The NIST Cybersecurity Framework

The Framework provides a tangible foundation for which individuals or organizations can conceptualize the virtual systems/processes used in the modern day in regards to risk management through the lens of cybersecurity. It allows an organization to analyze its cybersecurity posture, where they want to be with their cyber defense and its progress, and being able to quantify that to both communicate and further analyze the position of cybersecurity. Given the Frameworks organic and constantly evolving nature it allows it to be applied to almost any given situation and since it is technologically neutral it remains usefully in the constant progressive world. This is extremely pragmatic for organizations to use because it provides an operational structure to work through. The implementation of tiers also also for different threats and vulnerabilities to be quantified in terms of risk factor. Being able to express the importance of this risk to non cybersecurity disciplines is crucial to the cohesion of the effort.

I would use The Framework in an occupational setting to analyze and work to make the cybersecurity process one which is both more easily understood to those outside of the field but need to understand the summarized points and diligently follow the processes of The Framework Core to do this. Also given my fledgling understanding my current goal would be to bring a mastery of the basics and with the knowledge of the Framework it allows gives a mental structure to work through and a path to learn. 

References:

-NIST. (2018). Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1. Framework for Improving Critical Infrastructure Cybersecurity, 1.1(1.1). https://doi.org/10.6028/nist.cswp.04162018

Leave a Reply

Your email address will not be published. Required fields are marked *