Showing posts with label CSF Update. Show all posts
Showing posts with label CSF Update. Show all posts

Saturday, February 27, 2016

Responses to Latest CSF RFI – 02-27-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period was extended until February 23rd, 2016. The previous posts in this series include:


This week there were 47 new responses (almost as many as had been posted in total by last week) to the RFI and all but one of them were dated after February 9th, the original comment cut-off date and one was dated after the new cut-off date. Obviously it was a smart move on the part of NIST to extend the comment period. As I noted last week, I expect that there will probably be one more of these posts to catch any additional late adds to the response list.

The comments posted this week come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

One commenter suggested that federal regulators map their cybersecurity regulations to the CSF as the CSF is mapped to various standards. Another commenter suggested instead that NIST conduct such regulatory mapping. Regulatory mapping was addressed by a number (6) of additional commenters.

One commenter noted that the effect of IoT on the CSF should be looked at. Another commenter suggested that there should be more emphasis on acquisition and supply chain issues.

One commenter suggested that regulators use CSF reporting as their regulatory methodology.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

A number of commenters (1) recommended that the CSF should continue to be updated as existing standards are updated and new standards are published.

One commenter noted that the CSF should be expanded to include cyber threats, insider threats and physical threats. Another commenter suggested that the CSF should involve more detail about technological concepts that effect implementation. Yet another suggested that the CSF should include more detail on creating a target profile. And another suggested more emphasis on state-of-the-art risk management practices. And another requested that the CSF be expanded to include product integrity and supply chain security. Another commenter suggested that medical device and industrial control systems need coverage in the CSF. Big-data and cloud privacy issues were suggested by another commenter as areas that need to be addressed.

One commenter suggested that CSF stability should be a primary concern. Another commented that reducing the frequency of updates would be helpful.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

A number of commenters (7) noted that the private sector should continue to provide input on CSF improvements. One commenter specifically recommended continued use of RFI’s and regional workshops.

One commenter argued that the users of the framework should provide the governance. Another commenter suggested that the private sector should provide feed-back on implementation issues.

One commenter suggested that NIST should hold semi-annual workshops to address potential changes to the CSF.

Commentary

A total of 100 responses have been posted to the NIST site as of today. Fewer than half of the commenters used the either the spread-sheet format requested by NIST or keyed their responses to specific questions posed in the RFI. I really wish that the commenters that did not have the common decency to take the effort to consider how NIST was hoping to use their responses would sit down and read the 100 responses submitted to date and try to make sense of the data presented.

I am sure that a great deal of effort went into developing these 10 and 20 page responses that went into great detail about how the organization was diligently working on cybersecurity. Unfortunately, those comments were better suited to a press release than being helpful to NIST in charting the future of the CSF.

Over the last two weekends I have spent four hours reviewing responses to look for and analyze information on just three of the twenty questions. And I did not even attempt to read the responses that were not prominently keyed to the specific questions I was looking at. NIST on the other hand is going to have to peruse each of the missives to try to extract the requested information. I do not envy the NIST reviewers who will be required to review each and every submission, no matter how verbose and self-advertising.

It was interesting that out of 47 submissions posted this week, only one mentioned the fact that the CSF needs to be periodically updated to reflect revisions to the various standards referenced in the document. In the long run, I think that it was probably more important that a number of commenters noted that there should be a mapping of CSF and cybersecurity regulations. Comments went both ways; suggesting that regulations reference CSF and vice versa.

Nobody has suggested that new cybersecurity regulations have to be applied; instead they are recommending that regulated industries that are already facing security regulations have the cybersecurity provisions tied into the CSF. That way, commenters suggest, there would not be competing requirements, especially for those organizations facing multiple regulatory schemes.

I was happy to see a number of cybersecurity research organizations included in the responders this week. They had some different insights from those provided by industry organizations.


Saturday, February 20, 2016

Responses to Latest CSF RFI – 02-20-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period was extended and will remain open until February 23rd, 2016. The previous posts in this series include:



This week there were 37 new responses to the RFI and most of them were dated on or before February 9th, the original comment cut-off date. This lag has been fairly normal for the NIST RFI’s and is certainly due to the fact that they have to hand process these comments from emails. If NIST stays in the comment reception process they really need to come up with an automated system for receiving/posting the comments.

Since the new comment deadline is this week I expect that I will be doing these posts for at least two more weekends.

The comments posted this week come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

A couple of commenters recommended that the CSF continue to be voluntary in response to this question.

One commenter noted that DOD, DHS and NSA are developing separate voluntary and mandatory guidelines and approaches which makes compliance more difficult. Another commenter suggested that the CSF be used to harmonize cybersecurity regulatory development. It was suggested by yet another commenter that policy makers should collaborate with federal agencies and the private sector to prevent duplication of regulatory processes and prevent conflict with superseding of regulatory requirements. One health care commenter called for more alignment within the federal government in applying risk management principles. Another commenter suggested that regulators use CSF reporting frameworks as part of their regulatory scheme.

Continued cooperation between standards setting organizations was also suggested. One commenter suggested that a public/private sector guidance body be established.

One commenter noted that the voluntary nature of the CSF implementation was beneficial because it allowed an organization to ignore, add or eliminate processes so that the CSF would be more applicable to the organization.

Another commenter noted that NIST should expand its development of CSF profiles for different regulatory regimes or that regulators could reference the CSF in their rules. One commenter noted that Sector Specific Agencies be required to develop CSF implementation guidelines. Another commenter suggested that the CSF be expanded to an international scope. Another commenter suggested that the CSF should be expanded to include more specific measurable/observable criteria to better support regulatory reporting.

One commenter suggested that continued private sector involvement in CSF updates would ensure that the CSF does not conflict with regulatory requirements.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

A number of commenters (8) recommended that the CSF should continue to be updated as existing standards are updated and new standards are published. One commenter noted, however, that updates should be limited to allow for adequate implementation experience to guide future updates; this was reinforced by other commenters.

One commenter specifically recommended that health care organizations take an active role in the update process. Another commenter suggested that outdated measures should be removed. A suggestion was made that NIST and industry should work together to develop industry specific implementation guidelines. Yet another commenter suggested that there should be more public safety input into the CSF development process. It was suggested that the CSF remain technology neutral.

An equipment vendor noted that supply chain security issues need to be addressed in the CSF. Another commenter suggested that the internet of things and bring your own device problems should be addressed in the CSF. Yet another commenter suggested that high level control areas for PKI security be included. A government agency suggested that future updates should reflect all stakeholder needs.

One commenter opposed regular updates to the CSF, noting that continuity was more important in the changing field of cybersecurity.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

A number of commenters (10) noted that the private sector should continue to provide input on CSF improvements.

One commenter noted that the private sector should be providing input to both NIST and standards setting organizations. Another commenter noted that multiple inter-sector dependencies need to be identified. One commenter maintained that private sector involvement leads to a sustainable program. Yet another suggested that the private sector should play a critical role in the CSF governance with another suggesting that the private sector should own the CSF and its governance.

One commenter suggested that private sector input be limited to anonymized input on implementation issues.

Commentary

A total of 53 responses were ultimately received by the end of the original comment period from a broad cross section of responders. This actually ended up being a pretty decent number of responses for this type of non-regulatory request for comments. I was disappointed in the relative lack of responses from security researchers as I know that a number were involved in the original process that led to the publication of the CSF; I expect, however, that they would again get involved in any change process.

Having said that, it should be noted that I did not submit any comments to this RFI. Since the questions were mainly targeted at organizations that had either used the CSF or specifically decided not to use the Framework, I didn’t think that my more philosophical comments would really be appropriate. And that may have been why we saw so few comments from individuals in response to the RFI.

I want to remind folks that the continuing analysis of the responses to the RFI that I have been doing has been limited to those responses that specifically (and clearly) addressed specific questions in the RFI. For the most part I ignored (and suspect that NIST will largely ignore) the more verbose and erudite commentaries on the CSF that were submitted by a large number of the commenters. NIST was looking for specific information and those commenters were not helpful in that regards.

A number of those non-responsive responses were more targeted at the next version of the CSF and may have been more appropriately saved for that process. There was at least one exception to this; the comments submitted by HITRUST both addressed the NIST RFI questions and provided some in depth suggestions for how the next version of the CSF should look. If you are really interested in the future of the CSF I suggest that you take a look at their lengthy commentary; I expect (and hope) that they will be actively involved in the CSF revision process.

Readers of this series of posts will realize that I am a big fan of the NIST attempts to get commenters to use the spread sheet format for submitting responses to the questions that they asked. This makes the compilation and analysis of those comments so much easier. I would like to suggest that NIST continue to work at the development of this process and include the development of a methodology of automating the reception of those spread sheets.


OMB should be actively working with NIST on developing this process of automating the collection and analysis of public comments. This would go a long way to making the regulatory process more effective and reduce the time necessary to complete the regulatory process.

Saturday, February 13, 2016

Responses to Latest CSF RFI – 02-13-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:



This week there were ten new responses to the RFI. This is almost the same as the total number that had been submitted by last Saturday, and they all came before the original deadline. This week’s responses came from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

One commenter recommended that the Federal government should consolidate the Federal cybersecurity effort to avoid having multiple requirements from separate agencies. Similarly, another commenter suggested that if the CSF were to become the regulatory standard, that all agency regulations should be based upon that standard. On the other hand, a separate commenter noted that regulatory requirements should be included in the CSF. Alternatively, another commenter suggested that NIST should have greater outreach to Federal, State and local regulators to aid them in developing consistent regulatory schemes.

One commenter noted that as new industry and international standards are developed they should be incorporated in the CSF. Another commenter suggested that the relationship between the CSF and the NIST Risk Management Framework should be clarified.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

One commenter noted that the CSF should be cautiously updated to reflect changes in evolving cyber technology and the risk landscape. Another commenter suggested that the CSF needs an implementation plan and an assessment tool like DHS’ Cyber Resilience Review tool. Yet another commenter recommended that newer versions of the CSF should focus on critical areas and key mitigation plans like perimeter defense strategies.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

One commenter suggested that while NIST should maintain responsibility for CSF governance, ISACS should become directly involved in CSF changes. Another noted that industry Organizations like CHIME should become involved in the CSF process. One commenter suggested that the NERC CIP process has shown that a period of stability is needed between revisions of the CSF, so that lessons learned can be properly identified and incorporated.

Commentary

While the number of commenters that have provided input during the initial 60-day comment period is staggeringly inadequate, the latest batch has a number of interesting and provocative ideas for NIST to consider.

I would like to point out that the majority of the comments received this week were in the CSF comment submission format. This makes the review of the comments much easier. Commenters need to realize that if their intent is to actually influence the CSF improvement process, then making it easier for the reviewers to understand and collate the responses increases the efficiency of the influence.

There were a couple of commenters that seemed to have confused the management tool that is the Cybersecurity Framework and cybersecurity regulations. The CSF is a tool that can be used to analyze the current state of an organizations cybersecurity practices and to figure out what the organizational goals in the field should be and how to achieve them. Regulatory schemes are designed to set minimum standards, establish compliance measures for those standards and ensure that those compliance standards are met. One would like to think that an organization, while having to meet regulatory requirements, would aspire to a higher standard performance. The CSF provides a tool to establish that higher performance level and outline a means to achieve that goal.

Regulatory agencies could certainly use the CSF as a tool for ensuring that their minimum standards reflect industry standards and capabilities. It also provides the necessary references for finding appropriate measurement tools to gauge the effectiveness of responses to regulatory requirements.


But, the CSF is not a regulatory framework. It was never intended to be such and would lose much of its effectiveness if it became one. Probably the greatest advantage of the CSF verses cybersecurity regulations is that it should be easier to update the Framework to reflect changes in the cybersecurity landscape than it would ever be to update regulations. In large part this is because it’s voluntary nature makes organizations much less resistant to changes in the Framework.

Saturday, February 6, 2016

Responses to Latest CSF RFI – 02-06-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:


This week there were five new responses to the RFI. This is the largest number of responses in a single week, but it is still a remarkably small number of responses. This is even more concerning because the comment period ends on Tuesday. This week’s responses came from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Only three of the responders addressed this question in their response. One recommended that the CSF continue to be a voluntary program until such time that there was an industry wide consensus that the Framework should be adopted. Another commenter suggested that various cybersecurity regulatory standards be included in the reference standards. The final commenter on this questions suggested that a cross-functional group (including representatives from industry and standards organizations) be formed to establish a CSF change control process

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

The same three commenters also addressed this question. One suggested that change for change sake should be carefully avoided. A second recommended that the next update should address risk management decisions and prioritization processes in more detail. The other responded that updates should be responsive to industry feedback.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Again comments on this question were only receive from the same commenters that responded to questions 9 and 10. One expressed support for continuing NIST control of the CSF process with advice from industry. Another suggested that industry support should be specifically restricted to an advisory role to avoid conflict of interests. The third commenter suggested that NIST continue with using the RFI process and holding open public meetings and workshops when updating the CSF.

Commentary

Only two of this week’s commenters used the NIST spreadsheet for submitting comments. The third that responded to specific questions used a standard WORD® format with responses specifically keyed to the RFI questions. The remaining two commenters used the old-style letter format that pressed their organizational agenda rather than specifically respond to the RFI questions.

I suspect that that out-of-date response style means that what may have been legitimate and perhaps useful concerns will likely be given little consideration in moving the CSF update process forward. NIST has established a history of moving forward quickly in response to RFIs and that can only happen when specific responses are given to specific questions.


I really hope that there will be a much larger number of responses received in this last week of the response process. If we continue with the same level of response it is hard to imagine that NIST will be able to continue forward with a rigorous update process for the CSF.
 
/* Use this with templates/template-twocol.html */