0% found this document useful (0 votes)
4 views19 pages

Week 4

The document compares the NIST Cybersecurity Framework (CSF) and the NIST Risk Management Framework (RMF), highlighting their distinct purposes in managing cybersecurity risks. The NIST CSF focuses on enhancing cybersecurity posture across various sectors, while the NIST RMF provides a structured approach for federal agencies to secure information systems. Additionally, it outlines the roles and responsibilities of key stakeholders involved in the RMF process and mentions common audit frameworks and standards.

Uploaded by

es2200053
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views19 pages

Week 4

The document compares the NIST Cybersecurity Framework (CSF) and the NIST Risk Management Framework (RMF), highlighting their distinct purposes in managing cybersecurity risks. The NIST CSF focuses on enhancing cybersecurity posture across various sectors, while the NIST RMF provides a structured approach for federal agencies to secure information systems. Additionally, it outlines the roles and responsibilities of key stakeholders involved in the RMF process and mentions common audit frameworks and standards.

Uploaded by

es2200053
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Week 4

Cyber Security Frameworks and Standards

Dr Mustafa Mohammed | Digital Forensic & Cyber 1


Security
NIST Cybersecurity Framework (CSF) and the NIST Risk Management Framework RMF,
comparing and contrasting them to gain insights into how they can be leveraged to
manage cybersecurity risks effectively

• NIST frameworks

• Within the realm of cybersecurity, two prominent
frameworks developed by the NIST stand as cornerstones
for managing risk and enhancing security:
• The NIST Cyber Security Framework (CSF) and the NIST Risk
Management Framework (RMF).
• While both frameworks share the overarching goal of
bolstering cybersecurity, they serve different purposes and
operate at distinct stages of the cybersecurity life cycle.
• In this section, we will delve into a comprehensive
comparison between these two frameworks to understand
their key features, purposes, and how they can be
leveraged effectively.
NIST CSF
• Purpose The NIST CSF, officially titled the Framework for
Improving Critical Infrastructure Cybersecurity, was
created to provide organizations, particularly those in
critical infrastructure sectors, with a flexible framework
for enhancing their cybersecurity posture. It is
designed to help organizations manage and reduce
cybersecurity risk while fostering a culture of
cybersecurity awareness and resilience.
Key components
• The NIST CSF is built around five core functions:
Identify, Protect, Detect, Respond, and Recover. These
functions provide a structured approach to
cybersecurity activities. Within each function, various
categories and subcategories outline specific
cybersecurity activities and outcomes. Organizations
can select and implement relevant subcategories
based on their needs.
Application
• The NIST CSF is widely used by organizations across
various sectors to enhance their cybersecurity posture.
• It helps organizations identify and prioritize
cybersecurity activities, assess their current state and
develop a roadmap for improvement.
NIST RMF
• Purpose The NIST RMF, as outlined in NIST Special
Publication 800-37, provides a structured approach to
managing and mitigating risk throughout the system
development life cycle. It is primarily used by federal
agencies and government contractors to secure
information systems and achieve compliance with
federal regulations.
Key components
• The NIST RMF is built around seven core phases:
• Prepare: In this phase, an understanding of the organization’s risk environment is
developed, along with establishing the necessary resources, policies, and procedures
to manage risk.
• Categorize: In this phase, information systems are categorized based on their
sensitivity and importance, determining the level of security required.
• Select: Security controls are selected based on the system’s categorization and risk
assessment.
• Implement: Chosen security controls are implemented within the system.
• Assess: Security controls are assessed for effectiveness and compliance.
• Authorize: Based on the assessment results, the system is authorized for operation, or
further action is taken to address deficiencies.
• Monitor: Continuous monitoring of security controls and ongoing risk management
ensure the system remains secure throughout its life cycle.
Application
• The NIST RMF is primarily used by the US federal
government and its contractors to manage and secure
information systems. It helps ensure that federal
agencies and organizations adhere to a structured
process for assessing, authorizing, and maintaining the
security of their systems.
Comparison and contrast
• CSF: The NIST CSF primarily focuses on helping organizations manage and improve
their cybersecurity posture through risk reduction. It provides a set of guidelines and
best practices to help organizations identify, protect, detect, respond to, and recover
from cybersecurity threats and incidents. It applies to a wide range of organizations,
including critical infrastructure sectors such as energy, healthcare, finance, and
transportation, as well as non-critical infrastructure organizations.

• RMF: The NIST RMF is designed primarily to guide state, local, tribal, and territorial
(SLTT) government organizations in managing the security and privacy risks
associated with their information systems. It is specifically tailored to the federal
government and its contractors, although the underlying principles, and even the
framework itself, have a significant amount of applicability outside the government. It
is mandated for all federal information systems and is used to assess and authorize
the security of these systems.
The stages of the NIST RMF
• Prepare for RMF execution: This initial step involves preparing for the RMF process. It includes establishing
the context and the boundaries of the system, defining the roles and responsibilities, and ensuring that the
necessary resources are in place to support the RMF process.
• Categorize system and information: In this step, the system is categorized based on its potential impact on
organizational operations, assets, and individuals. This categorization helps determine the appropriate
security controls that need to be implemented.
• Select and tailor controls: Once the system is categorized, specific security controls are selected from the
NIST Special Publication 800-53, which provides a comprehensive set of security controls. The selection is
based on the categorized impact level and tailored to the system’s unique requirements.
• Implement controls: The selected security controls are implemented in the system during this step. This
involves configuring hardware and software, establishing security policies and procedures, and deploying
security technologies to ensure that the controls are correctly integrated.
• Assess controls: Security control assessments are conducted to evaluate the effectiveness of the
implemented controls. This step includes activities such as vulnerability scanning, penetration testing, and
other security tests to identify vulnerabilities and weaknesses.
• Authorize system or controls: The authorization step involves reviewing the results of the security control
assessments, assessing residual risks, and making a formal decision on whether to grant authorization to
operate (ATO). An Authorizing Official (AO) plays a crucial role in this decision-making process.
• Monitoring the system’s controls: The final step involves the continuous monitoring of the system’s security
controls. This ongoing process includes real-time threat detection, incident response, and regular security
assessments to ensure that the controls remain effective, as well as monitoring whether the system
maintains its security posture over time.
• These seven steps together create a structured and
systematic approach to risk management and
cybersecurity within an organization, ensuring that
information systems are secured and compliant with
established standards throughout their life cycle.
Roles and responsibilities in the RMF

• There are numerous stakeholders involved in


implementing the RMF in your organization. In this
section, we’ll give a breakdown of each role and what
their responsibilities are as it pertains to the
implementation of the NIST RMF.
Authorizing Official
• The AO plays a pivotal role in the NIST RMF process.
Their primary responsibility is to make the final
decision regarding ATO for an information system. This
decision is based on a comprehensive review of the
results of security control assessments and an
assessment of residual risks. To execute this role
effectively, the AO must have a profound
understanding of the RMF process, organizational
security policies, and the system’s specific
requirements. They must be able to weigh the
assessment findings against security standards and
acceptable risk levels.
Chief Information Officer
• The CIO holds a strategic position in the RMF process and is responsible for overseeing
the organization’s broader information technology and cybersecurity strategy. To
execute this role effectively, the CIO must align the RMF process with the
organization’s overarching IT strategy. This alignment includes resource allocation,
budgeting, and ensuring that the RMF supports the organization’s mission and goals.

• To fulfill these responsibilities, the CIO should work closely with the AO and other RMF
stakeholders to understand the specific security requirements of the information
system and to ensure that the RMF process is adequately resourced. This includes
collaborating with the ISO to define the system’s security requirements and security
control selection. The CIO plays a crucial role in ensuring that the RMF process is not
only effective in securing the information system but also aligns with the
organization’s strategic objectives.
Chief Information Security Officer
• The Chief Information Security Officer (CISO) is a high-ranking executive responsible for
the organization’s overall cybersecurity strategy, including the RMF process. The
CISO plays a pivotal role in ensuring the organization’s information systems are
secure, compliant, and resilient against evolving threats. Their responsibilities
encompass strategic leadership, risk management, and the alignment of the RMF
process with the organization’s broader security objectives.

• For the effective execution of their responsibilities, the CISO should possess a deep
understanding of cybersecurity principles, risk management, and the RMF process.
They need to stay current with evolving cyber threats and security technologies and
be able to translate technical security concepts into business-relevant terms.
Collaboration with other RMF stakeholders, such as the AO and ISO, is critical to
ensure that the RMF aligns with the organization’s strategic goals and security
requirements. T he CISO should also have strong leadership and communication skills
to convey the importance of cybersecurity and risk management to the
organization’s executive leadership and staff.
Information System Owner
• The ISO holds a key operational role in the RMF process. Their primary responsibility is
to oversee the day-to-day operation and security of the information system. To fulfil
this role effectively, the ISO should define the system’s security requirements, select
appropriate security controls, and ensure that the system operates securely.

• Collaboration is essential for ISOs, as they work closely with other RMF stakeholders,
such as the Security Control Assessor (SCA), to define security requirements and
select controls. They must also collaborate with the Security Officer (SO) to ensure
that security controls are correctly implemented and that the system maintains its
security posture. ISOs should have a deep understanding of the information system’s
operation, as well as a strong knowledge of security principles and controls.
Security Control Assessor

• SCAs play a critical role in the RMF process by conducting


security control assessments. Their primary responsibility is to
evaluate the effectiveness of the security controls that have
been implemented. This involves assessing whether the
controls are correctly configured and functioning as needed.

• To perform their duties effectively, SCAs need to possess in-depth
knowledge of security control specifications, assessment
methodologies, and relevant testing techniques. They should
have the ability to identify vulnerabilities and weaknesses in
security controls and provide recommendations for mitigation.
SCAs must be meticulous in documenting assessment results
and working closely with other RMF stakeholders, including the
ISO, to gather information and support.
Security Officer
• SOs are responsible for implementing and overseeing security measures for
the information system. T heir responsibilities include ensuring that security
controls are correctly implemented, monitoring their ongoing operation, and
managing incident response procedures.
• To execute these responsibilities effectively, SOs need to have a deep
understanding of security policies and procedures, security technologies,
and incident response protocols. They should collaborate closely with the
System Administrator (SA) to ensure that access to assessments is provided
and to address technical questions. SOs are key in maintaining the system’s
security posture, making ongoing monitoring and response to security
incidents critical aspects of their role.
• T hese roles, each with their specific responsibilities, collectively form a
structured approach to managing cybersecurity risks within the RMF
process. Collaborative efforts and a strong understanding of the RMF’s
principles are essential for the effective execution of these responsibilities.
Overview of common audit
frameworks and standards
• Different frameworks and standards guide the process and expectations of security
audits. Some of the most widely recognized are as follows:
• ISO/IEC 27001: An international standard that provides a framework for Information
Security Management Systems (ISMS).
• NIST SP 800 series: A set of guidelines provided by NIST for improving the security of
information systems.
• PCI-DSS: The Payment Card Industry Data Security Standard, which is crucial for
organizations handling credit card transactions.
• HIPAA: The Health Insurance Portability and Accountability Act, which is vital for
healthcare organizations in protecting patient data.

You might also like