NIST Cyber Risk Management Overview
NIST Cyber Risk Management Overview
Peter Romness
Cisco / US Public Sector Cybersecurity
Agenda
2. About NIST
3. NIST SP 800-53
4. NIST RMF
5. NIST CSF
6. Conclusion
PA Security Assessment
Framework
• Baseline Security Best Practices Assessment
• Security Policy & Organization Review
• Physical and Environmental Security Assessment
• Internal Network Discovery & Vulnerability Scans
• External Network Discovery & Vulnerability Scan
• Wireless Security Analysis
• Account Management Procedure Analysis
• Server and Workstation Configuration Review
• Security Infrastructure Analysis
• Continuity Plan Review
• Human Resources Review
• Security Awareness and Training Programs Assessment
Source:[Link]
03339
What’s the difference?
NIST References... How do these work?
A two-character
ID uniquely
identifies security
control families
NIST SP 800-53 Security Control Structure
1 Control section
Supplemental Guidance
2 section
Control Enhancements
3 section
4 References section
AC Access Control
AT Awareness/Training
AU Audit/Accountability
CA Security Assessment
CM Configuration Mgmt
CP Contingency Planning
IA Identification/AuthZ
IR Incident Response
MA Maintenance
MP Media Protection
PE Physical Environment Cisco Safety
and Security
PL Planning
PS Personnel Security
RA Risk Assessment
SA System Acquisition
SC Sys/Comm Protection
SI Sys/Info Integrity
PM Program Management
NIST RMF
NIST RMF Risk Management Framework
Start
Monitor Categorize
NIST SP 800-137 6 1 FIPS 199 & NIST SP 800-60
Authorize 5 2 Select
NIST SP 800-37 FIPS 200 & NIST SP 800-53
4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160
PRIORITY
CNTL INITIAL CONTROL BASELINES
CONTROL NAME
NO. LOW MOD HIGH
ACCESS CONTROL
AC-1 Access Control Policy and Procedures P1 AC-1 AC-1 AC-1
Implement the security controls and document how the controls are
deployed within the information system and environment of operation
ID PROCESS NAME ID PROCESS NAME
IP Implementation MA Maintenance
IN Integration DS Disposal
VE Verification
“If the authorizing official, after reviewing the authorization package deems that the risk to organizational operations
ATO and assets, individuals, other organizations, and the Nation is acceptable, an authorization to operate is issued for
the information system or for the common controls inherited by organizational information systems”
Start
Monitor Categorize
NIST SP 800-137 6 1 FIPS 199 & NIST SP 800-60
Authorize 5 2 Select
NIST SP 800-37 FIPS 200 & NIST SP 800-53
4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160
Focused Action
Better Communication
Process Support
Framework
Implementation An organization’s view on
Tiers how well it manages risk,
ranging from Partial (Tier 1)
to Adaptive (Tier 4)
Core
CSF Core
Functions Categories Subcategories Informative Resources
Identify
1 2 3 4
Protect
Detect
Respond
Recover
Core
CSF Core
Functions Categories Subcategories Informative Resources
Identify
1
Protect
Detect
High-level
cybersecurity
Respond
goals
Recover
Core
CSF Core
Functions Categories Subcategories Informative Resources
Identify
Protect
2
Detect Subdivide
Functions into
Respond specific
activities
Recover
Core
CSF Core
Functions Categories Subcategories Informative Resources
Identify
Protect
3
Detect Subdivide
Categories into
Respond desired
outcomes
Recover
Core
CSF Core
Functions Categories Subcategories Informative Resources
Identify
Protect
4
Detect Standards
references to
Respond achieve the
outcomes
Recover
Core
Functions
Functions
Develop the organizational understanding to manage cybersecurity risk to systems,
ID Identify assets, data, and capabilities
Develop and implement the appropriate activities to take action regarding a detected
RS Respond cybersecurity event
Develop and implement the appropriate activities to maintain plans for resilience and to
RC Recover restore any capabilities or services that were impaired due to a cybersecurity event
Core
Categories
Function Categories
The data, personnel, devices, systems, and facilities that enable the
Asset organization to achieve business purposes are identified and managed
[Link]
Management (AM) consistent with their relative importance to business objectives and the
organization’s risk strategy.
The organization’s mission, objectives, stakeholders, and activities are
Business
[Link] understood and prioritized; this information is used to inform cybersecurity
Environment (BE) roles, responsibilities, and risk management decisions.
Identify The policies, procedures, and processes to manage and monitor the
Governance (GV) organization’s regulatory, legal, risk, environmental, and operational
(ID) [Link]
requirements are understood and inform the management of cyber risk.
The organization understands the cybersecurity risk to organizational
Risk Assessment
[Link] operations (including mission, functions, image, or reputation),
(RA) organizational assets, and individuals.
Risk Management The organization’s priorities, constraints, risk tolerances, and assumptions
[Link] are established and used to support operational risk decisions.
Strategy (RM)
Core
Subcategories
Function Category Subcategories
[Link]-1 Physical devices and systems within the organization are inventoried
[Link]-2 Software platforms and applications within the organization are inventoried
Informative Resources
Function Category Subcategory Informative Resources
• CCS CSC 1
• COBIT 5 BAI09.01, BAI09.02
Asset Physical device • ISA 62443-2-1:2009 [Link]
Identify
Management inventories
(ID) ([Link]) ([Link]-1) • ISA 62443-3-3:2013 SR 7.8
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2
• NIST SP 800-53 Rev. 4 CM-8
Informative Resources
Function Category Subcategory Informative Resources
• CCS CSC 1
• COBIT 5 BAI09.01, BAI09.02
Asset Physical device • ISA 62443-2-1:2009 [Link]
Identify
Management inventories
(ID) ([Link]) ([Link]-1) • ISA 62443-3-3:2013 SR 7.8
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2
• NIST SP 800-53 Rev. 4 CM-8
Tier 2 Risk Informed: Practices approved but not completely established by policy
Profiles
Highlights the
importance of
both people and
process in
cybersecurity
CSF Uses
5 3
Create Target Profile 4 Create Current Profile
Orient
[Link]-3 Tier 2
ID [Link]
[Link]-4 Unused
Acceptable risks at this time
[Link]-5 Tier 4
[Link]-6 Tier 3
Target Profile 5
[Link]-1 Tier 4
This is where we want to be
[Link]-2 Tier 4
• Physical device and software
[Link]-3 Tier 2
inventories at Tier 4, “Adaptive” ID [Link]
Gap Analysis
Fxn. Cat. Sub. Current Profile Fxn. Cat. Sub. Target Profile
Action Plan
Fxn. Cat. Sub. Informative Resources NIST SP 800-53 Revision 4
• CCS CSC 1 CM-8 / Information System Component Inventory
• COBIT 5 BAI09.01, BAI09.02
Control: The organization:
• ISA 62443-2-1:2009 [Link] a. Develops and documents an inventory of
[Link]-1 information system components that:
• ISA 62443-3-3:2013 SR 7.8
1. Accurately reflects the current information
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2 system;
• NIST SP 800-53 Rev. 4 CM-8 2. Includes all components within the
ID [Link] authorization boundary of the information
• CCS CSC 2 system;
• COBIT 5 BAI09.01, BAI09.02, BAI09.05 3. Is at the level of granularity deemed
necessary for tracking and reporting; and
• ISA 62443-2-1:2009 [Link]
[Link]-2 4. Includes [Assignment: organization-defined
• ISA 62443-3-3:2013 SR 7.8 information deemed necessary to achieve
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2 effective information system component
accountability]
• NIST SP 800-53 Rev. 4 CM-8
7
?
?
Device Discovery
Implement Action Plan and Profiling
5 3
Create Target Profile 4 Create Current Profile
Start
Monitor Categorize
NIST SP 800-137 6 1 FIPS 199 & NIST SP 800-60
Authorize 5 2 Select
NIST SP 800-37 FIPS 200 & NIST SP 800-53
4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160
Authorize 5 2 Select
NIST SP 800-37 NIST SP 800-53
4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160
NIST RMF vs. NIST CSF Other Important Differences
NIST CSF can be used with the NIST RMF but does not require it
• Organizations may choose to follow the NIST RMF, but are also free choose to use the NIST CSF with
ISO/IEC 27005 -- or any other enterprise risk management process
NIST CSF references the NIST SP 800-53 security control catalog but
does not require it
• Organizations may choose to select security controls from NIST SP 800-53, but are also free to select
from ISACA COBIT 5, ISO/IEC 27001/27002, or other security control catalogs
• NIST CSF Informative Resources refer to certain controls from NIST SP 800-53, but the CSF does not
reference the complete set of NIST SP 800-53 controls
• NIST CSF describes its own cybersecurity improvement process that leverages CSF Profiles and
Implementation Tiers, but without the rigor of the NIST RMF (e.g., no FIPS 199 System Categorization)
Cisco Security Strategy The Threat-Centric Security Model
Attack Continuum
Attack Continuum
Asset Management
Business Environment Non-technical control area
ID Governance Non-technical control area
Risk Assessment
Risk Mgmt. Strategy Non-technical control area
Access Control
Awareness/Training Non-technical control area
B
Data Security
PR
Info Protection Process Non-technical control area
Maintenance
Protective Technology
Anomalies and Events
DE Continuous Monitoring D
Detection Processes Non-technical control area
Response Planning Non-technical control area
Communications Non-technical control area
RS Analysis
Mitigation
Improvements Non-technical control area
A
Recovery Planning Non-technical control area
RC Improvements Non-technical control area
Communications Non-technical control area
People Process
Cisco has the people, services, products, partners, corporate commitment and financial strength to
ensure your success
• Our worldwide security team, including threat intelligence, research, supply chain, and customer support
professionals, is focused on your success.
• Our services professionals can guide you as you plan, implement and manage your security, deliver security as a
service, or help you during an attack.
• Our family of best in class products work together to stop threats quickly while reducing complexity and cost.
• Because of our open platform and industry leadership, we team with comprehensive list of solutions providers and
delivery partners.
• Cisco is committed to your success with the financial strength to invest in research, develop new products, and
support your success