
What are the best tools and resources? (THIS IS DATED - written in 2016. If you've got tools you'd like featured in this article, reach out to
- Turn in your business email to get links and downloads
- CSF provides a cyber security model
- Use: NIST Framework for Improving Critical Infrastructure Cybersecurity; Annex A
- Determine Alignment to ISMS and NIST 800-53 or CCM or any standard ITGCC program
- Download NIST Assessment Tool http://www.nist.gov/cyberframework/csf_reference_tool.cfm
- Cyber Security Evaluation Tool
- Download and install CSET https://www.us-cert.gov/forms/csetiso
- HITRUST CSF 9.3 Resources – registration required
- Offers manual mapping of controls for implementation of controls assessment of HITECH / HIPAA security and privacy rule using multiple frameworks and standards https://hitrustalliance.net/hitrust-csf/https://hitrustalliance.net/hitrust-csf/
Other Cyber Security Must Reads
- International Organization for Standardization, Risk management – Principles and guidelines, ISO 31000:2009, 2009. http://www.iso.org/iso/home/standards/iso31000.htm
- International Organization for Standardization/International Electrotechnical Commission, Information technology – Security techniques – Information security risk management, ISO/IEC 27005:2011, 2011. http://www.iso.org/iso/catalogue_detail?csnumber=56742
- Joint Task Force Transformation Initiative, Managing Information Security Risk: Organization, Mission, and Information System View, NIST Special Publication 800-39, March 2011. http://csrc.nist.gov/publications/nistpubs/800-39/SP800-39-final.pdf
- U.S. Department of Energy, Electricity Subsector Cybersecurity Risk Management Process, DOE/OE-0003, May 2012. http://energy.gov/sites/prod/files/Cybersecurity%20Risk%20Management%20Process%20Guideline%20%20Final%20-%20May%202012.pdf
CSF Process requires analysis of attack surface (read more at Secure Host Baselines & Common Security Framework CSF)
All of these industries require asset-level cyber security
All industries expect us to provide:
- Board reports
- Boss reports
- Boss’s boss reports
- Decision support systems
- Security roadmap
- Enable business
- Drive IT Value
As an industry, our sensory system is overwhelmed
We need a fabric
What creates the threads that we can assert?
Ten normative references that totally rock the compliance world
- Benchmark contains both descriptive information and structural information
- Group item that can hold other items
- Item three types of items: <xccdf:Group>, <xccdf:Rule> and <xccdf:Value>
- Model suggested scoring model for an <xccdf:Benchmark>
- Profile element is a named tailoring for an <xccdf:Benchmark>
- Rule the description for a single item of guidance or constraint. <xccdf:Rule> elements form the basis for testing a target platform for benchmark compliance
- Status acceptance status of an element with an optional date attribute, which signifies the date of the status change
- Tailoring element holds one or more <xccdf:Profile> elements-records additional benchmark tailoring
- TestResult element encapsulates the results of a single application of an <xccdf:Benchmark> to a single target platform
- Value a named parameter that can be substituted into properties of other elements within the <xccdf:Benchmark>
KEY IT Security and Risk resources
- SANS Top 20 Critical Security Controls V8. https://www.sans.org/critical-security-controls/
- NIST Framework for Improving Critical Infrastructure Cybersecurity, V1.1. http://www.nist.gov/cyberframework/
- NIST 800-53 V5. Security and Privacy Controls for Federal Information Systems and Organizations (Right)
- DISA Secure Technical Implementation Guides. Complete STIG List (stigviewer.com) *This is managed by UCF
- ISO/IEC 27002:2013. Information Technology - Security techniques - Code of practice for information security controls. http://www.iso.org/iso/catalogue_detail?csnumber=54533
- COBIT V5. ISACA. http://www.isaca.org/cobit/pages/default.aspx (Visit Cobit at ISACA. It's up to version 19!)
- Payment Card Industry Data Security Standard V3.2.1 Official PCI Security Standards Council Site - Verify PCI Compliance, Download Data Security and Credit Card Security Standards

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics