Showing posts with label Framework Implementation. Show all posts
Showing posts with label Framework Implementation. Show all posts

Friday, January 9, 2015

DOE Publishes Cybersecurity Framework Implementation Guidance

Yesterday the Department of Energy published the Energy Sector Cybersecurity Framework Implementation Guidance. This is the DOE’s approach to helping “the energy sector establish or align existing cybersecurity risk management programs to meet the objectives of the Cybersecurity Framework released by the National Institutes of Standards and Technology (NIST) in February 2014”.

I’ve had a chance to just glance through the 24 page document and it looks like it provides a pretty good summary of the Framework and looks at how the Framework can be applied to cybersecurity management under a number of DOE related security programs and processes.

The discussion about the Framework implementation using the DOE’s Cybersecurity Capability Maturity Model (C2M2) approach is quite detailed. There is a lengthy table mapping the C2M2 practices to the Framework Core and another describing how the C2M2 practices can be utilized in establishing the Framework Tier ranking.

Since DOE components have probably been looking at cybersecurity concerns longer than most any non-military agency of the US Government, it is nice to see their take on the NIST Framework. It is somewhat disheartening though that this document took almost a year to field.


BTW: Thanks to ICS-CERT for pointing at this document.

Tuesday, August 26, 2014

NIST Publishes Framework Follow-up RFI

Today the National Institute of Standards and Technology published a request for information in the Federal Register (79 FR 50891-50894) concerning information about organizational experiences with the implementation of the Framework for Improving Critical Infrastructure Cybersecurity that was published in February.

Responses to this RFI will help NIST develop tools and resources to help organizations to use the Framework more effectively and efficiently. The information will also be shared with DHS to aid in the implementation of the Critical Infrastructure Cyber Community (C3) Voluntary Program that the Administration developed to encourage organizations to implement the Framework. Finally, the information will help NIST to establish the agenda details of the upcoming Framework review workshop in October 2014.

The RFI is looking for specific information in three broad categories. Within each of those areas NIST proposes a series of questions that it would like to have answered by critical infrastructure organizations, standards setting organizations, and governmental agencies at all levels concerned with cybersecurity issues. Those three categories are:



As we came to expect during the development of the Framework, NIST is not using the Federal eRulemaking Portal for their information collection process. Responses will be sent directly to NIST and may be submitted by email (cyberframework@nist.gov). Responses should be sent by October 10th, 2014. Responses will be published on the NIST Framework web site.
 
/* Use this with templates/template-twocol.html */