America's standards institute upgraded its already-good template?
The US National Institute of Standards and Technology (NIST) has released the second version of its framework — the one designed to help companies stay safe from cyberattacks.
The US National Institute of Standards and Technology (NIST) has released the second version of its framework — the one designed to help companies stay safe from cyberattacks. This version is more flexible and should be more accessible to companies of any size.
What does this framework cover?
It covers 5 functions: identify, protect, detect, respond, and recover. Each function covers a potential threat and how to deal with it.
Identify
To protect something, I have to know I have it. So it's important to identify what needs to be secured and how. Even though everything should be secure in principle, your personal Candy Crush account doesn't need the same level of protection as your company's bank account.
Protect
This covers all protective and preventive systems, like firewalls, network-scanning tools, encryption, password managers, etc.
Detect
The earlier you find out you've been hit, the earlier you can actively defend. This function focuses on damage mitigation by detecting the threat as fast as possible — whether through a report from one of your employees or a system scanning the network.
Respond
Closely related to the previous step — how do you react when you're under attack? It should include a so-called worst-case plan, with the steps to take after an attack written down.
Recover
You stopped the attack, but some things were still compromised? Here comes the recovery step — pulling the backups, bringing every downed system back up, and resetting passwords.
What's new in this framework
The whole framework was lightly edited, but the main change was the addition of profiles and tiers, which allow you to specialize the framework for your company. Profiles focus on shaping cybersecurity around the company's needs and capabilities; tiers focus on how the company itself sees its risks and how to most effectively reduce them.