The Cybersecurity Framework - Version 1.1, released 2019

Cybersecurity Framework History

Learn more at CSRC Topics - Cybersecurity Enhancement Act | CSRC (nist.gov)

The Cybersecurity Framework, Revision 1.1 is most recognized for its simple model, and the ease with which executives and nonfederal cloud providers have been able to grasp and implement its core functions:

Three Primary Components

  1. Core - Desired cybersecurity outcomes organized in a hierarchy and aligned to more detailed guidance and controls
  2. Profiles - Alignment of an organization’s requirements and objectives, risk appetite, and resources using the desired outcomes of the Framework Core
  3. Implementation Tiers - A qualitative measure of organizational cybersecurity risk management practices

CSF Domains

As with NIST SP 800-53 rev 5, the framework is outcome-based and designed to connect many interoperable frameworks and standards.

There are 5 Functions (as compared to 20 in the 800-53), 23 Categories (as compared to 110 in 800-171, or 298 in 800-53) and leverages 6 Informative References (whereas the 800-53 has over 400).

It's smaller, easier to implement, lighter, and broadly implemented by nonfederal cloud providers.

Key Framework Attributes

Principles of Current and Future Versions of the Framework

  • Common and accessible language
  • Adaptable to many technologies, lifecycle phases, sectors, and uses
  • Risk-based
  • Based on international standards
  • Living document
  • Guided by many perspectives – private sector, academia, public sector

CSF Content

Implementation Tiers

CSF Implementation Tiers

Framework Updates

  • Applicability for all system lifecycle phases
  • Enhanced guidance for managing cybersecurity within supply chains and for buying decisions
  • New guidance for self-assessment
  • Better accounts for Authorization, Authentication, and Identity Proofing
  • Incorporates emerging vulnerability information (a.k.a., Coordinated Vulnerability Disclosure)
  • Administratively updates the Informative References

NIST provides continuous crosswalks that facilitate the mapping of the CSF. EnterpriseGRC Solutions participates with the Cloud Security Alliance to lead mapping between the CCM v4 and CSF v1.1. We also map the CSF to around 5 thousand CIS and DISA STIG Benchmark Rules. The CSF has known a great many success stories. Why not read a few - https://www.nist.gov/cyberframework/success-stories 

Mapping CSF

 

CSF System Policy Framework

A critical resource that connects to the Cybersecurity Framework is the CIS-CSC 8.1 Standard. Read More CIS Critical Security Controls Version 8

Main Menu