This Monday DOC’s National Institute of Science and Technology (NIST) is publishing (available on line today) in the Federal Register (87 FR 9579-9581) a request for information on “Evaluating and Improving NIST Cybersecurity Resources: The Cybersecurity Framework (CSF) and Cybersecurity Supply Chain Risk Management.” NIST is considering aligning the CSF and the National Initiative for Improving Cybersecurity in Supply Chains (NIICS). In this RFI, NIST is requesting information that will support the identification and prioritization of supply chain-related cybersecurity needs across sectors.
NIST is looking for comments in the following areas:
Use of the CSF
In this section of the RFI, NIST is looking for discussions of the following topics:
The usefulness of the CSF for aiding organizations in organizing cybersecurity efforts,
Current benefits of using the CSF,
Challenges that may prevent organizations from using the CSF or using it more easily or extensively,
Features of the CSF that should be changed, added, or removed,
Impact to the usability and backward compatibility of the CSF if the structure of the framework is modified or changed, and
Additional ways in which NIST could improve the CSF or make it more useful.
CSF and Other Risk Management Resources
In this section of the RFI, NIST is looking for discussions of the following topics:
Suggestions for improving alignment or integration of the CSF with other NIST risk management resources,
Use of non-NIST frameworks or approaches in conjunction with the CSF,
Relationship of CSF to other international standards for cybersecurity, and
References that should be considered for inclusion within NIST's Online Informative References Program.
Cybersecurity Supply Chain Risk Management
In this section of the RFI, NIST is looking for discussions of the following topics:
Approaches, tools, standards, guidelines, or other resources necessary for managing cybersecurity-related risks in supply chains,
Gaps observed in existing cybersecurity supply chain risk management guidance and resources, and
Integration of Framework and Cybersecurity Supply Chain Risk Management Guidance.
Comments Requested
NIST is soliciting comments on this RFI. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NIST-2022-0001). Comments should be submitted by April 25th, 2022.
Commentary
The CSF is a corporate level cyber risk management tool rather than a true cybersecurity tool. Its greatest strength has always been that NIST proactively works to keep it current and responsive to current needs. It has relied heavily on the input from the public and outside experts. This RFI continues that tradition.