CHALLENGE - NIST Cybersecurity Framework for Improving Critical Infrastructure

Order 13636 requires accountability to assure cyber-security readiness, requiring Financial, Communications, Manufacturing, Defense, Energy, Emergency Services, Food and Agriculture, Healthcare, IT, Utilities, Chemical, Water, Nuclear Reactors, Materials, & Waste and Transportation sectors to initiate voluntary compliance with the NIST Cybersecurity Framework.

CSFsystempolicy2framwork

Get Cyber Ready

  • Know the critical assets and who’s responsible for them
  • Get everyone involved in cyber-resilience
  • Be prepared for an attack
  • Prevent cyber-attack from throwing your organization into complete chaos.
  • Businesses must understand their environment from the perspective of an adversary.
  • Expectation to use threat modeling and ask “Who is the adversary and what does the adversary want to accomplish?”

Cyber threat analysis, reducing the attack surface requires understanding

  • Methods attackers use to touch or exploit vulnerabilities
  • That an attack surface represents every interface an enemy could exploit to their own malicious intent
  • FIPS 200 Minimum Security Requirements for Federal Information and Information Systems, and
  • FIPS 199 Standards for Security Categorization of Federal Information and Information Systems

 NIST Cybersecurity Framework (CSF)

Main Menu