Resources
Resources
- Details
- Written by: NIST
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
Improving the Nation's Cybersecurity: NIST’s Responsibilities under the May 2021 Executive Order
Overview:
The President’s Executive Order (EO) on “Improving the Nation’s Cybersecurity (14028)” issued on May 12, 2021, charges multiple agencies – including NIST– with enhancing cybersecurity through a variety of initiatives related to the security and integrity of the software supply chain. The following is from NIST. Cybersecurity professionals need to spend considerable time understanding our resources as provided by NIST, by CISA Executive Order on Improving the Nation’s Cybersecurity | CISA, by Cloud Security Alliance, and by Center for Internet Security CIS Critical Security Controls Version 8 (cisecurity.org). We must understand our audience, the products they consume and design, and meet our obligations as US-certified cyber professionals and regulators. The war is digital. We are this country's defense.
- Hits: 1607
- Details
- Written by: Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
The Cybersecurity Framework - Version 1.1, released 2019
Cybersecurity Framework History
- February 2013 - Executive Order 13636: Improving Critical Infrastructure Cybersecurity
- December 2014 - Cybersecurity Enhancement Act of 2014 (P.L. 113-274)
- May 2017 - Executive Order 13800: Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure
Learn more at CSRC Topics - Cybersecurity Enhancement Act | CSRC (nist.gov)
- Hits: 1337
- Details
- Written by: Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
HIPAA – HITECH, Aligning Secure Host Baselines According to Common Security Framework CSF
- Hits: 2311
- Details
- Written by: Robin Basham and SECLORE
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
Europe Responds with GDPR - General Data Protection Regulation
The new General Data Protection Regulation 2016/679 ("GDPR" or the "Regulation") is about protecting people and their privacy. Replacing Directive 95/46/EC (aka EU Data Privacy) seven distinct principles now apply to all citizens under the European Convention; however, it is equally relevant to any US or other foreign national who wishes to do business with most of Europe and Australia. (Yes, this is pre-Brexit, but it's all still true. For the UK, read the UK Cyber Essential in Brief).
- Hits: 948
- Details
- Written by: NERC
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) – Standards for planning, operating, and securing North America’s Bulk Power System. Protects “Critical Cyber Assets”
- Hits: 1582
- Details
- Written by: ENISA
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
http://www.enisa.europa.eu/publications
http://www.enisa.europa.eu/publications
- Hits: 485
- Details
- Written by: NIST adapted by Robin Basham
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
FIPS PUB 199 is an impact assessment model used by DFARS 252.204-7012, as mentioned in NIST 171 DFARS and CMMC.
Here is the entire FIPS PUB 199
Required by Federal Information Security Management Act of 2002 (FISMA) all subcontractors and prime contract agencies working with the Federal Government must complete a FIPS PUB 199 assessment, designed to recognize “the importance of information security to the economic and national security interests of the United States.”
- Hits: 1401
- Details
- Written by: The National Institute of Standards and Technology (NIST)
- Parent Category: Resources
- Category: Regulatory Compliance Standards and Frameworks
Any discussion about the works delivered by NIST is at best, a summary to help our readers connect necessary frameworks and encourage them to know "they can do it". The writers at NIST get ALL OF THE CREDIT. FIPS 200, Minimum Security Requirements for Federal Information and Information Systems (nist.gov)
- Hits: 642
- Justice Kentaji Brown Jackson
- Extract - The Security Hippie
- Surviving the Storm - Actors, Writers, Directors
- Tweets
- It Can Get Done
- Tonight We Write and other routine inspirations from Dr. Carlotta Berry
- Inspiration with friends at night
- Helene Silver - The Artist
- Helene Silver - The Artist Gallery Three
- Helene Silver - The Artist Gallery Two
