Showing posts with label NIST. Show all posts
Showing posts with label NIST. Show all posts

Wednesday, February 20, 2019

2019 Update on frameworks, standards, and regulations for infosec

At the 2019 BSides Tampa Security conference I did a talk on 2019 Updates on frameworks, standards, and regulations for infosec.  Over the last year several new and updated frameworks and regulations have come out, as well as are being updated.

Most of the information can be found on the Internet, but if you're not making an effort to stay up to date, you can miss something.  So here I give links to much of the information I gave.

NIST is the National Institute of Standards and Technology, a non-regulatory part of the Department of Commerce.  They are doing a lot of things that impact us in infosec.  Most are hopefully familiar with the Special Publication 800 and 1800 series that are put out on a regular basis.  Several are being developed, updated, and in a few cases retired. Go HERE to access all of them.

The NIST Cybersecurity Framework (CSF) was updated to version 1.1 last year, and they later had a cyber risk conference in October.  It just had its 5th anniversary, too. For full info on the CSF, and any updates and the like, go HERE.  One element I am looking forward to is an update to informative references that will add additional references (such as crosswalks to PCI-DSS, Standards of Good Controls, etc).  Hopefully we'll start seeing these coming out.

NIST Privacy Framework.  NIST has embarked on creating a privacy framework like they've done for cybersecurity.  This work has just begun, and they are working on a preliminary framework which we should see soon.  I would hope there will be further workshops and feedback before the final version is out.  To see where they are, go HERE.

FISMA is the Federal Information Security Management Act. Basically sets down security standards for federal information systems.  NIST has developed the materials for this, the Risk Management Framework (SP 800 37), the controls set (SP 800-53) and other materials.  They are working on updating this, having just come out with the latest version of the RMF.  The control set is next, with others to follow.  Go HERE for their page on this work.  The schedule is HERE.

Baldridge Cybersecurity Excellence Builder is a combination of NIST's Baldridge Excellence work crossed with their CSF.  It was rolled out in 2017, and should get an update this Spring.  You can download it for free HERE, and there is info on how others have used it successfully.

NIST OSCAL is an interesting project that attempts to create a common set of control assessment language.  This is a project I want to spend more time looking into myself.  More info on their website HERE.

Hopefully most have heard of the "Critical Controls" or the "Critical Security Controls".  Maybe you've heard it referred to as the "Top 20" or the "SANS20" or the like.  While it was started by SANS, they no longer manage it.  For the last few years its been handled by the Center for Internet Security, which has rolled out v6 and in early 2018 they rolled out v7.  They have reorganized it into 3 groups: Basic, Foundational, Organizational.  They have been putting out other resources for it, including the CSAT, a self assessment tool.  They are working on a v7.1 and I expect more resources coming from CIS.  So keep your eye out for them, as they just rolled out a companion guide for cloud (go HERE) and is working on another for IoT.

ISO/IEC 27000 is the international standard set for information security.  This series is made up of about 50-60 documents in various states of work.  Sadly, the documents are not free, and the cost is over $100 for each.  Key documents is usually 27001 and 27002.  1 sets down the ISMS (Information Security Management System) and 2 is the control set (compare with SP800-53).  As several of the documents are being worked on, its hard to keep up.  ISO/IEC 27005 got updated.  My go-to site to keep up to date on this is iso27002security.com.

Privacy regs  (GDPR & California).  Privacy is getting more and more important.  While we work in security, we often get pulled into privacy work as well.  GDPR (General Data Protection Regulation) of the EU was rolled out last year.  And we've already seen some big companies get in trouble.  While I see a lot of groups pushing GDPR training and the like, as a consultant I'm not seeing a lot of clients asking for help.  Yet.  California is rolling out their regulation, which isn't in effect yet.  We'll see if other states will roll out or update their privacy regulations.

One I left out of my presentation is 23 NYCRR 500, which is the New York Department of Financial Services (NY DFS) regulations on cybersecurity.  Rolled out a couple of years ago, the various elements of the regulation has been slowly rolled out with the last one required this March.  This regulation expects companies do certain things to protect NPI (non-public information), such as have a security program, policies, doing pentesting and vulnerability scanning, have a CISO, do training, have an incident response plan, vendor management plan, etc.  This may be a model for other state.  You can read it all HERE.

Now, there are some other items that aren't pure infosec/cybersecurity, but do touch on it, so should be mentioned.

CMMI- The Capability Maturity Model Integrated, originally for assessing the maturity of software development, it was later expanded to others.  Later merged into the CMMI, with Development, Service, and Acquisition versions.  The Software Engineering Institute at CMU developed it, and it used to be available for free or via books.  But they moved the CMMI to the CMMI Institute, which was recently bought by ISACA.  They've rolled out CMMI v2, but its available as a SaaS product, and no longer free.  The CMMI Institute has also rolled out a Cybermaturity Platform, again as a SaaS product.  I'd like to learn more about it, but hard to do.

COBIT, which is ISACA framework for governance of enterprise IT has been updated to COBIT 2019.  They've rolled out the new books, and hopefully other materials will be updated to COBIT 2019.

ITIL is a framework for IT Service Management, which includes infosec.  The current version is ITIL v3 (updated in 2011).  It's being updated to a new version, ITIL 4.  So far only the foundation certification info have been updated.  Hopefully they will update the 5 main books this year.

PCI-DSS is the standard for assessing credit card processing systems.  Current version is 3.2.1, which was updated due to issues with SSL.  Well, the next version, v4, is going to be coming out, but not for another year or so.  It will be a very different version, but info on this is hard to find.  Am sure as we move further along we'll learn more.

Hopefully this is useful for others.  As I learn of new updates, I'll make further postings.


Sunday, February 3, 2019

2018 NIST Cybersecurity Risk Management Conference

Back in October I was in Baltimore for NIST's 2018 Cybersecurity Risk Management Conference.  For those not aware, let me break this down.  NIST is the National Institute of Standards and Technology, a non-regulatory research arm of the Department of Commerce.  For those of us in the IT and infosec world, we know NIST for their SP800 and SP1800 series of documents on various IT and infosec topics, for creating the Risk Management Framework (sometimes call FISMA) and the Cybersecurity Framework (CSF).

For the last two years they held annual workshops for the CSF (these were actually the 7th and 8th), which I was able to attend and previously reported on.  The main purpose of these workshops was to bring people together to look at the future of the CSF, and develop the next version, which was v1.1 that came out earlier this year.

This year we instead got a 3 day conference held at a hotel in Baltimore.  It was a mix of plenary sessions, work sessions, panel discussions, and presentations.  There were also working lunches for those who paid extra for 'catering'.

It was almost overwhelming the number of sessions, as there were about 8-9 sessions going on at once during certain period.  Some of the slide decks from these presentations are made available, as there was almost too much information.

Some of the items I learned was details on the updating going on with various documents related to FISMA.  I knew this was going on, but got more details.  Also learned more about the plans for PCI-DSS v4, which is planned for development over the coming year.  I also learned more about the Baldridge Cybersecurity Excellence Builder (which will have an update early next year).

There were some problems, I think due to the change in venue and expansion from the workshops.  I hope these will be addressed for the next one.  At this point, we don't know when or even where the next one will be.  So we'll have to see.  I hope I can attend the next one as well.

Monday, March 5, 2018

March Updates on Frameworks & Standards

Last month I posted some information on several information security framework/standards being updated and sense then there have been updated on all of them.  So here we go:
  • NIST CSF v1.1.  The second draft was released at the end of 2017, and we just wrapped up the comment period on this.  I believe the plans are to review and hopefully come out with the final release in a few months.  Not clear when.  They have also set a tentative date for the 2018 workshop as September 11-13 in "the DC area".  Now NIST headquarters is in Baltimore, so does that count as the "DC area"?  I should also point out that NIST has done a great job of revamping their NIST CSF website, with some more info.

  •  NIST SP 800-53 and 800-37.  NIST is also working on updated for a couple of important documents in FISMA/RMF.  SP 800-53 is the controls, and has now been expanded to include privacy controls as well as security. SP 800-37 defines the Risk Management Framework, and should also have info on how the RMF can work with the CSF.  As I had noted, the original plan was to come out with a second draft at the end of last year after they put out the discussion draft, but it slipped.  We were promised they they would re-asses and put out new dates, which they have: 
  • NIST Special Publication 800-37, Revision 2 (Risk Management Framework)
  • Initial Public Draft:  May 2018
  • Final Public Draft: July 2018
  • Final Publication:  October 2018
  •  
  • NIST Special Publication 800-53, Revision 5 (Security and Privacy Controls)
  • Final Public Draft:  October 2018
  • Final Publication:  December 2018
  •  
  • NIST Special Publication 800-53A, Revision 5 (Assessment Procedures for 800-53)
  • Initial Public Draft:  March 2019
  • Final Public Draft:  June 2019
  • Final Publication:  September 2019
  •  
  • FIPS Publication 200, Revision 1 (Minimum Security Requirements)
  • Initial Public Draft:  October 2018
  • Final Public Draft:  April 2019
  • Final Publication:  July 2019
  •  
  • FIPS Publication 199, Revision 1 (Security Categorization)
  • Initial Public Draft:  December 2018
  • Final Public Draft:  May 2019
  • Final Publication:  August 2019

  • CIS Critical Security Controls.  Better known as the "SANS Top 20", the Critical Security Controls are now managed by the Center for Internet Security.  The current version is 6.1 and they are working on a v7.  I had seen stuff on their site last year about this, but it disappeared, so I thought the effort was dead.  They put out a draft of v7 out with a short comment period.  And are rolling out v7 on March 19th in DC (or you can attend on-line).  So that is pretty quick
The only thing I am concerned is that both SP800-53 and the CSC are Informational References in the NIST CSF.  If they come out with new versions, will the Information References in the CSF be updated to these new versions?  I hope they will be.  Now NIST has on their new CSF website an on-line version of the Informational References that allows them to expand them.  Tho why they didn't include the HIPAA crosswalk here I don't know. Still awaiting the official PCI-CSF crosswalk to be made available as well.

As I learn more about these new updates, I'll be blogging about them.  I look forward to getting my hands on v7 of the CSC due to what I read in the draft version.

Tuesday, February 6, 2018

Framework/standard updates coming

Well, it's early 2018 and there are several information security framework/standards being updated:
  • NIST CSF v1.1.  The second draft was released at the end of 2017, and we just wrapped up the comment period on this.  I believe the plans are to review and hopefully come out with the final release in a few months.  Now I think we will also see another workshop held in conjunction with this, we just don't know exactly when.

  •  NIST SP 800-53 and 800-37.  NIST is also working on updated for a couple of important documents in FISMA/RMF.  SP 800-53 is the controls, and has now been expanded to include privacy controls as well as security. SP 800-37 defines the Risk Management Framework, and should also have info on how the RMF can work with the CSF.  Now the plan was to come out with a second draft at the end of last year after they put out the discussion draft, but it looks like the schedule has slipped.  If you read on-line, it looks like they need to re-assess the amount of work needed.  I do expect we will see these done this year, but no idea when at this point.

  • CIS Critical Security Controls.  Better known as the "SANS Top 20", the Critical Security Controls are now managed by the Center for Internet Security.  The current version is 6.1 and they are working on a v7.  I had seen stuff on their site last year about this, but it disappeared, so I thought the effort was dead.  Now they have a draft of v7 out with a short comment period (about to end).  It's not clear when they expect the final version to come out but clearly will be this year
The only thing I am concerned is that both SP800-53 and the CSC are Informational References in the NIST CSF.  If they come out with new versions, will the Information References in the CSF be updated to these new versions?  I hope they will be.  Still awaiting the official PCI-CSF crosswalk to be made available.

As I learn more about these new updates, I'll be blogging about them.

Wednesday, August 16, 2017

NIST releases DRAFT SP800-53R5

Recently NIST finally releases the DRAFT of SP800-53R5.  800-53 is entitled Security and Privacy Controls for Federal Information Systems and Organizations and is the set of controls used in FISMA, the mandated set of infosec controls used in federal systems (tho many others use it as well, often times state and local governments, as well as government contractors).

This has been in the works for awhile now, and many expected this draft to come out several months ago.  The due date for comments is September 17, 2017.  They want to put out the final draft (second draft) in October, with the final version by the end of the year.

They note several changes.  They have incorporated privacy controls into this.  They have separated out the control selection process from the controls.  The Risk Management Framework is that control selection process.  By doing this, it more easily allows others to use the controls as is.  With the NIST CSF referencing the controls in SP800-53, it makes it easier for those using the CSF to use these controls.  This is actually called out that SP800-53 can be used with the RMF, CSF, and Systems Engineering Processes.

One big change was the striking out "federal" from the title within the document, again as part of making the controls more accessible to non-federal users.

Tuesday, August 8, 2017

News on NIST CSF v1.1

I've previously posted on the NIST Cybersecurity Framework (NIST CSF) and the recent work to update it to v1.1.  I had attended the recent workshop held at NIST headquarters following the released of the Draft v1.1 and comments.  And I've been awaiting their report on the Workshop and a better idea as to what are the next steps.

Well, just before "Hacker Summer Camp" they released their summary and I missed it.  You can read it HERE.

Thursday, June 15, 2017

NIST Cybersecurity Workshop 2017

In May 2017, NIST hosted another Cybersecurity Workshop.  This 2 day workshop was held as part of their process to update the Cybersecurity Framework.  This process actually started a year ago when NIST had a request for comments on how the framework was used, followed by a workshop to review that input and see if there was a need for an update.

A big question was should the update be incremental (a version 1.1) or major (a version 2.0).  The answer was more for an incremental update.

So this was followed by a draft v1.1 update at the end of 2016, followed by another request for comments on the draft, which lead to this workshop to review the results and do further work to get to a finished v1.1

Monday, May 22, 2017

Recent events

Am a little behind on posting on some very recent events.

Last week I was at the NIST Cybersecurity Workshop.  Lot of interesting things there.  Further, the prior week Trump signed an Executive Order on Cybersecurity that has an impact on things.

This past weekend I was at the HackMiamiCon5, where I also spoke on cyber resilience.  More on that as well.

Hopefully soon I will be speaking at an upcoming HackMiami meeting on various updates (the NIST CSF Workshop, recent EO, and some other regulations that have come out).


Friday, May 12, 2017

News and upcoming events

One of the news items floating around is the recently signed executive order regarding cybersecurity.  I haven't had a chance to really look over it, but hope to soon and will post my thoughts here.

There are a couple of upcoming events I will be at next week.

First off is the NIST Cybersecurity Framework Workshop at NIST HQ.  I look forward to that.  Should be a great opportunity to gather information, give input, and meet others.  I hope that impact of this new EO will also be covered.

Then next weekend is the HackMiamiCon5 in Miami Beach.  I'll be there, and be speaking on the second day on Cyber Resilience.  Look forward to that.

I will be posting on both events here on the blog, so be sure to check back.

Wednesday, March 8, 2017

News on NIST's update to Cybersecurity Framework

As I have previously posted, and hopefully most are aware, NIST (National Institute of Standards and Technology) has released a draft for an update of the Cybersecurity Framework (CSF), to be v1.1.

Recently NIST held 2 webinars on the CSF, each an hour long.  One was an overview, and the other on the proposed updates.  The webinars had a limited number that could watch them live, but they have now put up the videos on their website.  Both are good to watch.

Friday, January 13, 2017

NIST Cybersecurity Framework v1.1 is coming!!!

Well, NIST (National Institute of Standards and Technology) has announced an update for the Cybersecurity Framework (CSF).  The new version will be v1.1, an incremental update which was expected.

They have released a draft of this update for comments.

You may read about it HERE.   There is also THIS page that explain the update AND gives info on feedback, which has a deadline of APRIL 10, 2017 and were to send comments.

At that page you can read the draft in a couple of different versions.

What has been added/updated?

They added more stuff regarding supply chain.  They did a few tweaks on the Core.  I had hoped they would have gotten rid of the Implementation Tiers, but instead of dumping it or major work they did some tweaks to it.  And there is a new section on metrics and measurement.

I was disappointed they didn't update the Critical Security Controls references.  They are still listing v5, which is no longer valid and the group that managed it is no more.  However, they note they are still updating all the Information References, so hopefully that is just something that is in progress and will appeared in the released version.

I had hoped that the HIPAA crosswalk that was done would be incorporated into the document, at least as an appendix.  And I think the should add a PCI DSS crosswalk.  Am told it exists, and think it would be good to include it.  Again, maybe this will be including in the final version.

Am debating if I should put together a talk on this proposed draft for upcoming conferences.


Friday, June 10, 2016

Updates on the NIST Cybersecurity Framework

I've previously posted on the NIST Cybersecurity Framework, and was very surprised that in the last week there has been some new development in that area.

I especially found this interesting because on June 11th I am presenting my "NIST CSF at 2" presentation to the HackMiami meeting at the Broward Main Library.  This is the presentation I gave at BSides Tampa 2016, and had made a few tweaks.  And so I am doing some updates in light of these developments.


Wednesday, April 13, 2016

NIST hosts a Cybersecurity Framework Workshop for 2016

For two days, April 6 and 7 2016, NIST (National Institute for Standards and Technology) hosted a workshop for the Cybersecurity Framework (CSF).  This is the 7th they have held.

In developing the CSF, NIST held a series of 5 such workshops to gather feedback which was used in developing the Framework.  A 6th workshop was held shortly after the Frameworks release.  As part of the process in further developing and supporting the Framework, NIST put our a Call for Information (CFI) on the Frameworks use as well as solicite comments on possible improvements or revisions (say a 1.x update or a 2.0 update).  This CFI ran from December to February of 2016.  This workshop was held to review the outcomes of that CFI, as well as to gather further feedback.



For more info on these past workshops, go HERE.  At present, their report on this workshop won't be available until mid May, however, the webcast recordings should now be available.

Sunday, March 13, 2016

Resources for workshop on security standards/frameworks/regulations for information security professionals

At the 2016 Security BSides Orlando conference, I gave a workshop on security standards, frameworks, regulations for information security professionals.  While not an exhaustive survey of such, I focused on the ones that seem the most known, and which I typically see on job descriptions.

Not covered were enterprise architecture models like Zachman or TOGAF.  Left out are other security frameworks like SABSA or things like RESILIAFedRAMP or Cloud Control Matrix, SSAE 16/SOC, Secure DevOps, or Maturity Models for security.

Covered were:
  • CIS CSC
  • NIST CSF (plus FFIEC CAT)
  • ISO/IEC 27001
  • FISMA
  • HIPAA
  • GLBA 
  • SOX (plus COSO)
  • PCI-DSS
  • COBIT 5
  • ITIL

Monday, April 13, 2015

Resources for the NIST CSF

At the recent Security BSides Orlando conference, I gave a talk on the NIST Cybersecurity Framework (NIST CSF).

As an aide to that talk, here are a collection of resources on the CSF.