NIST Drafts Major Update to Its Widely Used Cybersecurity Framework

AMTV/Gaithersburg, MD, Aug 8 – The world’s leading cybersecurity guidance is getting its first complete makeover since its release nearly a decade ago.

After considering more than a year’s worth of community feedback, the National Institute of Standards and Technology (NIST) has released a draft version of the Cybersecurity Framework (CSF) 2.0, a new version of a tool it first released in 2014 to help organizations understand, reduce and communicate about cybersecurity risk. The draft update, which NIST has released for public comment, reflects changes in the cybersecurity landscape and makes it easier to put the CSF into practice — for all organizations.

“With this update, we are trying to reflect current usage of the Cybersecurity Framework, and to anticipate future usage as well,” said NIST’s Cherilyn Pascoe, the framework’s lead developer. “The CSF was developed for critical infrastructure like the banking and energy industries, but it has proved useful everywhere from schools and small businesses to local and foreign governments. We want to make sure that it is a tool that’s useful to all sectors, not just those designated as critical.”

NIST is accepting public comment on the draft framework until Nov. 4, 2023. NIST does not plan to release another draft. A workshop planned for the fall will be announced shortly and will serve as another opportunity for the public to provide feedback and comments on the draft. The developers plan to publish the final version of CSF 2.0 in early 2024.

The CSF provides high-level guidance, including a common language and a systematic methodology for managing cybersecurity risk across sectors and aiding communication between technical and nontechnical staff. It includes activities that can be incorporated into cybersecurity programs and tailored to meet an organization’s particular needs. In the decade since it was first published, the CSF has been downloaded more than two million times by users across more than 185 countries and has been translated into at least nine languages.

While responses to NIST’s February 2022 request for information about the CSF indicated that the framework remains an effective tool for reducing cybersecurity risk, many respondents also suggested that an update could help users adjust to technological innovation as well as a rapidly evolving threat landscape.

“Many commenters said that we should maintain and build on the key attributes of the CSF, including its flexible and voluntary nature,” Pascoe said. “At the same time, a lot of them requested more guidance on implementing the CSF and making sure it could address emerging cybersecurity issues, such as supply chain risks and the widespread threat of ransomware. Because these issues affect lots of organizations, including small businesses, we realized we had to up our game.”

The CSF 2.0 draft reflects a number of major changes, including:

The framework’s scope has expanded — explicitly — from protecting critical infrastructure, such as hospitals and power plants, to providing cybersecurity for all organizations regardless of type or size. This difference is reflected in the CSF’s official title, which has changed to “The Cybersecurity Framework,” its colloquial name, from the more limiting “Framework for Improving Critical Infrastructure Cybersecurity.”

Until now, the CSF has described the main pillars of a successful and holistic cybersecurity program using five main functions: identify, protect, detect, respond and recover. To these, NIST now has added a sixth, the govern function, which covers how an organization can make and execute its own internal decisions to support its cybersecurity strategy. It emphasizes that cybersecurity is a major source of enterprise risk, ranking alongside legal, financial and other risks as considerations for senior leadership.

The draft provides improved and expanded guidance on implementing the CSF, especially for creating profiles, which tailor the CSF for particular situations. The cybersecurity community has requested assistance in using it for specific economic sectors and use cases, where profiles can help. Importantly, the draft now includes implementation examples for each function’s subcategories to help organizations, especially smaller firms, to use the framework effectively.

A major goal of CSF 2.0 is to explain how organizations can leverage other technology frameworks, standards and guidelines, from NIST and elsewhere, to implement the CSF.

Bolstering this last effort will be the launch of a CSF 2.0 reference tool, which NIST plans to release in a few weeks. This online resource will allow users to browse, search and export the CSF Core data in human-consumable and machine-readable formats. In the future, this tool will provide “Informative References” to show the relationships between the CSF and other resources to make it easier to use the framework together with other guidance to manage cybersecurity risk.

Pascoe said the development team is encouraging anyone with recommendations about the updated CSF to respond with comments by the Nov. 4 deadline.
“This is an opportunity for users to weigh in on the draft of CSF 2.0,” she said. “Now is the time to get involved if you’re not already.”

AMTV

Share
Published by
AMTV

Recent Posts

沃尔格林将提供更便宜的阿片类药物过量逆转药物纳洛酮

全美电视5月15日迪尔菲尔德报道,美国药店零售商沃尔格林(Walgreens)今天表示,将推出更便宜的非处方阿片类药物过量逆转喷雾纳洛酮,这种药可以在其网站上买到,并将在本月底在所有线下商店出售。 总部位于伊利诺伊州迪尔菲尔德的沃尔格林的目标,是提高这种救命药物在美国的可获得性,因为美国正在努力应对阿片类药物的流行,并试图降低高得惊人的药物死亡率。 根据美疾病控制和预防中心(CDC)的最新数据,从1999年到2021年,超过64.5万人死于过量服用任何阿片类药物,包括处方和非法阿片类药物。 如果及时给药,纳洛酮可以暂时逆转过量服用阿片类药物,包括海洛因和芬太尼的影响。这种药物阻断阿片类药物对大脑的影响,恢复正常呼吸,防止死亡。 根据沃尔格林的一份新闻稿,尽管纳洛酮很有效,但在许多社区,获得这种治疗的机会“仍然有限”。 该公司表示,将以34.99美元的价格出售两剂“沃尔格林品牌纳洛酮”。这比非处方品牌药物纳洛酮便宜10美元左右,纳洛酮是去年获得美国食品和药物管理局(FDA)批准的首个无需处方的纳洛酮。以前,患者需要处方才能获得纳洛酮。 沃尔格林临床诚信办公室高级医学主任普里亚·曼曼(Priya Mammen)博士在接受媒体采访时表示:“这是一个一致的决定,我们真的尽一切努力提高可及性,不仅在数量和可用性方面,而且在价格方面。” 普里亚·曼曼博士表示,希望沃尔格林可以帮助减少与药物过量和纳洛酮使用有关的耻辱,这种药物“不仅仅适用于某些人。这是一种挽救生命的药物,可以在任何年龄、任何时间对任何人进行干预,家庭、个人和社区可以通过获得它来增强自己的能力,并可以成为解决方案的一部分。” 沃尔格林表示,在美国食品和药物管理局最近批准该产品后,推出了其无处方纳洛酮鼻喷雾剂。它相当于非处方的纳洛酮,沃尔格林目前在其连锁药店门店出售。 Reporter: Jason Quin, Wen Liu

5 hours ago

美国4月份通胀有所缓解,消费者价格仍较上年同期上涨3.4%

全美电视5月15日华盛顿报道,美国劳工部劳工统计局(BLS)今天公布,消费者价格指数(CPI)较3月份上涨0.3%。消费者价格指数是衡量收银机上商品和服务价格的一个宽泛指标。这略低于道琼斯预测的0.4%。在12个月的基础上,CPI增长了3.4%,符合预期。 报告显示4月份通胀略有放缓,但仍高于暗示美联储即将降息的水平。剔除食品和能源后,关键核心通胀率环比0.3%,同比3.6%,均与预期相符。核心12个月通胀指数是自2021年4月以来的最低水平,而月度涨幅是自去年12月以来的最小水平。 该数据公布后,美国市场反应积极,与主要股指挂钩的期货上涨,美国国债收益率暴跌。期货交易员提高了美联储(Fed)将于9月开始降息的隐含可能性。 美国商务部的今天在一份报告中表示,当月零售额与上月持平,而此前的预期是增长0.4%。这一数据经季节性因素调整,但未考虑通胀因素,表明消费者没有跟上价格上涨的步伐。 就美国通胀报告而言,6月份的价格上涨在很大程度上受到住房和能源价格上涨的推动。 住房成本一直是美联储官员预期通胀今年会回落的一个特别麻烦的地方。住房成本本月上涨0.4%,较上年同期上涨5.5%。对于试图将整体通胀率降至2%的美联储来说,这两个水平都高得令人不安。 能源指数一个月上涨1.1%,较上年同期上涨2.6%。食品价格持平,上涨2.2%。在新冠病毒疫情最严重时期,二手车和新车价格都有所下降,分别下降1.4%和0.4%。 本月显著增长的领域包括服装1.2%、运输服务0.9%和医疗服务0.4%。交通运输服务业同比增长11.2%。不包括政策制定者一个关键指标的能源在内的服务业,环比增长了0.4%,同比增长5.3%。 通货膨胀率的上升对劳工们来说是个坏消息,经通胀因素调整后,他们的收入较上月下降了0.2%。以12个月为基础,实际收益仅增长0.5%。 在住房组成部分,主要住宅的租金和重要业主等效租金,即房主认为他们可以从自己的房产中获得的租金,均较上月上涨0.4%。它们在12个月的基础上分别增长了5.4%和5.8%。 数据显示,零售销售令人失望。消费者显然仍然感受到本月物价上涨的压力。4月份零售额的预估与3月份相比没有变化,3月份的预估向下修正为增长0.6%。不过,销售额同比增长了3%。扣除汽车后,销售增长0.2%,符合道琼斯的预期。 数据还显示,在线收入下降1.2%拖累了销售数据,体育用品及相关商店的销售额下降0.9%,汽车和零部件经销商的销售额下降0.8%。受汽油价格上涨的推动,汽油的价格上涨了3.1%,而电子产品和电器的价格上涨了1.5%。 所谓的控制组下降了0.3%。控制组剔除了一些项目,并将其纳入美国商务部的国内生产总值(GDP)计算。 这些报告出炉之际,美联储自2023年7月以来一直暂停加息,因为事实证明通胀比预期更具弹性。政策制定者最近几周表示,在同意降息之前,他们需要更多证据证明通胀正在可持续地回到2%的目标水平。 美联储的基准隔夜贷款利率目标在5.25%-5.5%之间,为23年来的最高水平。…

10 hours ago

拜登和特朗普同意在6月27日和9月10日举行总统辩论

全美电视5月15日华盛顿报道,美国总统乔·拜登(Joe Biden)和前总统唐纳德·特朗普(Donald Trump)今天接受了美国有线电视新闻网(CNN)和美国广播公司(ABC)的邀请,将在6月27日和9月10日举行总统辩论。 根据拜登竞选团队制定的条件,这些辩论应该由任何监督过特朗普参加的2016年共和党初选辩论和拜登参加的2020年民主党初选辩论的媒体机构主持。符合这些条件的媒体是哥伦比亚广播公司CBS、美国广播公司ABC、美国有线电视新闻网CNN和西班牙语电视台Telemundo。2016年特朗普参加过Telemundo和CNN举办的共和党初选辩论。 拜登竞选团队今天在一封信中表示,他愿意在11月大选前与特朗普进行两次辩论后,辩论计划很快就制定出来了。这引发了民主党和共和党候选人的一系列提案和社交媒体帖子,最终导致定于6月和9月举行两场辩论。 拜登今天在社交媒体上确认,他已接受邀请参加6月27日由CNN主持的辩论,并敦促特朗普加入他的行列,拜登在社交媒体上发帖说:“我已经收到并接受了CNN的邀请,参加6月27日的辩论。”“就像你说的:任何地方、任何时间、任何地点。” CNN随后宣布,将于美国东部时间6月27日晚9点在其亚特兰大演播室主持拜登和特朗普之间的辩论。CNN表示,“为了确保候选人可以最大限度地利用辩论的时间”,不会有观众。 CNN列出了参加辩论的五条标准。候选人必须:1、依照宪法规定有资格担任总统。2、向联邦选举委员会提交参选声明。3、名字出现在足够多的州选票上,以达到赢得总统职位所需的270张选举人票的门槛。4、同意辩论的规则和形式。5、在四个独立的全国民意调查中获得至少15%的符合CNN标准的注册或潜在选民。 拜登和特朗普是迄今为止仅有的两位符合这些条件的总统候选人,且辩论是一对一的,所以独立候选人小罗伯特·肯尼迪(Robert Kennedy, Jr.)不太可能有机会出现在辫论舞台上。 CNN的辩论将在共和党和民主党的提名大会之前举行,届时两党代表将选出各自的总统候选人。 此外,拜登还宣布,他已收到并接受邀请参加9月10日周二由美国广播公司新闻(ABC News)主持的第二场辩论。特朗普很快表示,他也将出席。他的竞选团队还在争取在7月和8月再举行两场辩论。 拜登在今年3月中旬获得民主党总统候选人提名,特朗普在今年3月中旬也获得了共和党总统候选人提名,这将是拜登和特朗普自2020年总统竞选以来的再次对决。…

10 hours ago

WHO prequalifies new dengue vaccine

AMTV/ Geneva, 15 May - A new vaccine for dengue received prequalification from the World…

14 hours ago

美国七个战场州中监督选举的近80名官员怀疑2020年大选结果

全美电视5月14日内华达州瓦肖县报道,根据美国媒体哥伦比亚广播公司(CBS)的一项新调查发现,在包括内华达州在内的七个战场州,有近 80 名在选举监督岗位上工作的官员,怀疑2020 年美国总统大选结果,并拒绝认证拜登当选结果。 美国内华达州瓦肖县(Washoe County)共和党的执行委员会成员比德尔斯 (Robert Beadles) 认为,2020年选举被操纵了。自2022 年以来,比德尔斯一直在游说支持该县选举委员会其他委员提出的投票改革,其中包括取消投票机,改用手工计票纸质选票,并在投票站部署国民警卫队,美国公民自由联盟(ACLU)则声称这些措施“绝对非法”。 比德尔斯在当地学校董事会、市议会和州立法机构的地方选举中投入了大量资金,还花费了 10 多万美元支持该县委员会竞选,特别是支持现任5名委员中两位委员赫尔曼(Jeannie Herman)和克拉克(Michael Clark),他的目标是在委员会中建立多数席位来推动他的议程。…

1 day ago