Resources
Resources
- Details
- Written by: Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
Are women uniquely qualified to answer "why?" and "do I have to?"
Maybe so.
Yes, because it's the law.
- Hits: 406
- Details
- Written by: Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
As quickly as I save this it will be out of date, but it's here to make an important point. Most people think they can "do NIST" by downloading the SP 800-53 r5 and using it like an ingredients list. They are very wrong. The process to earn Government Certifications is arduous and complex. There are distinct roles in who and how you prepare for attaining authority to operate, ATO. Even this table, which is embedded in several templates includes out-of-date references. For example, NIST SP 800-54 r4 is obsolete and no typo is going to change that. The SP 800-53A released a substantial new version this week. Many people confuse the NIST SP 800-53A R5 is here with the 800-53B and so will likely miss this positively critical new resource.
- Hits: 536
- Details
- Written by: Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
This is entirely quoted and verbatim except for the AMERICAN spelling.
"...In November 2021 the NCSC announced an overhaul of the Cyber Essentials technical controls and a change to the pricing structure. Both these changes come into effect on 24 January 2022. (NOTICE - if we provided you with mapping, it's time for an update AND you will have to provide evidence of your license.)
Updating the technical controls
- Hits: 767
Read more: National Cyber Security Center NCSC UK Announces...
- Details
- Written by: Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
Please, Just Tell Me What to Do
Building Cloud Products for Federal Agencies – Using NIST to Shift Compliance Left
Vendors and Consultants working with Federal Agencies are required to establish secure products and services as tagged to their associated commonly defined security controls (outcomes) and do so using a Cybersecurity Framework mapped to address common cybersecurity-related responsibilities. The most common set of categorized outcomes (a.k.a. Control Families or Control Objectives) is the security controls in NIST SP 800-53 Rev. 5[i], Security and Privacy Controls for Federal Information Systems and Organizations.
- Hits: 5352
- Details
- Written by: NIST
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
NIST PRIVACY FRAMEWORK: A TOOL FOR IMPROVING PRIVACY THROUGH ENTERPRISE RISK MANAGEMENT, VERSION 1.0 - January 16, 2020
Download NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management, Version 1.0 and csf-pf-to-sp800-53r5-mappings.xlsx (live.com)
- Hits: 1600
- Details
- Written by: The CIS Critical Security Controls
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
The CIS Critical Security Controls (CIS Controls) are a prioritized set of Safeguards to mitigate the most prevalent cyber-attacks against systems and networks. They are mapped to and referenced by multiple legal, regulatory, and policy frameworks. CIS Controls v8 has been enhanced to keep up with modern systems and software. The movement to cloud-based computing, virtualization, mobility, outsourcing, Work-from-Home, and changing attacker tactics prompted the update and supports an enterprise's security as they move to both fully cloud and hybrid environments.
- Hits: 811
- Details
- Written by: NIST
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
Improving the Nation's Cybersecurity: NIST’s Responsibilities under the May 2021 Executive Order
Overview:
The President’s Executive Order (EO) on “Improving the Nation’s Cybersecurity (14028)” issued on May 12, 2021, charges multiple agencies – including NIST– with enhancing cybersecurity through a variety of initiatives related to the security and integrity of the software supply chain. The following is from NIST. Cybersecurity professionals need to spend considerable time understanding our resources as provided by NIST, by CISA Executive Order on Improving the Nation’s Cybersecurity | CISA, by Cloud Security Alliance, and by Center for Internet Security CIS Critical Security Controls Version 8 (cisecurity.org). We must understand our audience, the products they consume and design, and meet our obligations as US-certified cyber professionals and regulators. The war is digital. We are this country's defense.
- Hits: 1600
- Details
- Written by: Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
The Cybersecurity Framework - Version 1.1, released 2019
Cybersecurity Framework History
- February 2013 - Executive Order 13636: Improving Critical Infrastructure Cybersecurity
- December 2014 - Cybersecurity Enhancement Act of 2014 (P.L. 113-274)
- May 2017 - Executive Order 13800: Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure
Learn more at CSRC Topics - Cybersecurity Enhancement Act | CSRC (nist.gov)
- Hits: 1336
- Secure Host Baselines & Common Security Framework CSF
- Data Centric Security tackles GDPR, CCPA & DLP
- NERC CIP
- ENISA Publications
- FIPS 199 - Security Categorization
- FIPS PUB 200 Minimum Security Requirements
- Justice Kentaji Brown Jackson
- Extract - The Security Hippie
- Surviving the Storm - Actors, Writers, Directors
- Tweets
