Framework for Improving Critical Infrastructure Cybersecurity

Similar documents
Framework for Improving Critical Infrastructure Cybersecurity

Critical Infrastructure Cybersecurity Framework. Overview and Status. Executive Order Improving Critical Infrastructure Cybersecurity

How To Write A Cybersecurity Framework

Cybersecurity Framework. Executive Order Improving Critical Infrastructure Cybersecurity

Framework for Improving Critical Infrastructure Cybersecurity

Cybersecurity Framework: Current Status and Next Steps

Executive Order 13636: The Healthcare Sector and the Cybersecurity Framework. September 23, 2014

NIST Cybersecurity Framework. ARC World Industry Forum 2014

Cybersecurity in the Utilities Sector Best Practices and Implementation 2014 Canadian Utilities IT & Telecom Conference September 24, 2014

Framework for Improving Critical Infrastructure Cybersecurity

Framework for Improving Critical Infrastructure Cybersecurity

Applying Framework to Mobile & BYOD

NIST Cybersecurity Initiatives. ARC World Industry Forum 2014

Voluntary Cybersecurity Initiatives in Critical Infrastructure. Nadya Bartol, CISSP, SGEIT, 2014 Utilities Telecom Council

NIST Cybersecurity Framework Sean Sweeney, Information Security Officer 5/20/2015

Health Industry Implementation of the NIST Cybersecurity Framework

National Institute of Standards and Technology Smart Grid Cybersecurity

PROTIVITI FLASH REPORT

NIST Cybersecurity Framework What It Means for Energy Companies

Cybersecurity Audit Why are we still Vulnerable? November 30, 2015

Information and Communications Technology Supply Chain Risk Management (ICT SCRM) AND NIST Cybersecurity Framework

The President issued an Executive Order Improving Critical Infrastructure Cybersecurity, on February 2013.

Business Continuity for Cyber Threat

CForum: A Community Driven Solution to Cybersecurity Challenges

National Cybersecurity Challenges and NIST. Donna F. Dodson Chief Cybersecurity Advisor ITL Associate Director for Cybersecurity

Why you should adopt the NIST Cybersecurity Framework

Westlaw Journal. What is the Cybersecurity Framework? Risk Management Process And Pathway to Corporate Liability? Expert Analysis

Framework for Improving Critical Infrastructure Cybersecurity

No. 33 February 19, The President

Framework for Improving Critical Infrastructure Cybersecurity

Intel Security Professional Services Leveraging NIST Cybersecurity Framework (CSF): Complexity is the enemy of security

Billing Code: 3510-EA

How To Understand And Manage Cybersecurity Risk

Which cybersecurity standard is most relevant for a water utility?

Framework for Improving Critical Infrastructure Cybersecurity

A Guide to Successfully Implementing the NIST Cybersecurity Framework. Jerry Beasley CISM and TraceSecurity Information Security Analyst

ENERGY SECTOR CYBERSECURITY FRAMEWORK IMPLEMENTATION GUIDANCE

NIST Cybersecurity Framework & A Tale of Two Criticalities

IAPP Global Privacy Summit Protecting Privacy Under the Cybersecurity Microscope

Building Security In:

NIST CYBERSECURITY FRAMEWORK IMPLEMENTATION: ENERGY SECTOR APPROACH

Improving Critical Infrastructure Cybersecurity Executive Order Preliminary Cybersecurity Framework

Envisioning Collaboration for Medical Device and Healthcare Cybersecurity

The NIST Cybersecurity Framework (CSF) Unlocking CSF - An Educational Session

The NIST Cybersecurity Framework

Why you should adopt the NIST Cybersecurity Framework

Re: Experience with the Framework for Improving Critical Infrastructure Cybersecurity ( Framework )

Report: An Analysis of US Government Proposed Cyber Incentives. Author: Joe Stuntz, MBA EP 14, McDonough School of Business

Understanding the NIST Cybersecurity Framework September 30, 2014

Cybersecurity & Public Utility Commissions

Overview TECHIS Manage information security business resilience activities

Delving Into FCC's 'Damn Important' Cybersecurity Report

cyberr by e-management The Leader in Cybersecurity Risk Intelligence (RI) Cybersecurity Risk: What You Don t Know CAN Hurt You!

Diane Honeycutt National Institute of Standards and Technology (NIST) 100 Bureau Drive, Stop 8930 Gaithersburg, MD 20899

Cybersecurity as a Risk Factor in doing business

70% of US Business Will Be Impacted by the Cybersecurity Framework: Are You Ready?

Remarks for Admiral David Simpson WTA Advocates for Rural Broadband Spring Meeting Cybersecurity Panel

The Cybersecurity Framework in Action: An Intel Use Case

Applying IBM Security solutions to the NIST Cybersecurity Framework

Treasury Department Summary Report to the President on. Cybersecurity Incentives Pursuant to Executive Order 13636

NIST Unveils Preliminary Cybersecurity Framework

RE: Experience with the Framework for Improving Critical Infrastructure Cybersecurity

CONCEPTS IN CYBER SECURITY

istockphoto/ljupco 36 June 2015 practicallaw.com 2015 Thomson Reuters. All rights reserved.

RECOMMENDED CHARTER FOR THE IDENTITY ECOSYSTEM STEERING GROUP

CLIENT UPDATE CRITICAL INFRASTRUCTURE CYBERSECURITY: U.S. GOVERNMENT RESPONSE AND IMPLICATIONS

April 8, Ms. Diane Honeycutt National Institute of Standards and Technology 100 Bureau Drive, Stop 8930 Gaithersburg, MD 20899

PROTECTING CRITICAL CONTROL AND SCADA SYSTEMS WITH A CYBER SECURITY MANAGEMENT SYSTEM

Cybersecurity Framework Security Policy Mapping Table

DOE Cyber Security Policy Perspectives

C2M2 and the NIST Cyber Framework: Applying DOE's NIST Cyber Security Framework Guidance

Healthcare s Model Approach to Critical Infrastructure Cybersecurity

How To Manage Cybersecurity In Healthcare

Suzanne B. Schwartz, MD, MBA Director Emergency Preparedness/Operations & Medical Countermeasures (EMCM Program) CDRH/FDA

Happy First Anniversary NIST Cybersecurity Framework:

Discussion Draft of the Preliminary Cybersecurity Framework

The NIST Framework for Improving Critical Infrastructure Cybersecurity - An Executive Guide

CYBER SOLUTIONS HANDBOOK

Critical Manufacturing Cybersecurity Framework Implementation Guidance

Cybersecurity: What CFO s Need to Know

Cyber Security. U.S. Executive Order and Critical Security Capabilities to Consider. Intel Corporation. White Paper. Authors

RE: ITI comments in response to NIST RFI: Experience with the Framework for Improving Critical Infrastructure Cybersecurity

Ed McMurray, CISA, CISSP, CTGA CoNetrix

Implementing the U.S. Cybersecurity Framework at Intel A Case Study

Re: Request for Comments on the Preliminary Cybersecurity Framework

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors

Domain 1 The Process of Auditing Information Systems

Transcription:

Framework for Improving Critical Infrastructure Cybersecurity Implementation of Executive Order 13636 NARUC Winter Committee Meeting Committee & Staff Committee on Critical Infrastructure February 15, 2015 cyberframework@nist.gov

Executive Order: Improving Critical Infrastructure Cybersecurity It is the policy of the United States to enhance the security and resilience of the Nation s critical infrastructure and to maintain a cyber environment that encourages efficiency, innovation, and economic prosperity while promoting safety, security, business confidentiality, privacy, and civil liberties President Barack Obama Executive Order 13636, Feb. 12, 2013 The National Institute of Standards and Technology (NIST) was directed to work with stakeholders to develop a voluntary framework for reducing cyber risks to critical infrastructure Version 1.0 of the framework was released on Feb. 12, 2014, along with a roadmap for future work 3

Since the February 12, 2014 release of the Cybersecurity Framework Request for Information: Experience with the Cybersecurity Framework Questions focused on: awareness, experiences, and roadmap areas 6 th Cybersecurity Framework Workshop Goal: Raise awareness, encourage use as a tool, highlight examples of sector-specific efforts, implementation efforts, gather feedback Update on the Cybersecurity Framework Summary posted that includes analysis of RFI responses, feedback from the 6 th workshop, an update on Roadmap areas, and next steps February 13, 2015 White House Releases Fact Sheet on Cybersecurity and Consumer Protection 1 Year Anniversary of the Release NIST Cybersecurity Framework site update to include: FAQs, Upcoming Events, and Industry Resources. Ongoing, targeted outreach continues 4

Some Additional Cybersecurity Framework Resources Developed by Industry The Cybersecurity Framework in Action: An Intel Use Case Cybersecurity Guidance for Small Firms Energy Sector Cybersecurity Framework Implementation Guidance Process Control System Security Guidance for the Water Sector Other online communities of interest 5

Near Term Framework Activities In summary, Collect, Reflect, and Connect understand where industry is having success, help others understand those successes, and facilitate relationships that support use and implementation Continue education efforts, including creation of self-help and reuse materials for those who are new to the Framework Continue awareness and outreach with an eye toward industry communities who are still working toward basal Framework knowledge and implementation Educate on the relationship between Framework and the larger risk management process, including how organizations can use Tiers To allow for adoption, Framework version 2.0 is not planned for the near term 6

Where to Learn More and Stay Current The Framework for Improving Critical Infrastructure Cybersecurity, the Roadmap, related news and information are available at:www.nist.gov/cyberframework Email: cyberframework@nist.gov

Back-Up Slides Cybersecurity Framework Background Introduction to the Components of the Cybersecurity Framework 8

Based on the Executive Order, the Cybersecurity Framework Must Include a set of standards, methodologies, procedures, and processes that align policy, business, and technological approaches to address cyber risks Provide a prioritized, flexible, repeatable, performance-based, and cost-effective approach, including information security measures and controls, to help owners and operators of critical infrastructure identify, assess, and manage cyber risk Identify areas for improvement to be addressed through future collaboration with particular sectors and standards-developing organizations Be consistent with voluntary international standards 9

Development of the Framework Engage the Framework Stakeholders EO 13636 Issued February 12, 2013 NIST Issues RFI February 26, 2013 1 st Framework Workshop April 03, 2013 Collect, Categorize, and Post RFI Responses Completed April 08, 2013 Identify Common Practices/Themes May 15, 2013 Ongoing Engagement: Open public comment and review encouraged and promoted throughout the process cyberframework@nist.gov Analyze RFI Responses 2 nd Framework Workshop at CMU May 2013 Draft Outline of Preliminary Framework June 2013 Identify Framework Elements 3 rd Workshop at UCSD July 2013 4 th Workshop at UT Dallas September 2013 Prepare and Publish Framework 5 th Workshop at NC State November 2013 Published Framework February 2014 10

Framework Components Aligns industry standards and best practices to the Framework Core in a particular implementation scenario Cybersecurity activities and informative references, organized around particular outcomes Supports prioritization and measurement while factoring in business needs Framework Profile Framework Core Enables communication of cyber risk across an organization Framework Implementation Tiers Describes how cybersecurity risk is managed by an organization and degree the risk management practices exhibit key characteristics 11

Framework Core What assets need protection? What safeguards are available? What techniques can identify incidents? What techniques can contain impacts of incidents? What techniques can restore capabilities? 12

Framework Core - Sample 13

Framework Profile Alignment of Functions, Categories, and Subcategories with business requirements, risk tolerance, and resources of the organization Enables organizations to establish a roadmap for reducing cybersecurity risk that is well aligned with organizational and sector goals, considers legal/regulatory requirements and industry best practices, and reflects risk management priorities Can be used to describe current state or desired target state of cybersecurity activities 14

Framework Implementation Tiers Feedback indicated the need for the Framework to allow for flexibility in implementation and bring in concepts of maturity models. Responding to feedback, Framework Implementation Tiers were proposed to reflect how an organization implements the Framework Core functions and manages its risk. The Tiers are progressive, ranging from Partial (Tier 1) to Adaptive (Tier 4), with each Tier building on the previous Tier. The Tier characteristics are defined at the organizational level and are applied to the Framework Core to determine how a category is implemented. 15

Why You Should Consider Adopting the Framework Benefits Reduces time and expense of starting an information security program Reduces risk within current information security programs by identifying areas for improvement Increases efficiencies and reduce the possibility of miscommunication within your information security program and with other organizations such as partners, suppliers, regulators, and auditors Features Organizes reconciliation and de-confliction of legislation, regulation, policy, and industry best practice (Core) Guides organization and management of and information security program (Core) Measures current state and expresses desired state (Profile) Enables investment decisions to address gaps in current state (Profile) Communicates cybersecurity requirements with stakeholders, including partners and suppliers (Profile) Enables informed trade-off analysis of expenditure versus risk (Tiers) 16

Key Points about the Cybersecurity Framework It s a framework, not a prescription It provides a common language and systematic methodology for managing cyber risk It does not tell a company how much cyber risk is tolerable, nor does it claim to provide the one and only formula for cybersecurity Having a common lexicon to enable action across a very diverse set of stakeholders will enable the best practices of elite companies to become standard practices for everyone The framework is a living document It is intended to be updated over time as stakeholders learn from implementation, and as technology and risks change That s one reason why the framework focuses on questions an organization needs to ask itself to manage its risk. While practices, technology, and standards will change over time principals will not 17