ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

NIST Is Updating Its Cybersecurity Framework

lowResearchimportance 30
Full article184 words · extracted from schneier.com · click to collapse

NIST is planning a significant update of its Cybersecurity Framework. At this point, it’s asking for feedback and comments to its concept paper.

  1. Do the proposed changes reflect the current cybersecurity landscape (standards, risks, and technologies)?
  2. Are the proposed changes sufficient and appropriate? Are there other elements that should be considered under each area?
  3. Do the proposed changes support different use cases in various sectors, types, and sizes of organizations (and with varied capabilities, resources, and technologies)?
  4. Are there additional changes not covered here that should be considered?
  5. For those using CSF 1.1, would the proposed changes affect continued adoption of the Framework, and how so?
  6. For those not using the Framework, would the proposed changes affect the potential use of the Framework?

The NIST Cybersecurity Framework has turned out to be an excellent resource. If you use it at all, please help with version 2.0.

EDITED TO ADD (2/14): Details on progress and how to engage.

Tags: cybersecurity, national security policy, NIST

Posted on January 30, 2023 at 7:13 AM6 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2023/01/nist-is-updating-its-cybersecurity-framework.html