Framework for Improving Critical Infrastructure Cybersecurity Version 1.1 National Institute of Standards and Technology April 16, 2018 c . 5 b u h t i g m o April 16, 2018 Cybersecurity Framework Version 1.1 Note to Readers on the Update Version 1.1 of this Cybersecurity Framework refines, clarifies, and enhances Version 1.0, which was issued in February 2014. It incorporates comments received on the two drafts of Version 1.1. Version 1.1 is intended to be implemented by first-time and current Framework users. Current users should be able to implement Version 1.1 with minimal or no disruption; compatibility with Version 1.0 has been an explicit objective. The following table summarizes the changes made between Version 1.0 and Version 1.1. Table NTR-1 - Summary of changes between Framework Version 1.0 and Version 1.1. Update Clarified that terms like “compliance” can be confusing and mean something very different to various Framework stakeholders Description of Update Added clarity that the Framework has utility as a structure and language for organizing and expressing compliance with an organization’s own cybersecurity requirements. However, the variety of ways in which the Framework can be used by an organization means that phrases like “compliance with the Framework” can be confusing. m o A new section on selfassessment c . 5 Added Section 4.0 Self-Assessing Cybersecurity Risk with the Framework to explain how the Framework can be used by organizations to understand and assess their cybersecurity risk, including the use of measurements. Greatly expanded An expanded Section 3.3 Communicating Cybersecurity explanation of using Requirements with Stakeholders helps users better understand Framework for Cyber Cyber Supply Chain Risk Management (SCRM), while a new Supply Chain Risk Section 3.4 Buying Decisions highlights use of the Framework Management purposes in understanding risk associated with commercial off-the-shelf products and services. Additional Cyber SCRM criteria were added to the Implementation Tiers. Finally, a Supply Chain Risk Management Category, including multiple Subcategories, has been added to the Framework Core. Refinements to better The language of the Access Control Category has been refined account for authentication, to better account for authentication, authorization, and identity authorization, and identity proofing. This included adding one Subcategory each for proofing Authentication and Identity Proofing. Also, the Category has been renamed to Identity Management and Access Control (PR.AC) to better represent the scope of the Category and corresponding Subcategories. Better explanation of the Added language to Section 3.2 Establishing or Improving a relationship between Cybersecurity Program on using Framework Tiers in Implementation Tiers and Framework implementation. Added language to Framework Profiles Tiers to reflect integration of Framework considerations within organizational risk management programs. The Framework Tier concepts were also refined. Updated Figure 2.0 to include actions from the Framework Tiers. h t i g b u This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018 ii April 16, 2018 Consideration of Coordinated Vulnerability Disclosure Cybersecurity Framework Version 1.1 A Subcategory related to the vulnerability disclosure lifecycle was added. As with Version 1.0, Version 1.1 users are encouraged to customize the Framework to maximize individual organizational value. m o c . 5 b u h t i g This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018 iii April 16, 2018 Cybersecurity Framework Version 1.1 Acknowledgements This publication is the result of an ongoing collaborative effort involving industry, academia, and government. The National Institute of Standards and Technology (NIST) launched the project by convening private- and public-sector organizations and individuals in 2013. Published in 2014 and revised during 2017 and 2018, this Framework for Improving Critical Infrastructure Cybersecurity has relied upon eight public workshops, multiple Requests for Comment or Information, and thousands of direct interactions with stakeholders from across all sectors of the United States along with many sectors from around the world. The impetus to change Version 1.0 and the changes that appear in this Version 1.1 were based on:      Feedback and frequently as

pdf文档 NIST Framework for Improving Critical Infrastructure Cybersecurity v1.1 英文版

安全标准 > NIST > 文档预览
中文文档 55 页 50 下载 1000 浏览 0 评论 0 收藏 3.0分
温馨提示:本文档共55页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
NIST  Framework for Improving Critical Infrastructure Cybersecurity v1.1 英文版 第 1 页 NIST  Framework for Improving Critical Infrastructure Cybersecurity v1.1 英文版 第 2 页 NIST  Framework for Improving Critical Infrastructure Cybersecurity v1.1 英文版 第 3 页
下载文档到电脑,方便使用
本文档由 路人甲2022-06-17 06:03:20上传分享
给文档打分
您好可以输入 255 个字符
网站域名是多少( 答案:github5.com )
评论列表
  • 暂时还没有评论,期待您的金玉良言
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。