Showing posts with label NIST RFI. Show all posts
Showing posts with label NIST RFI. Show all posts

Saturday, August 12, 2017

NIST Cybersecurity Workforce RFI Comments – 08-05-17

This is part of a continuing series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. The earlier posts in the series were:


This week there were only four new submissions posted to the NIST web site. Those were from:


AT&T pointed at a report that it had helped prepare for the Federal Communications Commission on cybersecurity workforce development in the communication’s sector.

The comments from Southern Utah University pointed at the course outline for their Masters program in Cybersecurity & Information Assurance. They also emphasized the need for academia and industry to cooperate in providing internship/apprenticeship opportunities for students or early career professionals.

The UI LABS – DMDII comments outline work that organization has done looking at the DFARS cybersecurity requirements for DOD contractors. They point out their research points to the problems that many of those contractors are having complying with the 109 cybersecurity requirements outlined in NIST 800-171.


UMass Lowell describes the certification program they have developed for implementation of the NIST Cybersecurity Framework.

Saturday, August 5, 2017

NIST Cybersecurity Workforce RFI Comments – 08-05-17

This is part of a continuing series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. The earlier posts in the series were:


There were comments received from 76 different organizations this week, some with multiple submissions. There is no way that I am going to do even a cursory review of that many submissions; I will leave that to the professionals at NIST. Instead I’ll select some of the submissions and hit some high points; all perfectly arbitrary and non-random.

One very important point was made by Anna Johnston from the Information Systems Security
Association (ISSA) in Colorado Springs, CO. She noted that: “Too many businesses are seeking to hire senior cyber personnel to do basic diagnostics, patching, etc., when those tasks can be done by more junior cyber-skilled people.” Everyone wants rock stars to be backup singers. Great if you can afford it, but expect high-turnover.

The Automation Federation asks an interesting question; why isn’t cybersecurity included as a base fundamental skill in every part of our education system? They note: “Little attention is paid to the millions of workers in the middle, who are most likely the ones who need the most knowledge on how to perform their day to day tasks in a cyber secure manner.”

The California Governor’s Office of Emergency Services response addresses an often overlooked aspect of cybersecurity; emergency response. They that California is attempting to develop a strategy “intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among California's workforce of cybersecurity professionals, and expand cybersecurity awareness and public education”.

The Center for Long-Term Cybersecurity (CLTC) points out a long standing problem with government hiring of cybersecurity professionals; the “cumbersome security clearance processes that often cause applicants to lose interest in government jobs before their application process is completed, and security policies that can unnecessarily isolate employees from their social and
professional networks”.

The Energy Sector Security Consortium, Inc. (EnergySec) makes two important points. First the continuing disconnect between IT and OT cybersecurity, noting that:

“Although NICE has a workforce framework, it is not widely used in our industry to identify the security roles or job descriptions. The roles identified in the framework are mostly applicable to traditional Information Technology aspects of business vs. the Operational Technology (e.g. industrial control systems).”

Second, they note the very real need for entry-level jobs “to provide a bridge from the emerging academic programs to mid and senior levels positions”.

While the Security University’s response has a very odd organization it does make a series of interesting points. Very importantly, they note:

“95% of cyber security professionals do not require a cybersecurity degree for a high wage in demand cyber job. They need qualified and validated skills learned from seasoned, skilled cybersecurity professionals with a practicum that demonstrates the student has learned a process and methodology that uses cybersecurity tools and understands enough of the risk policy to determine how to defend based on known threats in order to defend against unknown threats.”

Tenable makes an interesting observation in their response:

“However, our efforts to expand the human workforce will inevitably fall short of the insatiable demand for cyber talent, and we have to prepare for that. We need to have a complementary focus on technology and automation, enabling us to make the most of the human experts we have. Asymmetrically leveraging our cyber talent through the use of technology is the only path to success.”

The Coast Guard response also makes a very important point:


“Cybersecurity training and education must be agile in its planning, assessment, development and delivery cycle to adapt to the speed at which technology drives change and the need to adapt.”

Saturday, July 29, 2017

NIST Cybersecurity Workforce RFI Comments – 07-29-17

This is the second in a series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. The earlier post in the series was:


Comments posted (16) this week came from:


Issues addressed include:

• The private sector vs government pay differential;
• The use of Cyber Security Gaming and Simulations Cloud (CGSC) academies to engage K12 students and teachers;
• The lack of standard metrics or data for cybersecurity education, training, and workforce development programs;
• The NIST NICE Regional Alliances for Multistakeholder Partnerships Program (RAMPS);
• The  NCSF Controls Factory™ model created by Larry Wilson, CISO in the university (U of Massachusetts) president’s office to engineer, operate and manage the business risk of a NIST Cybersecurity Program;
• Vehicle cybersecurity workforce development program paper;
• The Scholarships for Women Studying Information Security (SWSIS) program; and
• Support for academic training programs.


A much higher percentage of respondents attempted to specifically answer the question that were posed in the RFI document (marked with *). Those responses may be worth reading depending on the amount detail one is looking for in the RFI. NIST will certainly pay close scrutiny to those submissions.

Saturday, July 22, 2017

NIST Cybersecurity Workforce RFI Comments – 07-22-17

This is the first in a series of blog posts looking at the comments that NIST has received on their request for information (RFI) on cyber workforce development. The comments are posted to the NIST National Initiative for Cybersecurity Education (NICE) web site. Comments posted this week came from:


 One commenter specifically responded to questions posed by NIST in their RFI. The others were long form explications of viewpoints about specific issues. One was a copy of an article published on CIODive.com addressing some different non-traditional cybersecurity-training activities that have been tried. Another suggested that we need to start looking at specialization training for cybersecurity personnel rather than generalist training. And the last one addressed the need for rapid changes in cybersecurity training programs to reflect changes in the environment.


The comments from Eric Baechle provided specific responses for the NIST questions. The views from Eric paint a very bleak picture of how cybersecurity specialists are utilized at one, unnamed agency (presumably government agency, but that is not exactly clear). Not unexpectedly they paint a picture of an agency management that does not understand the complexities of the cybersecurity problems being addressed by the specialized workforce nor the work actually being done by their cybersecurity team. While this is not directly a workforce development issue (other than apparently there is no effort in this organization being made to continue developing the skills of the team being employed) it does help to explain why there may be retention issues and employee burnout affecting cybersecurity operations.

Sunday, October 5, 2014

No Responses to NIST RFI

Back in August the National Institute for Standards and Technology published a request for information about organizational experience with the Cybersecurity Framework (CSF) that was published last February. With five days left in the comment period NOT ONE RESPONSE has been posted to the NIST web site. I suppose that it could be that NIST is so overwhelmed with responses that they just haven’t had a chance to get them up on their site, but I don’t really expect that that is the case.

I suspect that while the information security press has had qualified good things to say about the CSF that it is mainly a dead issue with industry in general. We have seen no movement by the regulatory agencies that might have been able to use the CSF as a tool to help gauge cybersecurity management to publicize much less use this tool.


It is a shame. The folks at NIST, and many folks in the private sector, spent a great deal of time and effort coming up with a consensus document that is either so perfect that no one sees a need to improve it, or is so lame that nobody thinks that it is fixable. 

NOTE: Thanks to a TWEET by Aristotle Tzafalias I learned that NIST has said that they will only post the comments to their web site after the close of the comment period. Certainly an odd way of doing things, but within their prerogative. 10-16-14 04:20 CDT.

Tuesday, February 26, 2013

NIST Publishes Cybersecurity RFI


This morning the National Institute of Standards and Technology (NIST) Published a notice in the Federal Register (78 FR 13024-13028) requesting information in support of their development of the Cybersecurity Framework directed by the President’s Executive Order “Improving Critical Infrastructure Cybersecurity” (EO 13636).

The RFI

The bulk of the request for information (RFI) is as I have described in two previous blog posts on the President’s Executive Order:


The opening paragraphs of the Supplementary Information section of the RFI are substantially different than those found in the Draft RFI published a week and a half ago. There is not a lot of new information here; mainly just a change in focus and justification for the development of the Framework. An important part of this is the following general statement of how NIST will tackle this complex task:

“As a non-regulatory Federal agency, NIST will develop the Framework in a manner that is consistent with its mission to promote U.S. innovation and industrial competitiveness through the development of standards and guidelines in consultation with stakeholders in both government and industry. While the focus will be on the Nation’s critical infrastructure, the Framework will be developed in a manner to promote wide adoption of practices to increase cybersecurity across all sectors and industry types.”

Suggested Changes

The suggestions that I made for additional questions and the modification of one question were certainly not adopted in the RFI. Since the suggestions were made just yesterday, even if NIST had been so inclined, there was not time to make changes to the RFI for today’s publication.

While the RFI provides a number of questions that NIST wants to have the critical infrastructure community address in their responses, the RFI also makes clear that any additional information the community can provide that might assist NIST in developing the framework will be appreciated. With that in mind I want to re-post the additional questions that I think should be addressed in the development of the Cybersecurity Framework. I would like to suggest that any critical infrastructure facility or organization with industrial control systems should address these questions when providing a response to this RFI.

• Does the organization maintain separate security programs for control systems and information systems or are they combined under a single manager?
• Are there significant differences in the ways in which the security programs for IT and control systems manage the risks associated with those systems?
• Does the organization utilize different standards, guidelines and/or best practices in establishing the security requirements for their IT systems and control systems?

Public Response

The whole point of an RFI is to solicit public comments on the topic. Comments on this RFI may be submitted to NIST via email (cyberframework@nist.gov). Comments need to be submitted by April 8th, 2013. NIST reports that they will publish all comments received, without redaction, at http://csrc.nist.gov.

It is important that everyone in the control system cybersecurity community should take the time to read and respond to this RFI. NIST needs as much as possible from this community to ensure that the unique cybersecurity concerns of control systems be adequately addressed in the preliminary Framework being developed by NIST.

Moving Forward

This early publication of the NIST RFI is one of the best signs that I have seen that this Executive Order might actually get implemented before President Obama leaves office. There are still a number of potential road blocks and political hurdles that must be overcome, but this is an encouraging sign.

Monday, February 25, 2013

Cybersecurity EO – NIST RFI Questions


This is the second in a series of posts about the Cybersecurity Framework being developed by the Director of the National Institute of Standards and Technology (NIST). This post looks at some of the questions NIST is including in their Request for Information that will be published in the Federal Register in the hopefully not too distant future.

Earlier blog posts include:


As I noted in the earlier post, the Director has posted on the NIST web site a draft of the request for information (RFI) that he intends on publishing in the Federal Register as part of the collaborative effort to develop a consensus supported Cybersecurity Framework as part of President Obama’s Executive Order “Improving Critical Infrastructure Cybersecurity” (EO 13636). Under the terms of that EO the Director of NIST is supposed to publish a preliminary Framework by October 17th, 2013.

The draft RFI addresses three main areas that it wishes the critical infrastructure community to address in providing information to support the development of the Cybersecurity Framework. They are:

• Current Risk Management Practices (pg 4);
• Use of Frameworks, Standards, Guidelines, and Best Practices (pg 5); and
• Specific Industry Practices (pg 6).

Current Risk Management Practices

There are twelve general questions listed in this section that NIST would like the critical infrastructure (CI) community to answer. The first two are sort of generic questions dealing with the challenges associated with cybersecurity; specifically with improving CI cybersecurity practices and with developing a cross-sector, standards based Framework. The remaining questions deal more specifically with how CI organizations are currently dealing with cybersecurity management issues.

While I have mentioned an apparent information technology focus of the EO and the RFI, that focus is much less noticeable here. None of the questions actually mentions IT and they all could clearly include policies and procedures dealing with control system issues. I do think that the vast majority of the responses that NIST will receive for these questions will be IT focused. That realistically reflects the fact that the IT portion of the cyber-community is much larger and has been focusing on cybersecurity issues longer.

Having said that, and given the fact that control system security issues are more likely to lead to catastrophic effects, I would like to suggest that NIST add two control-system specific questions to the mix about current risk management practices:

• Does the organization maintain separate security programs for control systems and information systems or are they combined under a single manager?
• Are there significant differences in the ways in which the security programs for IT and control systems manage the risks associated with those systems?

Use of Frameworks, Standards, Guidelines, and Best Practices

Since the President’s guidance for the development of the Cybersecurity Framework emphasizes the maximum possible use of existing consensus standards this second set of questions will be very important in gathering the data necessary for that development.

Again, the questions in this section are generic enough that they could address both IT and control system security issues. Unfortunately, given the relative size of the IT security and control system security communities within most organizations, I’m afraid that the control-system security side of the problem will not receive the same level of attention in the responses to these questions.

To ensure that the control-system side receives adequate attention I would like to see one question added to this section:

• Does the organization utilize different standards, guidelines and/or best practices in establishing the security requirements for their IT systems and control systems?

Specific Industry Practices

The last set of questions deal with 9 specific areas dealing with current industry practices concerning cybersecurity. Those areas are:


• Separation of business from operational systems;
• Use of encryption and key management;
• Identification and authorization of users accessing systems;
• Asset identification and management;
• Monitoring and incident detection tools and capabilities;
• Incident handling policies and procedures;
• Mission/system resiliency practices;
• Security engineering practices; and
• Privacy and civil liberties protection.

Reading the questions for this section it is clear that NIST considers these 9 areas to be the core practices that will be included in the framework. This makes the inclusion of the first area very important. I would, however, like to suggest that one key area is missing from this list, a personnel surety program though I suppose that could be shoe-horned into the identification and authorization of users.

The IT-centric nature of the program does raise its head unnecessarily in Questions 7 in this section. That question reads:

Do organizations have a methodology in place for the proper allocation of business resources to invest in, create, and maintain IT standards?

Substitute ‘cybersecurity’ for ‘IT’ in that question and I think that you have a more appropriate question for both sides of the cyber house.

Moving Forward

It was encouraging to see that NIST was so far ahead of the game with their development of the draft RFI before the ink was dry on Obama’s signature on the EO. Of course they were well aware of the Cybersecurity Framework requirements, probably back in November, or maybe even before. The delay in getting the RFI published in the Federal Register, however, points to the political wrangling that will inevitably make it difficult for NIST to meet their October 17th deadline for the publishing of the preliminary Framework.

And remember, there are other deadlines that will have an impact on the timeliness of NIST’s work. I’ll look at those in some detail in future blogs in this series.
 
/* Use this with templates/template-twocol.html */