Showing posts with label CSF Workshop. Show all posts
Showing posts with label CSF Workshop. Show all posts

Saturday, April 22, 2017

NIST Announces CSF 1.1 Workshop – May 16th, 2017

NIST has announced another in a series of workshops concerning the proposed new version of their Cybersecurity Framework (CSF 1.1). The 2-day workshop will be held in Gaithersburg, Maryland on May 16th, 2017. The draft agenda for the workshop was made available this week on their CSF website.

I have not covered CSF 1.1 because the CSF is not operationally an industrial control system (ICS) security program. There are ICS components, but this is a cybersecurity management tool, not actually a cybersecurity tool. I have not seen anything in CSF 1.1 that would change that assessment.

Having said that, I am mentioning this workshop because it contains an internet of things (IOT) breakout session on the second day of the CSF 1.1 workshop. The agenda describes it this way:

“Cyber Meets the Physical World: The diverse use and rapid proliferation of connected devices – typically captured by the “Internet of Things (IoT)” – creates enormous value for industry, consumers, and broader society. At the same time, emerging threats, such as last year’s Mirai DDoS attacks, highlight the critical need to develop and apply guidance to maintain the cybersecurity of devices and the ecosystems into which they are deployed. NIST is seeking feedback on how the Framework may be applied to the IoT, both in terms of the devices themselves, as well as their integration into broader enterprise and network environments. Topics in this breakout may include: existing IoT definitions and taxonomies and their consistency with the Framework; IoT specific threats and constraints; sector-specific considerations for IoT security; and the integration of IoT-specific threats into the Framework model.”

Even this description of ‘Cyber Meets the Physical World’ contains no specific reference to industrial control systems, or even really hints at their existence. This is the thing that continues to concern me about the CSF. I hope that I am reading too much into this brief description and I hope that we hear from some attendees with an ICS cybersecurity background that there was some specific and realistic discussion of ICS specific security concerns with IOT and how that might be dealt with in the CSF environment.


Early registration is recommended by NIST due to the limited seating available. Registration closes on May 9th, 2017.

Saturday, March 26, 2016

NIST Announces Pre-Workshop Session

This week NIST announced that the NIST National Cybersecurity Center of Excellence (NCCoE) will be holding a two-hour meeting before the Cybersecurity Framework Workshop next month. The meeting will be for personnel in the maritime and the oil/gas industries.

According to the announcement:

“In this NCCoE-facilitated Open Session, attendees will identify and prioritize hard cybersecurity problems in addressing challenges for enterprises in the maritime and oil & natural gas industries. The session will begin with a quick overview of the NCCoE's Use Case & Building Block tool identification process. We will then conduct a facilitated discussion identifying and prioritizing potential cybersecurity Use Case challenge statements to solve with partners in our labs. As part of the session, the NCCoE will share some candidate use cases identified during its work with the maritime and oil & natural gas industry to develop a CyberSecurity Framework Profile.”

There is a possibility that the discussion will be extended by up to two additional hours depending on participation.

NOTE: NIST also has a YouTube® video available about the workshop.


Saturday, March 19, 2016

NIST Updates CSF Meeting Agenda

This week the National Institute of Standards and Technology (NIST) updated the draft agenda for their 2016 Cybersecurity Framework Workshop next month. The new agenda (.PDF) expands the information available on the topics to be discussed. My earlier post on this workshop can be found here.

The first day of the workshop (April 5th) is primarily designed for attendees who are not completely familiar with the Cybersecurity Framework (CSF) or the methodology that NIST used to develop the CSF. There will be two separate (but identical) Framework overviews presented by NIST. Attendance is obviously optional.

During the remainder of the 3-day workshop there will be three panel discussions and a number of working sessions. The panels will include:

• NIST Panel RFI Readout;
• Framework Use (Red Auditorium);
• International Alignment (Red Auditorium);
• Maritime Framework Profile (Green Auditorium);
• Cybersecurity Insurance (Red Auditorium); and
• State, Local, and Tribal Framework Use (Red Auditorium)

Based upon past NIST CSF workshops the working sessions will typically be led by NIST personnel, but will focus on audience participation and input. Topics for the working sessions will include:

• Roadmap Items – Privacy and Civil Liberties, International Alignment;
• RFI Topics – Governance, Framework Update;
• Special Topics in Framework Use – U.S. Coast Guard Framework Profile;
• Roadmap Items – Supply Chain Risk Management, Confidence Mechanisms;
• RFI Topics – Governance, Framework Update, Best Practice Sharing;
• Roadmap Items – Workforce and Education, Automated Indicator Sharing;
• RFI Topics – Governance, Framework Update, Best Practice Sharing;
• Special Topics in Framework Use – FFIEC Cybersecurity Assessment Tool;
• Roadmap Items – Authentication, Federal Agency Cybersecurity Alignment;
• RFI Topics - Framework Update; and
• Special Topics in Framework Use – CSIP Recover Publication

This agenda may be refined somewhat more as the dates approach, but based upon past workshops, this will be pretty much what will be going on. Before the workshop starts I expect that we will have at least a preliminary assessment by NIST of the RFI Comments.


 
/* Use this with templates/template-twocol.html */