Update Released for NIST Cybersecurity Framework

The First Update in a Decade

An Article Review

With its first major update since 2014, the NIST Cybersecurity Framework 2.0 aims to expand its scope.

A decade can be a long time in any industry, and when it comes to cybersecurity that’s especially true. Each passing year seems to bring with it new threats and changes to the tools that we use to try and combat those threats.

When it comes to our regulatory agencies and their guidance though, things can move just a little bit slower. Such is the case with the National Institute of Standards and Technology (NIST) and their Cybersecurity Framework (CSF), which has recently received its first major update in ten years. With many other organizations basing their guidance in whole or in part on the NIST CSF this new framework is certainly worth paying attention to, so just what has changed?

Some of the larger changes start at the top, literally: NIST has added Governance to its list of cybersecurity pillars, stressing the importance of participation from the Board of Directors and other executive-level positions in cybersecurity decisions. In addition to this new core functionality, the framework’s target audience has been expanded from those critical to the nation’s economy and defense to include all organizations. Continuing the theme of expanded scope greater focus is now placed on third-party vendors and supply chain management, recognizing the increasing reliance being placed on cloud processing and storage since the original CSF was published in 2014.

This new framework will also have an impact on the tools and regulatory guidance issued by other organizations, including the FFIEC and its Cybersecurity Assessment Tool, which could see its own overhaul as soon as next year.

Original article by Robert Lemos writing for DarkReading

This Article Review was written by Vigilize.


Matt Jolley is the current Vigilize, he is also the recipient of the 2023 Cyb3rP0e+ designation!

To see more content like this in your inbox, sign up for our newsletter here!

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts

The Magnificent Seven 2023

Seven Trends . . . …that small bank Information Security Officers face in 2023 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcome t...

“Lock It” – Awareness Poster

Another awareness poster for YOUR customers (and users). Now that we have our own employees aware, maybe it’s time to start posting content for our customers!Check out posters.infotex.com for th...