0% found this document useful (0 votes)
5 views71 pages

NIST Cyber Risk Management Overview

Understanding NIST Cybersecurity Risk Management

Uploaded by

birth.evander
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views71 pages

NIST Cyber Risk Management Overview

Understanding NIST Cybersecurity Risk Management

Uploaded by

birth.evander
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

NIST, No Mystery:

Understanding NIST Cybersecurity Risk Management

Peter Romness
Cisco / US Public Sector Cybersecurity
Agenda

1. PA Security Assessment Framework

2. About NIST

3. NIST SP 800-53

4. NIST RMF

5. NIST CSF

6. Conclusion
PA Security Assessment
Framework
• Baseline Security Best Practices Assessment
• Security Policy & Organization Review
• Physical and Environmental Security Assessment
• Internal Network Discovery & Vulnerability Scans
• External Network Discovery & Vulnerability Scan
• Wireless Security Analysis
• Account Management Procedure Analysis
• Server and Workstation Configuration Review
• Security Infrastructure Analysis
• Continuity Plan Review
• Human Resources Review
• Security Awareness and Training Programs Assessment

Source:[Link]
03339
What’s the difference?
NIST References... How do these work?

NIST Cybersecurity Framework (CSF)

NIST Risk Management Framework (RMF)

NIST Special Publication 800-53


National Institute of Standards
NIST and Technology

Information Technology publications, security


standards, tools, and best practices
• Computer Security Resource Center (CSRC)
• Cybersecurity Framework (CSF)
Mission
• National Cybersecurity Center of Excellence (NCCoE)
• Information Technology Laboratory (ITL)
• National Strategy for Trusted Identities in Cyberspace (NSTIC)
“To promote innovation and
Breadth and depth across vast subject areas industrial competitiveness by
advancing measurement
beyond Information Technology as well science, standards, and
• Telecommunications, nanotechnology, bioscience, energy, chemistry, technology in ways that
math, physics, transportation, public safety -- and more enhance economic security
and improve our quality of life”
Source: National Institute of Standards and Technology, [Link]
NIST CSRC Computer Security Resource Center

Federal Information Processing Standards (FIPS)

NIST Interagency or Internal Reports (NISTIRs)

Information Technology Laboratory (ITL) Bulletins

NIST Special Publications (SPs) 800-Series: NIST's primary mode of


• 800-Series: Computer Security publishing computer/cyber/information
security guidelines, recommendations
• 1800-Series: Cybersecurity Practice Guides
and reference materials.
• 500-Series: Information Technology

Source: NIST CSRC Publications, [Link]


NIST Publications Key Standards and Guidelines

• FIPS 199: Standards for Security Categorization


• FIPS 200: Minimum Security Requirements

NIST Risk Management Framework


1. Categorize information system (NIST SP 800-60)
2. Select security controls (NIST SP 800-53)
3. Implement security controls (NIST SP 800-160)
4. Assess security controls (NIST SP 800-53A)
5. Authorize information system (NIST SP 800-37)
6. Monitor security controls (NIST SP 800-137)

Source: NIST CSRC, [Link]


NIST Publications Key Standards and Guidelines

• FIPS 199: Standards for Security Categorization


• FIPS 200: Minimum Security Requirements

NIST Risk Management Framework


1. Categorize information system (NIST SP 800-60)
2. Select security controls (NIST SP 800-53) Focus Area
3. Implement security controls (NIST SP 800-160)
4. Assess security controls (NIST SP 800-53A)
5. Authorize information system (NIST SP 800-37)
6. Monitor security controls (NIST SP 800-137)

Source: NIST CSRC, [Link]


NIST SP 800-53
Security and Privacy Controls for
NIST SP 800-53 Federal Information Systems

Security Control Catalog


• 18 security control families with hundreds of security controls
• Essential for FISMA and the NIST Risk Management Framework

“Special Publication 800-53, Revision 4, provides a more holistic approach


to information security and risk management by providing organizations with
the breadth and depth of security controls necessary to fundamentally
strengthen their information systems and the environments in which those
systems operate—contributing to systems that are more resilient in the face
of cyber attacks and other threats.”
“This ‘Build It Right’ strategy is coupled with a variety of security controls for
Continuous Monitoring to give organizations near real-time information that
is essential for senior leaders making ongoing risk-based decisions affecting
their critical missions and business functions.”

Source: NIST SP 800-53, Foreword, Page XV


NIST SP 800-53 Security Control Structure

Security Control Families


• Each family contains security controls related to the general security topic of the family
• Security controls may involve aspects of policy, oversight, supervision, manual processes, actions by
individuals, or automated mechanisms implemented by information systems/devices

A two-character
ID uniquely
identifies security
control families
NIST SP 800-53 Security Control Structure

Control families drill


down into individual
security controls

Next slide for security SI


control sections
NIST SP 800-53 Security Control Structure

SI-3 Malicious Code Protection

1 Control section

Supplemental Guidance
2 section

Control Enhancements
3 section

4 References section

Priority and Baseline


5 Allocation section
Cisco Solution Alignment
NIST SP 800-53 Summary by Control Family

AC Access Control
AT Awareness/Training
AU Audit/Accountability
CA Security Assessment
CM Configuration Mgmt
CP Contingency Planning
IA Identification/AuthZ
IR Incident Response
MA Maintenance
MP Media Protection
PE Physical Environment Cisco Safety
and Security
PL Planning
PS Personnel Security
RA Risk Assessment
SA System Acquisition
SC Sys/Comm Protection
SI Sys/Info Integrity
PM Program Management
NIST RMF
NIST RMF Risk Management Framework

Start
Monitor Categorize
NIST SP 800-137 6 1 FIPS 199 & NIST SP 800-60

Authorize 5 2 Select
NIST SP 800-37 FIPS 200 & NIST SP 800-53

4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160

Source: NIST RMF Overview, [Link]


1
FIPS 199 and
Categorize NIST SP 800-60

The loss of confidentiality, integrity, or availability could be expected to


High have a severe or catastrophic adverse effect on organizational
operations, organizational assets, or individuals.
System
The loss of confidentiality, integrity, or availability could be expected to
Impact Moderate have a serious adverse effect on organizational operations,
Levels organizational assets, or individuals.

The loss of confidentiality, integrity, or availability could be expected to


Low have a limited adverse effect on organizational operations,
organizational assets, or individuals.

SC = {(confidentiality, impact), (integrity, impact), (availability, impact)}


FIPS 200 and
Select NIST SP 800-53
2

Select the Initial Control Baseline according to System Category (SC)

PRIORITY
CNTL INITIAL CONTROL BASELINES
CONTROL NAME
NO. LOW MOD HIGH
ACCESS CONTROL
AC-1 Access Control Policy and Procedures P1 AC-1 AC-1 AC-1

AC-4 Separation of Duties P1 Not Selected AC-4 AC-4


AC-6(1)(2)(5) AC-6(1)(2)(3)
AC-6 Least Privilege P1 Not Selected
(9)(10) (5)(9)(10)
AC-7 Unsuccessful Logon Attempts P2 AC-7 AC-7 AC-7

AC-11 Session Lock P3 Not Selected AC-11(1) AC-11(1)

Source: NIST SP 800-53, Table D-2: Security Control Baselines


Implement NIST SP 800-160
3

Implement the security controls and document how the controls are
deployed within the information system and environment of operation
ID PROCESS NAME ID PROCESS NAME

SR Stakeholder Requirements Definition TR Transition

RA Requirements Analysis VA Validation

AD Architectural Design OP Operation

IP Implementation MA Maintenance

IN Integration DS Disposal

VE Verification

Source: NIST SP 800-60, Table 1: Process Names and Designators


Assess NIST SP 800-53A
4

Assess the implemented security Security Control Assessment


Process Overview
controls to determine whether they are:
• Implemented correctly
• Operating as intended
• Producing the desired results

Security control assessment goals:


• Consistent, comparable, and repeatable assessments of
security controls with reproducible results
• More cost-effective assessments of security controls
• Better understanding of the risks to organizational
operations, assets, individuals

Source: NIST SP 800-53A, Figure 1: Security Control Assessment Process Overview


Authorize NIST SP 800-37 5

Plan of Action and Milestones Security Authorization Package


1 Prepare based on the findings and
2 Assemble the security authorization package and
recommendations of the security assessment submit the package to the authorizing official for
report excluding any remediation actions taken adjudication

Risk Determination Risk Acceptance


3 Determine the risk to organizational operations
4 Determine if the risk to organizational operations,
(including mission, functions, image, or organizational assets, individuals, other
reputation), organizational assets, individuals, etc. organizations, or the Nation is acceptable

“If the authorizing official, after reviewing the authorization package deems that the risk to organizational operations
ATO and assets, individuals, other organizations, and the Nation is acceptable, an authorization to operate is issued for
the information system or for the common controls inherited by organizational information systems”

Source: NIST SP 800-37, Appendix F: Security Authorization


6

Monitor NIST SP 800-137

Information Security Continuous


Monitoring (ISCM) Define
• Provides security situational awareness
• Enables appropriate action as the situation changes Review/
Establish
• Part of the larger strategy of enterprise risk management Update

The role of automation in ISCM ISCM


• Augments the security processes conducted by security
professionals within an organization Respond Implement
• Reduces the amount of time a security professional must
spend on doing redundant tasks Analyze/
• Frees the security professional to spend time on tasks that Report
do require human cognition
Source: NIST SP 800-137, Chapter 2: The Fundamentals
NIST RMF Summary Risk Management Framework

Start
Monitor Categorize
NIST SP 800-137 6 1 FIPS 199 & NIST SP 800-60

Authorize 5 2 Select
NIST SP 800-37 FIPS 200 & NIST SP 800-53

4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160

Source: NIST RMF Overview, [Link]


NIST CSF
Improving Critical Infrastructure Cybersecurity
Executive Order 13636
February 2013

“It is the policy of the United States to enhance the security


and resilience of the Nation’s critical infrastructure and to
maintain a cyber environment that encourages efficiency,
innovation, and economic prosperity while promoting safety,
security, business confidentiality, privacy, and civil liberties.”
NIST CSF Cybersecurity Framework

Outcome of Executive Order 13636, and result of


collaboration between public and private sectors
• Manages cybersecurity risks in a cost-effective way, while
protecting privacy and civil liberties
• References the globally accepted standards (COBIT,
ISO/IEC, ISA, NIST, CCS) that are working well today
• Intended for worldwide adoption -- not US only
• Uses common terminology to discuss cybersecurity risk
• Ensures business drivers guide cybersecurity activities
• Considers cybersecurity risks as part of organization’s
overall risk management process
Best Practices

People Process Technology

Framework covers all three


People

Focused Action

Framework helps organizations


optimize their cybersecurity activities
• Aligns cybersecurity
activities with business risk
• Prioritizes activities that are
most important for critical
service delivery
• Maximizes the impact of
cybersecurity spending
People

Better Communication

Framework uses a common language


to discuss cybersecurity risk
• Improves communication among
cybersecurity experts and senior
leadership within an organization
• Improves communication with external
vendors, partners, and contractors
• Aligns the Information Technology (IT)
and Operations Technology (OT) teams
Process

Process Support

Framework works with existing risk


management programs
• ISO/IEC 27005, Information Security Risk
Management
• ISO/IEC 31000, Risk Management
• NIST SP 800-39, Managing Information Security Risk
• Electricity Subsector Cybersecurity Risk Management
Process (RMP)
Broad Applicability

Framework enables all organizations


to improve security and resilience
• Any size or type of organization
• Both public and private sectors
• Any degree of cybersecurity risk
• Any level of cybersecurity sophistication
• Anywhere in the world
CSF Components

Set of activities, desired Alignment of Framework


outcomes, and Core structure with the
applicable references specific business
common across critical Framework Framework requirements of a
infrastructure sectors Core Profile particular organization

Framework
Implementation An organization’s view on
Tiers how well it manages risk,
ranging from Partial (Tier 1)
to Adaptive (Tier 4)
Core

CSF Core
Functions Categories Subcategories Informative Resources

Identify
1 2 3 4
Protect

Detect

Respond

Recover
Core

CSF Core
Functions Categories Subcategories Informative Resources

Identify
1
Protect

Detect
High-level
cybersecurity
Respond
goals
Recover
Core

CSF Core
Functions Categories Subcategories Informative Resources

Identify

Protect
2
Detect Subdivide
Functions into
Respond specific
activities
Recover
Core

CSF Core
Functions Categories Subcategories Informative Resources

Identify

Protect
3
Detect Subdivide
Categories into
Respond desired
outcomes
Recover
Core

CSF Core
Functions Categories Subcategories Informative Resources

Identify

Protect
4
Detect Standards
references to
Respond achieve the
outcomes
Recover
Core

Functions
Functions
Develop the organizational understanding to manage cybersecurity risk to systems,
ID Identify assets, data, and capabilities

Develop and implement the appropriate safeguards to ensure delivery of critical


PR Protect infrastructure services

Develop and implement the appropriate activities to identify the occurrence of a


DE Detect cybersecurity event

Develop and implement the appropriate activities to take action regarding a detected
RS Respond cybersecurity event

Develop and implement the appropriate activities to maintain plans for resilience and to
RC Recover restore any capabilities or services that were impaired due to a cybersecurity event
Core

Categories
Function Categories
The data, personnel, devices, systems, and facilities that enable the
Asset organization to achieve business purposes are identified and managed
[Link]
Management (AM) consistent with their relative importance to business objectives and the
organization’s risk strategy.
The organization’s mission, objectives, stakeholders, and activities are
Business
[Link] understood and prioritized; this information is used to inform cybersecurity
Environment (BE) roles, responsibilities, and risk management decisions.
Identify The policies, procedures, and processes to manage and monitor the
Governance (GV) organization’s regulatory, legal, risk, environmental, and operational
(ID) [Link]
requirements are understood and inform the management of cyber risk.
The organization understands the cybersecurity risk to organizational
Risk Assessment
[Link] operations (including mission, functions, image, or reputation),
(RA) organizational assets, and individuals.
Risk Management The organization’s priorities, constraints, risk tolerances, and assumptions
[Link] are established and used to support operational risk decisions.
Strategy (RM)
Core

Subcategories
Function Category Subcategories

[Link]-1 Physical devices and systems within the organization are inventoried

[Link]-2 Software platforms and applications within the organization are inventoried

Asset [Link]-3 Organizational communication and data flows are mapped


Identify
Management
(ID) ([Link]) [Link]-4 External information systems are catalogued

Resources (hardware, devices, data, and software) are prioritized based


[Link]-5
on their classification, criticality, and business value
Cybersecurity roles and responsibilities for the entire workforce and third-
[Link]-6
party stakeholders (suppliers, customers, partners) are established
Core

Informative Resources
Function Category Subcategory Informative Resources
• CCS CSC 1
• COBIT 5 BAI09.01, BAI09.02
Asset Physical device • ISA 62443-2-1:2009 [Link]
Identify
Management inventories
(ID) ([Link]) ([Link]-1) • ISA 62443-3-3:2013 SR 7.8
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2
• NIST SP 800-53 Rev. 4 CM-8

International • Council on CyberSecurity (CCS)


standards • Control Objectives for Information and Related Technology (COBIT)
references • International Society of Automation (ISA)
• International Organization for Standardization (ISO)
• International Electrotechnical Commission (IEC)
Core

Informative Resources
Function Category Subcategory Informative Resources
• CCS CSC 1
• COBIT 5 BAI09.01, BAI09.02
Asset Physical device • ISA 62443-2-1:2009 [Link]
Identify
Management inventories
(ID) ([Link]) ([Link]-1) • ISA 62443-3-3:2013 SR 7.8
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2
• NIST SP 800-53 Rev. 4 CM-8

ISO/IEC 27001:2013 Annex A


A.8 Asset Management
A.8.1.1 Inventory of Assets
A.8.1.2 Ownership of Assets
Tiers Tiers

Reflect how an organization views cybersecurity


risk and the processes in place to manage that risk
Tier 4 Adaptive: Practices fully established and continuously improved

Tier 3 Repeatable: Practices approved and established by organizational policy

Tier 2 Risk Informed: Practices approved but not completely established by policy

Tier 1 Partial: Informal, ad hoc, reactive responses


Profiles

Profiles

The alignment of the Framework core with an


organizations business requirements, risk
tolerance, and resources
• Describes the current state
and desired future state
• Reveals gaps that can flow
into action plan development
• Facilities a roadmap for
reducing cybersecurity risk
Core

High Level Core View

Know what you have

Secure what you have


Spot threats quickly
Take action immediately
Restore operations
Important Points
Only half of the
Framework’s
Categories are
addressed by
technology

Highlights the
importance of
both people and
process in
cybersecurity
CSF Uses

Basic Establishing Communicating Identifying Methodology


Review or Improving Cybersecurity Opportunities to
of a Requirements for Updated Protect Privacy
Cybersecurity Cybersecurity with Informative and
Practices Program Stakeholders References Civil Liberties

“How well are “Can we “Can we speak “What else “Can we


we doing assess and the same should we protect data
today?” improve?” language?” consider?” better?”

Let’s focus here


Improving a Program

Implement Action Plan Start Prioritize and Scope


7 1

Analyze Gaps 6 2 Orient

5 3
Create Target Profile 4 Create Current Profile

Conduct Risk Assessment


1

Prioritize and Scope

Identify business/mission objectives


and high-level organizational priorities
• Make strategic decisions on
cybersecurity
• Determine scope of systems and
assets that support the mission
• Assess risk tolerance
2

Orient

Identify related systems, regulatory


requirements, and overall risk approach
• Identify threats to systems and
assets
• Identify vulnerabilities associated
with systems and assets
Current Profile 3

Function Category Subcategory Current Profile


Physical device Manual, spreadsheet-based system is
inventories ([Link]-1) Tier 1 insufficient and lacks network visibility.

Software inventories Asset management system cannot detect new


([Link]-2) Tier 1 software applications being deployed.

Communication/data Flow maps are documented and approved but


Identify
Asset flow maps ([Link]-3) Tier 2 needs to be formalized by policy.
Management
(ID) ([Link]) External system Current business model does not require
catalogs ([Link]-4) Unused external system catalogs.

Resource prioritization Prioritization system is working well for our


([Link]-5) Tier 4 needs today.

Roles/responsibilities New cybersecurity responsibilities need to be


clarification ([Link]-6) Tier 3 formalized by policy.
Risk Assessment
4

Fxn. Cat. Sub. Current Profile Risk Assessment


[Link]-1 Tier 1
Unacceptably high risks
[Link]-2 Tier 1

[Link]-3 Tier 2
ID [Link]
[Link]-4 Unused
Acceptable risks at this time
[Link]-5 Tier 4
[Link]-6 Tier 3
Target Profile 5

Fxn. Cat. Sub. Target Profile

[Link]-1 Tier 4
This is where we want to be
[Link]-2 Tier 4
• Physical device and software
[Link]-3 Tier 2
inventories at Tier 4, “Adaptive” ID [Link]

• Practices fully established,


[Link]-4 Unused
continuously improved, and [Link]-5 Tier 4
built into our overall risk
management program [Link]-6 Tier 3
6

Gap Analysis
Fxn. Cat. Sub. Current Profile Fxn. Cat. Sub. Target Profile

[Link]-1 Tier 1 [Link]-1 Tier 4

[Link]-2 Tier 1 [Link]-2 Tier 4

[Link]-3 Tier 2 Enables a [Link]-3 Tier 2


ID [Link] ID [Link]
[Link]-4 Unused prioritized [Link]-4 Unused
action plan
[Link]-5 Tier 4 [Link]-5 Tier 4

[Link]-6 Tier 3 [Link]-6 Tier 3


7

Action Plan
Fxn. Cat. Sub. Informative Resources NIST SP 800-53 Revision 4
• CCS CSC 1 CM-8 / Information System Component Inventory
• COBIT 5 BAI09.01, BAI09.02
Control: The organization:
• ISA 62443-2-1:2009 [Link] a. Develops and documents an inventory of
[Link]-1 information system components that:
• ISA 62443-3-3:2013 SR 7.8
1. Accurately reflects the current information
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2 system;
• NIST SP 800-53 Rev. 4 CM-8 2. Includes all components within the
ID [Link] authorization boundary of the information
• CCS CSC 2 system;
• COBIT 5 BAI09.01, BAI09.02, BAI09.05 3. Is at the level of granularity deemed
necessary for tracking and reporting; and
• ISA 62443-2-1:2009 [Link]
[Link]-2 4. Includes [Assignment: organization-defined
• ISA 62443-3-3:2013 SR 7.8 information deemed necessary to achieve
• ISO/IEC 27001:2013 A.8.1.1, A.8.1.2 effective information system component
accountability]
• NIST SP 800-53 Rev. 4 CM-8
7

Develop Action Plan Device Inventory

?
?

We need an accurate ...but how can we know what’s


device inventory... actually on our network?
7

Device Discovery
Implement Action Plan and Profiling

NIST SP 800-53 Revision 4


CM-8 / Information System Component Inventory

Cisco Identity Control: The organization:


a. Develops and documents an inventory of
Services Engine (ISE) information system components that:
1. Accurately reflects the current information
system;
• Discovers and accurately identifies 2. Includes all components within the
authorization boundary of the information
devices connected to wired, wireless, system;
and virtual private networks 3. Is at the level of granularity deemed
necessary for tracking and reporting; and
4. Includes [Assignment: organization-defined
information deemed necessary to achieve
effective information system component
ISE accountability]
Continuous Improvement Not once and done!

Implement Action Plan Prioritize and Scope


7 1

Analyze Gaps 6 2 Orient

5 3
Create Target Profile 4 Create Current Profile

Conduct Risk Assessment


NIST RMF vs. NIST CSF What’s the difference?

Risk Management Framework


NIST RMF Overview Risk Management Framework

Start
Monitor Categorize
NIST SP 800-137 6 1 FIPS 199 & NIST SP 800-60

Authorize 5 2 Select
NIST SP 800-37 FIPS 200 & NIST SP 800-53

4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160

Source: NIST RMF Overview, [Link]


NIST RMF vs. NIST CSF Security Control Selection

NIST CSF guides organizations to risk-based Selection of effective


security controls for inclusion in existing risk-management process
Monitor Categorize
NIST SP 800-137 6 1 FIPS 199 & NIST SP 800-60

Authorize 5 2 Select
NIST SP 800-37 NIST SP 800-53

4 3
Assess Implement
NIST SP 800-53A NIST SP 800-160
NIST RMF vs. NIST CSF Other Important Differences

NIST CSF can be used with the NIST RMF but does not require it
• Organizations may choose to follow the NIST RMF, but are also free choose to use the NIST CSF with
ISO/IEC 27005 -- or any other enterprise risk management process

NIST CSF references the NIST SP 800-53 security control catalog but
does not require it
• Organizations may choose to select security controls from NIST SP 800-53, but are also free to select
from ISACA COBIT 5, ISO/IEC 27001/27002, or other security control catalogs
• NIST CSF Informative Resources refer to certain controls from NIST SP 800-53, but the CSF does not
reference the complete set of NIST SP 800-53 controls
• NIST CSF describes its own cybersecurity improvement process that leverages CSF Profiles and
Implementation Tiers, but without the rigor of the NIST RMF (e.g., no FIPS 199 System Categorization)
Cisco Security Strategy The Threat-Centric Security Model

Attack Continuum

Before During After


Discover Detect Scope
Enforce Block Contain
Harden Defend Remediate

Network Endpoint Mobile Virtual Cloud Email and Web

Point in Time Continuous


Cisco Security Strategy NIST CSF Alignment

Attack Continuum

Before During After


Discover Detect Scope
Enforce Block Contain
Harden Defend Remediate

CSF Identify Protect Detect Respond Recover


Technology

Cisco Security Products NIST CSF Alignment

Asset Management
Business Environment Non-technical control area
ID Governance Non-technical control area
Risk Assessment
Risk Mgmt. Strategy Non-technical control area
Access Control
Awareness/Training Non-technical control area
B
Data Security
PR
Info Protection Process Non-technical control area
Maintenance
Protective Technology
Anomalies and Events
DE Continuous Monitoring D
Detection Processes Non-technical control area
Response Planning Non-technical control area
Communications Non-technical control area
RS Analysis
Mitigation
Improvements Non-technical control area
A
Recovery Planning Non-technical control area
RC Improvements Non-technical control area
Communications Non-technical control area
People Process

Cisco Security Services NIST CSF Alignment

Advisory Integration Managed


Asset Management
Business Environment
ID Governance
Risk Assessment
Risk Mgmt. Strategy
Access Control
Awareness/Training
B
Data Security
PR
Info Protection Process
Maintenance
Protective Technology
Anomalies and Events
DE Continuous Monitoring D
Detection Processes
Response Planning
Communications
RS Analysis
Mitigation
Improvements
A
Recovery Planning
RC Improvements
Communications
Cisco Our Advantages

Cisco has the people, services, products, partners, corporate commitment and financial strength to
ensure your success
• Our worldwide security team, including threat intelligence, research, supply chain, and customer support
professionals, is focused on your success.

• Our services professionals can guide you as you plan, implement and manage your security, deliver security as a
service, or help you during an attack.

• Our family of best in class products work together to stop threats quickly while reducing complexity and cost.

• Because of our open platform and industry leadership, we team with comprehensive list of solutions providers and
delivery partners.

• Cisco is committed to your success with the financial strength to invest in research, develop new products, and
support your success

Securely digitizing you enterprise allows you to secure your


reputation, accelerate your mission, and save money.
Conclusion
Summary Did we accomplish our mission?

1. PA Cybersecurity Reviewed Assessment Framework

2. About NIST Discussed who they are and what they do

3. NIST SP 800-53 Explained how the control catalog works

[Link] RMF Connected with the Strategic Plan

5. NIST CSF Recommended it for cyber risk management


Call to Action
Learn more about Pennsylvania IT Governance
1 [Link]
nt_framework/203339

Learn more about NIST cybersecurity best practices:


2
[Link]
Learn more about Cisco’s threat-centric security:
3
[Link]

Thanks for your time today!

You might also like