Cyber Security Fundamentals and Applications
Cybersecurity Frameworks
Why Use a Framework?
Instead of inventing a security strategy from scratch, organizations can use established cybersecurity frameworks. These provide a structured approach, offering guidelines and best practices to manage and reduce cybersecurity risk. Think of them as a blueprint for building a strong defense, ensuring all essential areas are covered.
Fundamentally, the NIST Cybersecurity Framework is a valuable tool for businesses looking to manage cybersecurity risk.
Using a framework helps align security activities with business goals, manage risks effectively, and communicate security requirements clearly to everyone from engineers to executives. They are not one-size-fits-all solutions but are designed to be adapted to an organization's specific needs, size, and risk profile.
The NIST Cybersecurity Framework
The National Institute of Standards and Technology (NIST) Cybersecurity Framework, often called the CSF, is one of the most widely adopted frameworks, especially in the United States. It was developed through a collaboration between government and the private sector to protect critical infrastructure, but its principles are applicable to any organization.
The framework is voluntary and focuses on using business drivers to guide cybersecurity activities. It organizes information into three main parts:
- The Framework Core: A set of desired cybersecurity activities and outcomes. This is the heart of the framework.
- Implementation Tiers: These help organizations understand their current cybersecurity risk management practices. The tiers range from Partial (Tier 1) to Adaptive (Tier 4).
- Framework Profiles: A profile is an organization's unique alignment of its requirements and objectives, risk appetite, and resources against the desired outcomes of the Framework Core. A "Current Profile" indicates the current state, while a "Target Profile" indicates the desired state.
The Framework Core is built around five key functions. These functions provide a high-level, strategic view of the lifecycle of an organization's management of cybersecurity risk. They are not meant to be a checklist, but a continuous cycle of improvement.
| Function | Purpose |
|---|---|
| Identify | Develop an organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities. |
| Protect | Implement appropriate safeguards to ensure delivery of critical infrastructure services. |
| Detect | Develop and implement the appropriate activities to identify the occurrence of a cybersecurity event. |
| Respond | Take action regarding a detected cybersecurity incident. |
| Recover | Develop and implement activities to maintain plans for resilience and to restore any capabilities or services that were impaired. |
ISO/IEC 27001
While the NIST CSF is a set of voluntary guidelines, ISO/IEC 27001 is an international standard that provides a specification for an Information Security Management System (ISMS). An ISMS is a systematic approach to managing sensitive company information so that it remains secure.
Organizations can become formally certified against ISO 27001 to demonstrate to customers and partners that they take information security seriously. This certification involves a formal audit by an accredited body.
The standard is structured in clauses that cover topics like risk assessment and leadership commitment. Its most famous part is Annex A, which lists 114 security controls grouped into 14 domains, such as access control, cryptography, and incident management. Organizations must conduct a risk assessment to determine which controls are relevant to them.
CIS Controls
The Center for Internet Security (CIS) Controls are a prioritized set of actions to protect an organization from known cyber-attack vectors. They are more specific and technical than the high-level functions of the NIST CSF or the management focus of ISO 27001. The CIS Controls are developed and updated by a community of IT experts.
They are broken down into three Implementation Groups (IGs), which are tailored for organizations with different levels of resources and expertise. IG1 represents basic cyber hygiene, while IG3 is for organizations with dedicated security staff and advanced risks.
The controls themselves are very practical. For example, CIS Control 1 is "Inventory and Control of Enterprise Assets," and Control 2 is "Inventory and Control of Software Assets." By focusing on these foundational steps first, organizations can achieve a significant security improvement with a manageable amount of effort.
Think of the relationship this way: NIST CSF tells you what to do (e.g., "Protect"), ISO 27001 tells you how to manage it (e.g., through an ISMS), and CIS Controls give you specific, prioritized actions on how to do it (e.g., "Implement access control").
Choosing and Implementing a Framework
These frameworks are not mutually exclusive. Many organizations use them together. For example, a company might use the NIST CSF as its overall guide, implement an ISO 27001-certified ISMS to manage the program, and use the CIS Controls as a technical implementation guide for specific safeguards.
Selecting the right approach depends on several factors:
- Regulatory Requirements: Industries like healthcare (HIPAA) or finance (PCI-DSS) have specific security rules. A framework must be chosen that helps meet these obligations.
- Company Size and Resources: A small business might start with CIS Implementation Group 1, while a large enterprise may pursue full ISO 27001 certification.
- Risk Profile: An organization handling sensitive government data has a different risk profile than a local retail store.
Implementation is a journey, not a destination. It starts with assessing the current security posture, defining a target state using a framework profile, identifying and prioritizing gaps, and then creating an action plan to close those gaps. This is a continuous process of monitoring, assessing, and improving.
Let's test your understanding of these key cybersecurity frameworks.
What is the primary purpose of using a cybersecurity framework?
The NIST Cybersecurity Framework (CSF) is organized into three main parts: the Framework Core, Implementation Tiers, and which other part?
Frameworks provide a solid foundation for any cybersecurity program, turning an overwhelming task into a manageable, structured process.
