Managing the Risk

NIST Interagency/Internal Report (NISTIR-8170) Approaches for Federal Agencies to Use the Cybersecurity Framework [v] provides steps for implementing the Framework for Improving Critical Infrastructure Cybersecurity (known as the Cybersecurity Framework, CSF). This methodology uses various NIST security and privacy risk management standards, guidelines, and practices. Most NIST Special Publications are partially derived from FIPS 200 [vi] and the moderate security control baseline in SP 800-53B [vii]. This means there are sets of controls that act as an index or matrix to implement other dynamically required standards. The entire catalog of all controls is currently the NIST SP 800-53.

“Cybersecurity Framework Profiles enable agencies to reconcile mission objectives and cybersecurity requirements into the structure of the Cybersecurity Framework Core. This readily translates to the SP 800-53 controls that are most meaningful to the organization. Profiles can be used to tailor initial SP 800-53 baselines into final baselines, as deployed in the RMF Implementation step. Typical Participants: Information Owner/Steward, Information System Owner, Information Security Architect, Information System Security Engineer, stakeholders representing other risk management disciplines (e.g., finance, human resources, acquisition) Primary NIST Documents: NIST Special Publication 800-53, Cybersecurity Framework” [viii]

Even for Product and Service organizations with a formal Federal Procurement function, navigating the selection of the correct NIST standards and meeting all necessary assessment criteria is a formidable task. There are more than 450 Agencies[ix] of the US Federal Government, and just one of their many assignments is the development and implementation of their own industry’s process and technology-specific standards. Each agency is responsible for a program of conformity assessment. [x]

A key Federal Government Agency responsible for Conformance is the Joint Authorization Board (JAB). [xi] The JAB oversees The Federal Risk and Authorization Management Program (FedRAMP), providing a risk-based approach for adopting and using cloud services. FedRAMP empowers agencies to use modern cloud technologies, emphasizing security and protection of federal information. Another important conformity Agency is the Defense Federal Acquisition Regulation Supplement (DFARS) administered by the Department of Defense (DoD). In conjunction with oversight to legal and DoD-wide policy requirements, entities operating with this agency must implement NIST SP 800-171 Rev. 2, and NIST SP 800-172Enhanced Security Requirements for Protecting Controlled Unclassified Information. DFARS compliance is recorded via SPRS using NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information. In short, DFARS Rule 2019-D041 means that US Federal Agencies cannot award your contract unless you’ve met with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology and have validated that assessment either by a Self-Reported, Supplier Performance Risk System (SPRS) score, or, as certified by a DoD accredited assessor (third party) using the prescribed Cybersecurity Maturity Model Certification (CMMC) Framework. [xii]

Both DFARS and FedRAMP assessments rely on control families located in NIST SP 800-53 Rev 5.1 and SP 800-53B and the NIST SP 800-171, which is derived from the 800-53.[xiii] FedRamp Authorization [xiv] and the DFARS Supplement [xv] Supplier Performance Risk System (SPRS) leverage a catalog of controls intended to provide consumers and providers with context-specific technical guidance as necessary to mitigate risk. Both NIST standards (800-53 and 800-171) require the reporting organization to provide evidence of their System Security Plans as maintained by their Plans of Action & Milestones (POA&Ms). Assessments diverge relative to their risk, which is reflected in the scope and depth of their assessment requirements. For example, FedRamp is concerned with information stored in Federal Systems, and DFARS is concerned with protecting controlled unclassified information (CUI). They also differ in their reliance on an authorized third-party assessor and their allowance for self-reported v. third-party DoD assessed and scored criteria. Each has distinct rules for revealing and reporting exceptions, for remediation prior to authorization, and the manner of monitoring agreements to resolve issues within a period following the review. (For more detail see Compliance with Cybersecurity and Privacy Laws and Regulations | NIST. [xvi]

While mandatory NIST compliance among United States Federal Agencies and their Contractors has been enforced by DFARS since 2017, and FedRamp since 2011, stringent requirements for independently gathered evidence of controls and third-party assurance amped up in 2021. Changes in Federal Law now require relevant NIST Standards to apply across the entirety of the Federal Agency Supply Chain. [xvii] 

Main Menu