Initial Summary Analysis of Responses to the Request for Information (RFI) Evalu ating and Improving Cybersecurity Resources: The Cybersecurity Framework and Cyb ersecurity Supply Chain Risk Management National Institute of Standards and Technology (NIST) June 3, 2022 Introduction On February 22, 2022, NIST issued a public Request for Information (RFI), “ Evaluating and Improving NIST Cybersecurity Resources: The Cybersecurity Framework and Cybersecurity Supply Chain Risk Management .” The RFI sought information on the use of the NIST Cybersecurity Framework as well as recommendations to improve the effectiveness of the Framework and its alignment with other cyberse curity resources. The RFI also sought suggestions to inform other cybersecurity efforts at NIST , especially related to supply chain cybersecurity risks. When the RFI was issued , Commerce Deputy Secretary Don Graves stated: “ Ever y organization needs to manage cybersecurity risk as a part of doing business, whether it is in industry, government or academia...It is critical to their resilience and to our nation’s economic security. There are many tools available to help, and the CSF is one of the leading frameworks for private sector cybersecurity maintenance. We want private and public sector organizations to help make it even more useful and widely used, including by small companies.” This document represents an initial, high -level summary of the RFI responses. NIST received more than 130 RFI responses, including many comments submitted jointly by multiple organizations or associations representing numerous organizations. The responses can be found on the NIST CSF website. Figure 1 RFI Responses Received by Category Summary Analysis of Responses to the Cybersecurity RFI Page 2 Figure 2 RFI Responses Received by Subc ategory The NIST Framework for Improving Critical Infrastructure Cybersecurity (also called Cybersecurity Framework , Framework , or CSF) was released in February 2014 after extensive public engagement and collaboration. The Framework serves as a prominent resource to manage cybersecurity risks holistically across an organization. It has been downloaded over 1.7 million times and is used by organizations of varying sectors, sizes, and locations . It has been adopted internationally, with the English version complemented by nine translations . The CSF was intended to be a living document that is refined, improved, and evolves over time to keep pace with technology and threat trends, integrate lessons learned, and move best practice to common practice. NIST updated the Framework in April 2018 with CSF 1.1. Based on the RFI responses, and in order t o keep pace with the ever -evolving cybersecurity landscape and to help organizations more easily and effectively manage cybersecurity risk, NIST is planning a new update to the Framework. The RFI also sought information on the challenges organizations are facing from a technology supply chain perspective to inform the NIST -led public -private partnership, the National Initiative for Improving Cybersecurity in Supply Chains (NIICS) . NIST requested information about needed supply chain tools and guidance , as well as how NIICS might be aligned and integrated with the CSF. Summary Analysis of Responses to the Cybersecurity RFI Page 3 This summary analysis will serve as a starting point for scoping the update to the NIST Cybersecurity Framework, as well as scoping NIICS . NIST intends to continue to rely on and seek stakeholder feedback throughout the process to update the Framework. This will include public webinars and workshops, as well as feedback on at least one Framework draft

pdf文档 NIST-Cybersecurity-RFI-Summary-Analysis-Final

安全标准 > NIST > 文档预览
中文文档 32 页 50 下载 1000 浏览 0 评论 0 收藏 3.0分
温馨提示:本文档共32页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
NIST-Cybersecurity-RFI-Summary-Analysis-Final 第 1 页 NIST-Cybersecurity-RFI-Summary-Analysis-Final 第 2 页 NIST-Cybersecurity-RFI-Summary-Analysis-Final 第 3 页
下载文档到电脑,方便使用
本文档由 思安2022-12-05 09:21:22上传分享
给文档打分
您好可以输入 255 个字符
网站域名是多少( 答案:github5.com )
评论列表
  • 暂时还没有评论,期待您的金玉良言
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。