Showing posts with label Cybersecurity Framework. Show all posts
Showing posts with label Cybersecurity Framework. Show all posts

Wednesday, February 20, 2019

2019 Update on frameworks, standards, and regulations for infosec

At the 2019 BSides Tampa Security conference I did a talk on 2019 Updates on frameworks, standards, and regulations for infosec.  Over the last year several new and updated frameworks and regulations have come out, as well as are being updated.

Most of the information can be found on the Internet, but if you're not making an effort to stay up to date, you can miss something.  So here I give links to much of the information I gave.

NIST is the National Institute of Standards and Technology, a non-regulatory part of the Department of Commerce.  They are doing a lot of things that impact us in infosec.  Most are hopefully familiar with the Special Publication 800 and 1800 series that are put out on a regular basis.  Several are being developed, updated, and in a few cases retired. Go HERE to access all of them.

The NIST Cybersecurity Framework (CSF) was updated to version 1.1 last year, and they later had a cyber risk conference in October.  It just had its 5th anniversary, too. For full info on the CSF, and any updates and the like, go HERE.  One element I am looking forward to is an update to informative references that will add additional references (such as crosswalks to PCI-DSS, Standards of Good Controls, etc).  Hopefully we'll start seeing these coming out.

NIST Privacy Framework.  NIST has embarked on creating a privacy framework like they've done for cybersecurity.  This work has just begun, and they are working on a preliminary framework which we should see soon.  I would hope there will be further workshops and feedback before the final version is out.  To see where they are, go HERE.

FISMA is the Federal Information Security Management Act. Basically sets down security standards for federal information systems.  NIST has developed the materials for this, the Risk Management Framework (SP 800 37), the controls set (SP 800-53) and other materials.  They are working on updating this, having just come out with the latest version of the RMF.  The control set is next, with others to follow.  Go HERE for their page on this work.  The schedule is HERE.

Baldridge Cybersecurity Excellence Builder is a combination of NIST's Baldridge Excellence work crossed with their CSF.  It was rolled out in 2017, and should get an update this Spring.  You can download it for free HERE, and there is info on how others have used it successfully.

NIST OSCAL is an interesting project that attempts to create a common set of control assessment language.  This is a project I want to spend more time looking into myself.  More info on their website HERE.

Hopefully most have heard of the "Critical Controls" or the "Critical Security Controls".  Maybe you've heard it referred to as the "Top 20" or the "SANS20" or the like.  While it was started by SANS, they no longer manage it.  For the last few years its been handled by the Center for Internet Security, which has rolled out v6 and in early 2018 they rolled out v7.  They have reorganized it into 3 groups: Basic, Foundational, Organizational.  They have been putting out other resources for it, including the CSAT, a self assessment tool.  They are working on a v7.1 and I expect more resources coming from CIS.  So keep your eye out for them, as they just rolled out a companion guide for cloud (go HERE) and is working on another for IoT.

ISO/IEC 27000 is the international standard set for information security.  This series is made up of about 50-60 documents in various states of work.  Sadly, the documents are not free, and the cost is over $100 for each.  Key documents is usually 27001 and 27002.  1 sets down the ISMS (Information Security Management System) and 2 is the control set (compare with SP800-53).  As several of the documents are being worked on, its hard to keep up.  ISO/IEC 27005 got updated.  My go-to site to keep up to date on this is iso27002security.com.

Privacy regs  (GDPR & California).  Privacy is getting more and more important.  While we work in security, we often get pulled into privacy work as well.  GDPR (General Data Protection Regulation) of the EU was rolled out last year.  And we've already seen some big companies get in trouble.  While I see a lot of groups pushing GDPR training and the like, as a consultant I'm not seeing a lot of clients asking for help.  Yet.  California is rolling out their regulation, which isn't in effect yet.  We'll see if other states will roll out or update their privacy regulations.

One I left out of my presentation is 23 NYCRR 500, which is the New York Department of Financial Services (NY DFS) regulations on cybersecurity.  Rolled out a couple of years ago, the various elements of the regulation has been slowly rolled out with the last one required this March.  This regulation expects companies do certain things to protect NPI (non-public information), such as have a security program, policies, doing pentesting and vulnerability scanning, have a CISO, do training, have an incident response plan, vendor management plan, etc.  This may be a model for other state.  You can read it all HERE.

Now, there are some other items that aren't pure infosec/cybersecurity, but do touch on it, so should be mentioned.

CMMI- The Capability Maturity Model Integrated, originally for assessing the maturity of software development, it was later expanded to others.  Later merged into the CMMI, with Development, Service, and Acquisition versions.  The Software Engineering Institute at CMU developed it, and it used to be available for free or via books.  But they moved the CMMI to the CMMI Institute, which was recently bought by ISACA.  They've rolled out CMMI v2, but its available as a SaaS product, and no longer free.  The CMMI Institute has also rolled out a Cybermaturity Platform, again as a SaaS product.  I'd like to learn more about it, but hard to do.

COBIT, which is ISACA framework for governance of enterprise IT has been updated to COBIT 2019.  They've rolled out the new books, and hopefully other materials will be updated to COBIT 2019.

ITIL is a framework for IT Service Management, which includes infosec.  The current version is ITIL v3 (updated in 2011).  It's being updated to a new version, ITIL 4.  So far only the foundation certification info have been updated.  Hopefully they will update the 5 main books this year.

PCI-DSS is the standard for assessing credit card processing systems.  Current version is 3.2.1, which was updated due to issues with SSL.  Well, the next version, v4, is going to be coming out, but not for another year or so.  It will be a very different version, but info on this is hard to find.  Am sure as we move further along we'll learn more.

Hopefully this is useful for others.  As I learn of new updates, I'll make further postings.


Sunday, February 3, 2019

2018 NIST Cybersecurity Risk Management Conference

Back in October I was in Baltimore for NIST's 2018 Cybersecurity Risk Management Conference.  For those not aware, let me break this down.  NIST is the National Institute of Standards and Technology, a non-regulatory research arm of the Department of Commerce.  For those of us in the IT and infosec world, we know NIST for their SP800 and SP1800 series of documents on various IT and infosec topics, for creating the Risk Management Framework (sometimes call FISMA) and the Cybersecurity Framework (CSF).

For the last two years they held annual workshops for the CSF (these were actually the 7th and 8th), which I was able to attend and previously reported on.  The main purpose of these workshops was to bring people together to look at the future of the CSF, and develop the next version, which was v1.1 that came out earlier this year.

This year we instead got a 3 day conference held at a hotel in Baltimore.  It was a mix of plenary sessions, work sessions, panel discussions, and presentations.  There were also working lunches for those who paid extra for 'catering'.

It was almost overwhelming the number of sessions, as there were about 8-9 sessions going on at once during certain period.  Some of the slide decks from these presentations are made available, as there was almost too much information.

Some of the items I learned was details on the updating going on with various documents related to FISMA.  I knew this was going on, but got more details.  Also learned more about the plans for PCI-DSS v4, which is planned for development over the coming year.  I also learned more about the Baldridge Cybersecurity Excellence Builder (which will have an update early next year).

There were some problems, I think due to the change in venue and expansion from the workshops.  I hope these will be addressed for the next one.  At this point, we don't know when or even where the next one will be.  So we'll have to see.  I hope I can attend the next one as well.

Tuesday, February 6, 2018

Framework/standard updates coming

Well, it's early 2018 and there are several information security framework/standards being updated:
  • NIST CSF v1.1.  The second draft was released at the end of 2017, and we just wrapped up the comment period on this.  I believe the plans are to review and hopefully come out with the final release in a few months.  Now I think we will also see another workshop held in conjunction with this, we just don't know exactly when.

  •  NIST SP 800-53 and 800-37.  NIST is also working on updated for a couple of important documents in FISMA/RMF.  SP 800-53 is the controls, and has now been expanded to include privacy controls as well as security. SP 800-37 defines the Risk Management Framework, and should also have info on how the RMF can work with the CSF.  Now the plan was to come out with a second draft at the end of last year after they put out the discussion draft, but it looks like the schedule has slipped.  If you read on-line, it looks like they need to re-assess the amount of work needed.  I do expect we will see these done this year, but no idea when at this point.

  • CIS Critical Security Controls.  Better known as the "SANS Top 20", the Critical Security Controls are now managed by the Center for Internet Security.  The current version is 6.1 and they are working on a v7.  I had seen stuff on their site last year about this, but it disappeared, so I thought the effort was dead.  Now they have a draft of v7 out with a short comment period (about to end).  It's not clear when they expect the final version to come out but clearly will be this year
The only thing I am concerned is that both SP800-53 and the CSC are Informational References in the NIST CSF.  If they come out with new versions, will the Information References in the CSF be updated to these new versions?  I hope they will be.  Still awaiting the official PCI-CSF crosswalk to be made available.

As I learn more about these new updates, I'll be blogging about them.

Monday, February 5, 2018

Healthcare Industry Cybersecurity Task Force report- June 2017

Recently a report came out from the "Health Care Industry Cybersecurity Task Force".  This group was formed by Congress as part of the Cybersecurity Act of 2015.  The task force is made up of a diverse group from the healthcare industry, taking a look at the state of cybersecurity and how it can be improved.

You can read the report HERE.

At nearly 100 pages, it's a bit much to slog thru.  At a minimum, read over the executive summary.  As someone who works with healthcare clients, their findings are not a surprise to me.  They have a figure:


which points out some of this issues.  Lack of talent- yes.  Not that there is no talent, but that many orgs don't have enough people on board.  Smaller orgs can't afford to, sometimes outsourcing their IT to vendors who themselves may not have the right skills.  (it's one thing to go with a managed security service provider who hopefully knows healthcare, it's another to go with some local IT guys who has no idea of security or the issues facing healthcare)
Legacy equipment- wow.  yes.  Big problem as the vendors aren't supporting or updating these systems, and the orgs can't.  Most orgs don't understand that there are some solutions (isolated networks and the like) for this.  Over-connectivity ties back to lack of talent.  When you don't have people on board who can properly set things up, problems will arise.  Vulnerabilities impact- this is stuff like ransomware and the like hitting groups, which often was caused by not have the right talent in place to get things in a good shape.

Some of these actually interconnect.  Healthcare IT is behind everyone else.  Too many organizations have, for various reasons, not invested in IT.  This means they have not worked to get enough people on board with the right skills and given them the budget to setup things up well.

They define 6 imperatives:

  1. Define and streamline leadership, governance, and expectations for health care industry cybersecurity.
  2. Increase the security and resilience of medical devices and health IT.
  3. Develop the health care workforce capacity necessary to prioritize and ensure cybersecurity awareness and technical capabilities.
  4. Increase health care industry readiness through improved cybersecurity awareness and education.
  5. Identify mechanisms to protect research and development efforts and intellectual property from attacks or exposure.
  6. Improve information sharing of industry threats, weaknesses, and mitigations.
The report spends quite a bit of time on a variety of recommendations and action items off of these imperatives.

Check it out and add your comments.










Tuesday, August 8, 2017

News on NIST CSF v1.1

I've previously posted on the NIST Cybersecurity Framework (NIST CSF) and the recent work to update it to v1.1.  I had attended the recent workshop held at NIST headquarters following the released of the Draft v1.1 and comments.  And I've been awaiting their report on the Workshop and a better idea as to what are the next steps.

Well, just before "Hacker Summer Camp" they released their summary and I missed it.  You can read it HERE.

Monday, June 19, 2017

FFIEC CAT v1.1

In June of 2015 the FFIEC (Federal Financial Institutions Examination Council) released the first version of their Cybersecurity Assessment Tool (CAT).  The FFIEC, for those not aware, is a formal interagency body empowered to prescribe uniform principles, standards, and report forms for the federal examination of financial institutions and is made up of 6 different agencies.

The FFIEC already has a set of works called the IT Examination Handbooks, about a dozen, which help set down standards for IT in several areas.  One of interest would be the Information Security one that was finally updated in 2016.

Thursday, June 15, 2017

NIST Cybersecurity Workshop 2017

In May 2017, NIST hosted another Cybersecurity Workshop.  This 2 day workshop was held as part of their process to update the Cybersecurity Framework.  This process actually started a year ago when NIST had a request for comments on how the framework was used, followed by a workshop to review that input and see if there was a need for an update.

A big question was should the update be incremental (a version 1.1) or major (a version 2.0).  The answer was more for an incremental update.

So this was followed by a draft v1.1 update at the end of 2016, followed by another request for comments on the draft, which lead to this workshop to review the results and do further work to get to a finished v1.1

Tuesday, May 23, 2017

New Cybersecurity Executive Order

So by now hopefully most are aware of the recent Executive Order signed by President Trump.  While not numbered, it came out May 11th, which was just before the planned NIST Cybersecurity Framework Workshop.  Full title is "Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure".

So let's take a look at it.

It has 5 sections.  Sections 4 and 5 we can basically overlook.  Sec4 is definitions, while Sec5 is General Provisions.

Monday, May 22, 2017

Recent events

Am a little behind on posting on some very recent events.

Last week I was at the NIST Cybersecurity Workshop.  Lot of interesting things there.  Further, the prior week Trump signed an Executive Order on Cybersecurity that has an impact on things.

This past weekend I was at the HackMiamiCon5, where I also spoke on cyber resilience.  More on that as well.

Hopefully soon I will be speaking at an upcoming HackMiami meeting on various updates (the NIST CSF Workshop, recent EO, and some other regulations that have come out).


Friday, May 12, 2017

News and upcoming events

One of the news items floating around is the recently signed executive order regarding cybersecurity.  I haven't had a chance to really look over it, but hope to soon and will post my thoughts here.

There are a couple of upcoming events I will be at next week.

First off is the NIST Cybersecurity Framework Workshop at NIST HQ.  I look forward to that.  Should be a great opportunity to gather information, give input, and meet others.  I hope that impact of this new EO will also be covered.

Then next weekend is the HackMiamiCon5 in Miami Beach.  I'll be there, and be speaking on the second day on Cyber Resilience.  Look forward to that.

I will be posting on both events here on the blog, so be sure to check back.

Wednesday, March 8, 2017

News on NIST's update to Cybersecurity Framework

As I have previously posted, and hopefully most are aware, NIST (National Institute of Standards and Technology) has released a draft for an update of the Cybersecurity Framework (CSF), to be v1.1.

Recently NIST held 2 webinars on the CSF, each an hour long.  One was an overview, and the other on the proposed updates.  The webinars had a limited number that could watch them live, but they have now put up the videos on their website.  Both are good to watch.

Friday, January 13, 2017

NIST Cybersecurity Framework v1.1 is coming!!!

Well, NIST (National Institute of Standards and Technology) has announced an update for the Cybersecurity Framework (CSF).  The new version will be v1.1, an incremental update which was expected.

They have released a draft of this update for comments.

You may read about it HERE.   There is also THIS page that explain the update AND gives info on feedback, which has a deadline of APRIL 10, 2017 and were to send comments.

At that page you can read the draft in a couple of different versions.

What has been added/updated?

They added more stuff regarding supply chain.  They did a few tweaks on the Core.  I had hoped they would have gotten rid of the Implementation Tiers, but instead of dumping it or major work they did some tweaks to it.  And there is a new section on metrics and measurement.

I was disappointed they didn't update the Critical Security Controls references.  They are still listing v5, which is no longer valid and the group that managed it is no more.  However, they note they are still updating all the Information References, so hopefully that is just something that is in progress and will appeared in the released version.

I had hoped that the HIPAA crosswalk that was done would be incorporated into the document, at least as an appendix.  And I think the should add a PCI DSS crosswalk.  Am told it exists, and think it would be good to include it.  Again, maybe this will be including in the final version.

Am debating if I should put together a talk on this proposed draft for upcoming conferences.


Friday, June 10, 2016

Updates on the NIST Cybersecurity Framework

I've previously posted on the NIST Cybersecurity Framework, and was very surprised that in the last week there has been some new development in that area.

I especially found this interesting because on June 11th I am presenting my "NIST CSF at 2" presentation to the HackMiami meeting at the Broward Main Library.  This is the presentation I gave at BSides Tampa 2016, and had made a few tweaks.  And so I am doing some updates in light of these developments.


Monday, April 18, 2016

One of my slides from my NIST CSF presentation

When I did my recent presentation on the NIST CSF at BSides Tampa, I had some ask about the source of one of the pictures in my presentation.

All the pictures I got off Google Images, btw.

Here is the picture in question:


The source is this article on the ISACA website, in the section on "Information Security Management at HDFC Bank"

Hope this is of use to others.



Wednesday, April 13, 2016

NIST hosts a Cybersecurity Framework Workshop for 2016

For two days, April 6 and 7 2016, NIST (National Institute for Standards and Technology) hosted a workshop for the Cybersecurity Framework (CSF).  This is the 7th they have held.

In developing the CSF, NIST held a series of 5 such workshops to gather feedback which was used in developing the Framework.  A 6th workshop was held shortly after the Frameworks release.  As part of the process in further developing and supporting the Framework, NIST put our a Call for Information (CFI) on the Frameworks use as well as solicite comments on possible improvements or revisions (say a 1.x update or a 2.0 update).  This CFI ran from December to February of 2016.  This workshop was held to review the outcomes of that CFI, as well as to gather further feedback.



For more info on these past workshops, go HERE.  At present, their report on this workshop won't be available until mid May, however, the webcast recordings should now be available.

Monday, April 13, 2015

Resources for the NIST CSF

At the recent Security BSides Orlando conference, I gave a talk on the NIST Cybersecurity Framework (NIST CSF).

As an aide to that talk, here are a collection of resources on the CSF.