF is relied upon heavily and that significant changes would be disruptive to its usability and longevity. Many organizations discussed the CSF's utility as a flexible, voluntary, and risk-based document that can be applied in a variety of different use cases. Indeed, it is critical that companies pay attention to the CSF's consensus-based and voluntary approach to cybersecurity as the federal government pursues new regulatory approaches to addressing cybersecurity risks.

Suggested Changes

Beyond the general agreement on the CSF's utility, the record reflects a wide range of suggestions, both for improving the CSF and for guiding the NIICS. Several commenters sought targeted changes to the CSF. For example, several communications and technology trade associations recommended that NIST update the Informative References that it provides on its Informative Reference Catalog and map the CSF to additional frameworks, regulations, and standards. With respect to the NIICS, many commenters recommended that NIST coordinate and harmonize its C-SCRM efforts with other ongoing federal C-SCRM initiatives.

Certain commenters sought more extensive changes to the CSF. For example, a few commenters sought significant changes to the C-SCRM portion of the CSF, including changes to the CSF's Categories and Subcategories. However, many of the commenters who addressed C-SCRM discouraged NIST from building a new C-SCRM framework separate from the CSF. Several individual companies and security vendors suggested incorporating more metrics into the CSF, while others recommended adding more privacy and data protection elements to the CSF.

NIST plans to hold additional workshops to gain further perspectives on potential changes to the CSF. It is likely that NIST will also release public drafts of the updated CSF, which would provide additional opportunities for the public to provide feedback. Wiley's Cyber and Privacy Investigations, Incidents & Enforcement team has helped entities of all sizes and sectors proactively address their cybersecurity risks, including through advocacy at NIST. If you would like more information on this proceeding, please reach out to any of the authors of this article.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

Industry Highlights NIST Cybersecurity Framework's Value As NIST Weighs A Potential Update

United States Technology

Contributor

Wiley is a preeminent law firm wired into Washington. We advise Fortune 500 corporations, trade associations, and individuals in all industries on legal matters converging at the intersection of government, business, and technological innovation. Our attorneys and public policy advisors are respected and have nuanced insights into the mindsets of agencies, regulators, and lawmakers. We are the best-kept secret in DC for many of the most innovative and transformational companies, business groups, and nonprofit organizations. From autonomous vehicles to blockchain technologies, we combine our focused industry knowledge and unmatched understanding of Washington to anticipate challenges, craft policies, and formulate solutions for emerging innovators and industries.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More