The NIST Cybersecurity Framework

The NIST Cybersecurity Framework (CSF) is a tool that organization’s use in order to secure their infrastructure. In this case, infrastructure can be characterized as the organization’s physical structure or the means needed for the organization to operate. A benefit of this is that it gives the company a point of reference to analyze their risk management framework. This is imperative because cyber security is not just a technology issue, but is also a risk management issue. By having guidelines already put in place, employees are able to more readily avoid risks and mitigate harmful cyber security breaches. Implementing the NIST CSF will thereby reduce decrease response time, downtime, and secure company assets. I would use this at my future workplace in order to improve the overall security posture of my organization. Personally, I would judge all my decisions against NIST CSF and take on a risk-based attitude. If I were in a management role then I would make it a requirement for employees to familiarize themselves with the NIST CSF because it won’t do us any good if even one person is not security conscious and compromises our assets. Another practical way to implement this framework is to schedule regular incidents and to monitor our teams response to said incident by keeping a record on the course of action taken and the time it took to execute.

Leave a Reply

Your email address will not be published. Required fields are marked *