Showing posts with label RFI. Show all posts
Showing posts with label RFI. Show all posts

Wednesday, August 12, 2026

Review - NIST Publishes RFI for Updating NVD for AI

Today, DOC’s National Institute of Standards and Technology (NIST) published a request for information (RFI) on “Modernizing the National Vulnerability Database in the Age of Artificial Intelligence”. NIST is looking for input from the cybersecurity community on how the NVD can grow to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility. 

According to the document summary: 

“The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.” 

Public Feedback  

NIST is requesting public feedback on, and answers to, the provided questions. NIST is requesting that those public responses be submitted via the Federal eRulemaking Portal (www.Regulations.gov; docket # NIST-2026-0100). Comments should be submitted by October 13th, 2026. 


For more details about the questions proposed, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nist-publishes-rfi-for-updating-nvd - subscription required. 

Thursday, September 26, 2024

Review – NSF Publishes RFI for Cyber-Physical Resilience Research

Today, the National Science Foundation (NSF) published a request for information in the Federal Register (89 FR 78915-78916) for “Networking and Information Technology Research and Development Request for Information on a National Plan for Cyber-Physical Systems Resilience”. The notice reports that: “The goal of the plan is to shape a whole-of-government research and development (R&D) plan related to cyber-physical resilience across systems that may be local, regional, or national in scope.”

The proposed research plan would be based, at least in part, on the following documents:

PCAST Releases Report on Strategy for Cyber-Physical Resilience,

Strategy for Cyber-Physical Resilience: Fortifying Our Critical Infrastructure for a Digital World, and

Cyber-Physical Systems Resilience—The Networking and Information Technology Research and Development (NITRD) Program.

The NSF is soliciting comments that “address the topics of this RFI clearly and concisely”. Comments should be emailed to CPSR-ftacRFI@nitrd.gov. Comments should be submitted by October 26th, 2024.

 

For more information about the RFI, including a brief description of the scope of the information requested, see my article a CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/nsf-publishes-rfi-for-cyber-physical - subscription required.

Wednesday, August 16, 2023

Review - Cyber Director RFI on Harmonizing Cybersecurity Regulations

Today, the Office of the National Cyber Director published a request for information in the Federal Register (88 FR 55694-55697) for “Request for Information: Opportunities for and Obstacles To Harmonizing Cybersecurity Regulations”. An earlier version of this request was made by the ONCD on July 19th, 2023, but it was not published in the Federal Register.

Public Comments Solicited

ONCD is soliciting public comments on this RFI. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # ONCD-2023-0001). Comments should be submitted by October 31st, 2023. The earlier request on WhiteHouse.gov had a deadline of September 15th. That deadline is specifically extended by this RFI.

 

For more details on the RFI, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cyber-director-rfi-on-harmonizing - subscription required.

Friday, March 13, 2020

CG Sends Autonomous Vessel RFI to OMB


Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received from the Coast Guard a request for information (RFI) for review. This pre-rulemaking document concerns “Identifying Barriers to Autonomous Vessels”.

According to the 2019 Fall Unified Agenda entry for this rulemaking:

“This notice solicits the public’s views on United States Coast Guard (USCG) regulations that may need to be updated, modified, or eliminated to facilitate the safe introduction of automated commercial vessels into our nation’s waterways. USCG requests comment on specific regulatory and operational requirements that are likely to be affected by increased integration of automated vessels into the maritime transportation system.”

Friday, March 4, 2016

FDA Publishes RFI for Medical Device Refurbishment

Today the Food and Drug Administration (FDA) published a request for information (RFI) notice in the Federal Register (81 FR 11477-11479) to receive information and comments on the medical device industry and healthcare community that refurbish, recondition, rebuild, remarket, remanufacture, service, and repair medical devices.

The RFI


The FDA’s notice explains that:

“Stakeholders have expressed concerns that some third-party entities who refurbish, recondition, rebuild, remarket, remanufacture, service, and repair medical devices may use unqualified personnel to perform service, maintenance, refurbishment, and device alterations on their equipment and that the work performed may not be adequately documented. Possible public health issues arising from these activities include ineffective recalls, disabled device safety features, and improper or unexpected device operation. OEMs have also requested clarification of their responsibilities when their devices have been altered by a third-party entity. Federal Agencies other than FDA address service and maintenance activities as well.”

The notice provides descriptive definitions of the activities of interest in this RFI. Those activities are:

Servicing;
Repairing;
Remanufacturing; and


The FDA is soliciting comments on concerning the service, maintenance, refurbishment, and alteration of medical devices, including endoscopes (Ref. 3), by third-party entities. They are specifically looking for responses to the following questions:

• Who are the different stakeholders involved with the medical device activities listed previously?
• What evidence exists regarding actual problems with the safety and/or performance of devices that result from these activities?
• What are the potential risks (patients/users) and failure modes (devices) introduced as a result of performing the previously defined activities on medical devices?
• Are the risks different depending on who performs the previously mentioned activities?
• Which of these activities are more difficult or riskier to perform on certain devices versus others?
• What information do third-party entities need in order to perform these activities in a way that results in safe and effective operation of the medical device?
• What additional challenges do stakeholders encounter with devices that result from these activities?

The FDA is soliciting public feedback on these questions. Responses can be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # FDA-2016-N-0436). Comments should be submitted by May 3rd, 2016.

Commentary


As more and more of these devices contain electronic control systems and data storage systems the issue of cybersecurity must be included in any discussion of refurbishment of medical devices. Some of the types of cybersecurity issues that will need to be looked at will include:

• Verification that there has not been has not been tampering with any firmware/software loaded on the device;
• Verification that any manufacturer updates to firmware/software have successfully been applied;
• Verification that any additional communications protocols associated with the device are up to date; and
• Where the device must be hooked to a personal computer (PC) similar questions about the software on the PC must be addressed;

Additionally, before the device is sent to a third party, or even the original vendor, for refurbishment, specific procedures are going to have to be established to ensure that all patient information is permanently removed from the device.


Since the FDA is planning on holding meetings on the medical device refurbishment issue, perhaps is should consider holding a meeting to specifically look at the related cybersecurity issues.

A copy of this post was submitted to the FDA Docket on March 6th, 2015.

Saturday, February 27, 2016

Responses to Latest CSF RFI – 02-27-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period was extended until February 23rd, 2016. The previous posts in this series include:


This week there were 47 new responses (almost as many as had been posted in total by last week) to the RFI and all but one of them were dated after February 9th, the original comment cut-off date and one was dated after the new cut-off date. Obviously it was a smart move on the part of NIST to extend the comment period. As I noted last week, I expect that there will probably be one more of these posts to catch any additional late adds to the response list.

The comments posted this week come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

One commenter suggested that federal regulators map their cybersecurity regulations to the CSF as the CSF is mapped to various standards. Another commenter suggested instead that NIST conduct such regulatory mapping. Regulatory mapping was addressed by a number (6) of additional commenters.

One commenter noted that the effect of IoT on the CSF should be looked at. Another commenter suggested that there should be more emphasis on acquisition and supply chain issues.

One commenter suggested that regulators use CSF reporting as their regulatory methodology.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

A number of commenters (1) recommended that the CSF should continue to be updated as existing standards are updated and new standards are published.

One commenter noted that the CSF should be expanded to include cyber threats, insider threats and physical threats. Another commenter suggested that the CSF should involve more detail about technological concepts that effect implementation. Yet another suggested that the CSF should include more detail on creating a target profile. And another suggested more emphasis on state-of-the-art risk management practices. And another requested that the CSF be expanded to include product integrity and supply chain security. Another commenter suggested that medical device and industrial control systems need coverage in the CSF. Big-data and cloud privacy issues were suggested by another commenter as areas that need to be addressed.

One commenter suggested that CSF stability should be a primary concern. Another commented that reducing the frequency of updates would be helpful.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

A number of commenters (7) noted that the private sector should continue to provide input on CSF improvements. One commenter specifically recommended continued use of RFI’s and regional workshops.

One commenter argued that the users of the framework should provide the governance. Another commenter suggested that the private sector should provide feed-back on implementation issues.

One commenter suggested that NIST should hold semi-annual workshops to address potential changes to the CSF.

Commentary

A total of 100 responses have been posted to the NIST site as of today. Fewer than half of the commenters used the either the spread-sheet format requested by NIST or keyed their responses to specific questions posed in the RFI. I really wish that the commenters that did not have the common decency to take the effort to consider how NIST was hoping to use their responses would sit down and read the 100 responses submitted to date and try to make sense of the data presented.

I am sure that a great deal of effort went into developing these 10 and 20 page responses that went into great detail about how the organization was diligently working on cybersecurity. Unfortunately, those comments were better suited to a press release than being helpful to NIST in charting the future of the CSF.

Over the last two weekends I have spent four hours reviewing responses to look for and analyze information on just three of the twenty questions. And I did not even attempt to read the responses that were not prominently keyed to the specific questions I was looking at. NIST on the other hand is going to have to peruse each of the missives to try to extract the requested information. I do not envy the NIST reviewers who will be required to review each and every submission, no matter how verbose and self-advertising.

It was interesting that out of 47 submissions posted this week, only one mentioned the fact that the CSF needs to be periodically updated to reflect revisions to the various standards referenced in the document. In the long run, I think that it was probably more important that a number of commenters noted that there should be a mapping of CSF and cybersecurity regulations. Comments went both ways; suggesting that regulations reference CSF and vice versa.

Nobody has suggested that new cybersecurity regulations have to be applied; instead they are recommending that regulated industries that are already facing security regulations have the cybersecurity provisions tied into the CSF. That way, commenters suggest, there would not be competing requirements, especially for those organizations facing multiple regulatory schemes.

I was happy to see a number of cybersecurity research organizations included in the responders this week. They had some different insights from those provided by industry organizations.


Saturday, February 20, 2016

Responses to Latest CSF RFI – 02-20-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period was extended and will remain open until February 23rd, 2016. The previous posts in this series include:



This week there were 37 new responses to the RFI and most of them were dated on or before February 9th, the original comment cut-off date. This lag has been fairly normal for the NIST RFI’s and is certainly due to the fact that they have to hand process these comments from emails. If NIST stays in the comment reception process they really need to come up with an automated system for receiving/posting the comments.

Since the new comment deadline is this week I expect that I will be doing these posts for at least two more weekends.

The comments posted this week come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

A couple of commenters recommended that the CSF continue to be voluntary in response to this question.

One commenter noted that DOD, DHS and NSA are developing separate voluntary and mandatory guidelines and approaches which makes compliance more difficult. Another commenter suggested that the CSF be used to harmonize cybersecurity regulatory development. It was suggested by yet another commenter that policy makers should collaborate with federal agencies and the private sector to prevent duplication of regulatory processes and prevent conflict with superseding of regulatory requirements. One health care commenter called for more alignment within the federal government in applying risk management principles. Another commenter suggested that regulators use CSF reporting frameworks as part of their regulatory scheme.

Continued cooperation between standards setting organizations was also suggested. One commenter suggested that a public/private sector guidance body be established.

One commenter noted that the voluntary nature of the CSF implementation was beneficial because it allowed an organization to ignore, add or eliminate processes so that the CSF would be more applicable to the organization.

Another commenter noted that NIST should expand its development of CSF profiles for different regulatory regimes or that regulators could reference the CSF in their rules. One commenter noted that Sector Specific Agencies be required to develop CSF implementation guidelines. Another commenter suggested that the CSF be expanded to an international scope. Another commenter suggested that the CSF should be expanded to include more specific measurable/observable criteria to better support regulatory reporting.

One commenter suggested that continued private sector involvement in CSF updates would ensure that the CSF does not conflict with regulatory requirements.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

A number of commenters (8) recommended that the CSF should continue to be updated as existing standards are updated and new standards are published. One commenter noted, however, that updates should be limited to allow for adequate implementation experience to guide future updates; this was reinforced by other commenters.

One commenter specifically recommended that health care organizations take an active role in the update process. Another commenter suggested that outdated measures should be removed. A suggestion was made that NIST and industry should work together to develop industry specific implementation guidelines. Yet another commenter suggested that there should be more public safety input into the CSF development process. It was suggested that the CSF remain technology neutral.

An equipment vendor noted that supply chain security issues need to be addressed in the CSF. Another commenter suggested that the internet of things and bring your own device problems should be addressed in the CSF. Yet another commenter suggested that high level control areas for PKI security be included. A government agency suggested that future updates should reflect all stakeholder needs.

One commenter opposed regular updates to the CSF, noting that continuity was more important in the changing field of cybersecurity.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

A number of commenters (10) noted that the private sector should continue to provide input on CSF improvements.

One commenter noted that the private sector should be providing input to both NIST and standards setting organizations. Another commenter noted that multiple inter-sector dependencies need to be identified. One commenter maintained that private sector involvement leads to a sustainable program. Yet another suggested that the private sector should play a critical role in the CSF governance with another suggesting that the private sector should own the CSF and its governance.

One commenter suggested that private sector input be limited to anonymized input on implementation issues.

Commentary

A total of 53 responses were ultimately received by the end of the original comment period from a broad cross section of responders. This actually ended up being a pretty decent number of responses for this type of non-regulatory request for comments. I was disappointed in the relative lack of responses from security researchers as I know that a number were involved in the original process that led to the publication of the CSF; I expect, however, that they would again get involved in any change process.

Having said that, it should be noted that I did not submit any comments to this RFI. Since the questions were mainly targeted at organizations that had either used the CSF or specifically decided not to use the Framework, I didn’t think that my more philosophical comments would really be appropriate. And that may have been why we saw so few comments from individuals in response to the RFI.

I want to remind folks that the continuing analysis of the responses to the RFI that I have been doing has been limited to those responses that specifically (and clearly) addressed specific questions in the RFI. For the most part I ignored (and suspect that NIST will largely ignore) the more verbose and erudite commentaries on the CSF that were submitted by a large number of the commenters. NIST was looking for specific information and those commenters were not helpful in that regards.

A number of those non-responsive responses were more targeted at the next version of the CSF and may have been more appropriately saved for that process. There was at least one exception to this; the comments submitted by HITRUST both addressed the NIST RFI questions and provided some in depth suggestions for how the next version of the CSF should look. If you are really interested in the future of the CSF I suggest that you take a look at their lengthy commentary; I expect (and hope) that they will be actively involved in the CSF revision process.

Readers of this series of posts will realize that I am a big fan of the NIST attempts to get commenters to use the spread sheet format for submitting responses to the questions that they asked. This makes the compilation and analysis of those comments so much easier. I would like to suggest that NIST continue to work at the development of this process and include the development of a methodology of automating the reception of those spread sheets.


OMB should be actively working with NIST on developing this process of automating the collection and analysis of public comments. This would go a long way to making the regulatory process more effective and reduce the time necessary to complete the regulatory process.

Saturday, February 13, 2016

Responses to Latest CSF RFI – 02-13-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:



This week there were ten new responses to the RFI. This is almost the same as the total number that had been submitted by last Saturday, and they all came before the original deadline. This week’s responses came from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

One commenter recommended that the Federal government should consolidate the Federal cybersecurity effort to avoid having multiple requirements from separate agencies. Similarly, another commenter suggested that if the CSF were to become the regulatory standard, that all agency regulations should be based upon that standard. On the other hand, a separate commenter noted that regulatory requirements should be included in the CSF. Alternatively, another commenter suggested that NIST should have greater outreach to Federal, State and local regulators to aid them in developing consistent regulatory schemes.

One commenter noted that as new industry and international standards are developed they should be incorporated in the CSF. Another commenter suggested that the relationship between the CSF and the NIST Risk Management Framework should be clarified.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

One commenter noted that the CSF should be cautiously updated to reflect changes in evolving cyber technology and the risk landscape. Another commenter suggested that the CSF needs an implementation plan and an assessment tool like DHS’ Cyber Resilience Review tool. Yet another commenter recommended that newer versions of the CSF should focus on critical areas and key mitigation plans like perimeter defense strategies.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

One commenter suggested that while NIST should maintain responsibility for CSF governance, ISACS should become directly involved in CSF changes. Another noted that industry Organizations like CHIME should become involved in the CSF process. One commenter suggested that the NERC CIP process has shown that a period of stability is needed between revisions of the CSF, so that lessons learned can be properly identified and incorporated.

Commentary

While the number of commenters that have provided input during the initial 60-day comment period is staggeringly inadequate, the latest batch has a number of interesting and provocative ideas for NIST to consider.

I would like to point out that the majority of the comments received this week were in the CSF comment submission format. This makes the review of the comments much easier. Commenters need to realize that if their intent is to actually influence the CSF improvement process, then making it easier for the reviewers to understand and collate the responses increases the efficiency of the influence.

There were a couple of commenters that seemed to have confused the management tool that is the Cybersecurity Framework and cybersecurity regulations. The CSF is a tool that can be used to analyze the current state of an organizations cybersecurity practices and to figure out what the organizational goals in the field should be and how to achieve them. Regulatory schemes are designed to set minimum standards, establish compliance measures for those standards and ensure that those compliance standards are met. One would like to think that an organization, while having to meet regulatory requirements, would aspire to a higher standard performance. The CSF provides a tool to establish that higher performance level and outline a means to achieve that goal.

Regulatory agencies could certainly use the CSF as a tool for ensuring that their minimum standards reflect industry standards and capabilities. It also provides the necessary references for finding appropriate measurement tools to gauge the effectiveness of responses to regulatory requirements.


But, the CSF is not a regulatory framework. It was never intended to be such and would lose much of its effectiveness if it became one. Probably the greatest advantage of the CSF verses cybersecurity regulations is that it should be easier to update the Framework to reflect changes in the cybersecurity landscape than it would ever be to update regulations. In large part this is because it’s voluntary nature makes organizations much less resistant to changes in the Framework.

Friday, February 12, 2016

NIST Publishes RFI Comment Extension Notice

As I mentioned earlier this week, today the National Institute of Standards and Technology published a notice in the Federal Register (81 FR 7506) announcing the extension of the comment period on their request for information (RFI) on updating the Cybersecurity Framework. The comment period is extended until February 23rd, 2016.

It does not appear that there were any specific requests for extension of the comment period. The notice only mentions that the comment period coincides with “a timeframe in which a variety of cybersecurity events are scheduled to occur”. While a number of cybersecurity professionals do attend many of these events, I really doubt that that is the reason for the very poor comment rate that we have seen to date.


I would like to mention again that NIST has adopted the use of a spread sheet format for submission of comments. Since I also do my own personal reviews of these comments (as my readers are certainly aware) I can attest to the fact that it is much easier to compile comments from this spread sheet format. If you have to include a long expository comment showing your erudition and mastery of the subject matter, please at least take the time to put a brief answer to the questions into the NIST response form. I know that I will only give a cursory scan to your exposition and concentrate on the concise answers in the form.

Tuesday, February 9, 2016

CSF RFI Comment Deadline Extended

I just got a form type email from NIST announcing that they are extending the comment period on their latest Cybersecurity Framework (CSF) request for information (RFI) until February 23rd. The original deadline had been today.

As I have been mentioning in my weekly updates on the comments received, there has been a particularly inadequate response to the RFI. I’m assuming that that is at least part of the reason for the comment extension. I would also assume that NIST had specifically received requests for an extension, probably citing the Christmas holidays as a reason for the low response rate.


According to the email, NIST will be publishing a notice in Friday’s Federal Register officially announcing the extension of the comment deadline.

Saturday, February 6, 2016

Responses to Latest CSF RFI – 02-06-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:


This week there were five new responses to the RFI. This is the largest number of responses in a single week, but it is still a remarkably small number of responses. This is even more concerning because the comment period ends on Tuesday. This week’s responses came from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Only three of the responders addressed this question in their response. One recommended that the CSF continue to be a voluntary program until such time that there was an industry wide consensus that the Framework should be adopted. Another commenter suggested that various cybersecurity regulatory standards be included in the reference standards. The final commenter on this questions suggested that a cross-functional group (including representatives from industry and standards organizations) be formed to establish a CSF change control process

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

The same three commenters also addressed this question. One suggested that change for change sake should be carefully avoided. A second recommended that the next update should address risk management decisions and prioritization processes in more detail. The other responded that updates should be responsive to industry feedback.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Again comments on this question were only receive from the same commenters that responded to questions 9 and 10. One expressed support for continuing NIST control of the CSF process with advice from industry. Another suggested that industry support should be specifically restricted to an advisory role to avoid conflict of interests. The third commenter suggested that NIST continue with using the RFI process and holding open public meetings and workshops when updating the CSF.

Commentary

Only two of this week’s commenters used the NIST spreadsheet for submitting comments. The third that responded to specific questions used a standard WORD® format with responses specifically keyed to the RFI questions. The remaining two commenters used the old-style letter format that pressed their organizational agenda rather than specifically respond to the RFI questions.

I suspect that that out-of-date response style means that what may have been legitimate and perhaps useful concerns will likely be given little consideration in moving the CSF update process forward. NIST has established a history of moving forward quickly in response to RFIs and that can only happen when specific responses are given to specific questions.


I really hope that there will be a much larger number of responses received in this last week of the response process. If we continue with the same level of response it is hard to imagine that NIST will be able to continue forward with a rigorous update process for the CSF.

Saturday, January 30, 2016

Responses to Latest CSF RFI – 01-30-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:



As of this morning there are only one new response posted to the RFI Response site. They come from:

Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Emblem Health suggested using the CSF as the basis of any regulation noting: “If a minimum standard could be adopted that would allow health care companies to have a target that if reached would provide some guidance to the C-suite that the IT department had achieved the proper security level.”

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

Emblem Health responded that: “The framework should be continuously reviewed and updated.”

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Emblem Health suggested participation in a ‘governing committee’ would be an appropriate for private sector organizations to be involved in the future governance of the Framework.

Commentary

This week’s response was submitted using the NIST template and Emblem Health responded to nearly every question asked by NIST. The responses were short and to the point. It would be helpful to NIST if all responses were similarly prepared and targeted.


With less than two weeks left in the comment period, it is very disappointing to see only seven comments submitted to date. Hopefully we will begin seeing responses from corporate America next week.

Saturday, January 23, 2016

Responses to Latest CSF RFI – 01-23-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:



As of this morning there are only one new response posted to the RFI Response site. They come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Danilo noted that existing duplications and inconsistent policies across agencies resulted from “lack of collaboration and coordination across agencies”. This could be prevented by continuing NIST process.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

Not addressed in this response.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Not addressed by this commenter.

Commentary

The response today continues the unresponsive nature of the contributions to date. While the comments certainly have merit, they continue to ignore the basic questions posed by NIST in regards to future actions to improve the CSF.


With just a little over two weeks left in the comment period, it is very disappointing to see only six comments submitted to date. Hopefully we will begin seeing responses from corporate America next week.

Saturday, January 16, 2016

Responses to Latest CSF RFI – 01-16-16

This is part of an on-going look at the responses to the National Institute of Standards and Technology (NIST) latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016. The previous posts in this series include:


As of this morning there are only two new responses posted to the RFI Response site. They come from:


Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Not addressed by either commenter.

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

One of the commenters noted that the use of the CSF should be expanded to all small and medium businesses, even those not specifically considered ‘critical infrastructure’.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

Not addressed by either commenter.

Commentary


Both responses posted today were remarkably non-contributory to the intended discussion. With the comment period over half-way completed the number of responses has been underwhelming to say the least, but that is fairly typical of the response process. The response rate should increase significantly as the deadline approaches. It takes time for organizations to develop their official responses.

Saturday, January 9, 2016

Responses to Latest CSF RFI – 01-09-16

Almost a month has gone by and we are just now seeing the National Institute of Standards and Technology (NIST) posting comments to their latest request for information (RFI) on potential updates to the Cybersecurity Framework (CSF). A reminder, the comment period will remain open until February 9th, 2016.

As of this morning there are only three responses posted to the RFI Response site. They come from:


Comment Format

Before looking at the actual responses, I would first like to take a look at the reason that NIST has suggested that the comments to the RFI should be submitted using the provided spread sheet submission form on the RFI web site. This is a technique that NIST established in their earlier RFI submissions.

If you look at the three submissions available today, only one of them uses the spread sheet. In the first submission it is very hard to actually find the comments from Mr. Marks as he has appended them directly to the questions with no visual separation. The submission from Cybernance uses a similar format, but provides visual separation which makes the responses easy to identify and read. Finally, the Esterline submission uses the NIST spread sheet which not only makes it easy to identify and read the response, but it makes it easier for NIST to abstract the comments to a review/response database.

The whole point of responding to a request for information like this is to have one’s voice heard in the most effective manner possible. NIST has come up with a technique that makes this easier for them to evaluate the responses, and at the same time is relatively easy for the responding community to use. Not only do I think that the public should use this particular response form for replies to this RFI, but other agencies should consider employing the same technique when soliciting public comments on RFI’s and rulemakings.

Prevent Duplication of Regulatory Processes

NIST question 9 asks:

“What steps should be taken to “prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and related processes” as required by the Cybersecurity Enhancement Act of 2014?”

Only one commenter addressed this question with a fairly succinct: “Form a single body for the US gov't that has a singular standard system.”

Should CSF be Updated?

NIST question 10 asks:

“Should the Framework be updated?”

All three commenters generally agreed that the CSF should be updated regularly. One commenter suggested improving ability to access the referenced controls. Another suggested upgrading the ‘Profile’ section to aid charting a path forward to improving cybersecurity. The third suggested that the CSF should better reflect differences in response based upon organization size.

Private Sector Involvement

NIST question 20 asks:

“What should be the private sector’s involvement in the future governance of the Framework?”

All three commenters strongly supported continued involvement of the private sector. One noted that in particular organizations like the FS-ISAC (presumably including all information sharing and analysis centers) should be involved.


 
/* Use this with templates/template-twocol.html */