NIST Releases Criticality Analysis Guide

The agency is requesting public comments by Aug. 18 on the document, which will help organizations perform a step-by-step analysis to identify critical parts of a system that must not fail or be compromised if the system is to successfully support the organization's mission.

Nearly every organization depends on information or operational technology for its principal business or mission, but how can they keep the infrastructure up to date without jeopardizing its ability to function or breaking the budget? The National Institute of Standards and Technology (NIST) hopes to help answer this key question with new draft guidance to help organizations conduct criticality analyses.

The agency is requesting public comments by Aug. 18 on the document, which will help organizations perform a step-by-step analysis to identify critical parts of a system that must not fail or be compromised if the system is to successfully support the organization's mission.

The document is NIST Interagency Report (NISTIR) 8179, "Criticality Analysis Process Model." It builds on previous NIST guidance that emphasized the importance of identifying the critical points in a system but did not provide a method for doing so, says the agency. "This draft report shows people how to perform a criticality analysis that's tailored to their organization," explained NIST cybersecurity expert Jon Boyens, who co-authored the report with his colleague Celia Paulsen. "Each agency will have its own situation. We are developing this for the government, but we want it to be friendly and useful for the private sector."

"I think guidance like this will help secure the supply chain," said John Peterson, senior program manager at the Redhorse Corporation in San Diego. "A lot of these systems are integrated, so if you have one part that's compromised in some way, it could affect the entire system."

"The legacy problem is notorious throughout industry," said Carol Woody, technical manager for cybersecurity engineering at the Software Engineering Institute in Pittsburgh. "All organizations are trying to keep technology costs down. It's hard to do because they have to make choices that may not always anticipate problems 10 years down the road. What the NIST authors are doing is saying, 'Think broadly. Ask yourself why you bought something and how long it will be before it could conceivably need more capability—plan for its usable life and budget accordingly.'"

Product Showcase

  • Matrix's OmniPro Vision AI Collision Avoidance System

    OmniPro Vision AI is a state-of-the-art collision avoidance system that features NIOSH award-winning Visual Artificial Intelligence (AI) technology. This highly accurate, powerful system identifies and alerts on pedestrians, vehicles and specified objects, ensuring safer facilities, mining operations and industrial sites. With its web-based cloud application, OmniPro Vision AI also logs and analyzes a wide range of data related to zone breach notifications. Operating without needing personal wearable devices or tags, OmniPro has visual and audible zone breach alerts for both operators and pedestrians. Read More

  • Magid® D-ROC® GPD412 21G Ultra-Thin Polyurethane Palm Coated Work Gloves

    Magid’s 21G line is more than just a 21-gauge glove, it’s a revolutionary knitting technology paired with an advanced selection of innovative fibers to create the ultimate in lightweight cut protection. The latest offering in our 21G line provides ANSI A4 cut resistance with unparalleled dexterity and extreme comfort that no other 21-gauge glove on the market can offer! Read More

  • SwabTek® Cannabis Test Kit

    The SwabTek® Cannabis Test Kit is a single-use spot test designed for use in screening for cannabis compounds in any sample type or on any surface. The test is capable of identifying the presumed presence of cannabinoids in very small quantities, with a level of detection as little as 6 μg in mass. Learn more about the SwabTek® Cannabis Test Kit and the rest of SwabTek surface drug testing solutions through the webinar titled "Everything You Want To Know About Surface Testing" Read More

Featured

Artificial Intelligence