NIST Updates Risk Management Framework

The updated RMF will interest federal agencies and contractors that do business with them because it connects the RMF with NIST's well-known Cybersecurity Framework and highlights relationships between the two documents.

The National Institute of Standards and Technology recently announced it has issued a draft update of its Risk Management Framework to help organizations more easily meet the goals of protecting the nation's critical assets from cybersecurity threats and also protect individuals' privacy. The RMF update is Draft NIST Special Publication 800-37 Revision 2, a guidance document to help organizations assess and manage risks to their information and systems. Previous versions of the framework were primarily concerned with cybersecurity protections from external threats, while the updated version adds an overarching concern for individuals' privacy.

NIST explained that the update will interest federal agencies and contractors that do business with them because it connects the RMF with NIST's well-known Cybersecurity Framework and highlights relationships between the two documents.

"Until now, federal agencies had been using the RMF and CSF separately," explained NIST's Ron Ross, one of the publication's authors. "The update provides cross-references so that organizations using the RMF can see where and how the CSF aligns with the current steps in the RMF. Conversely, if you're using the CSF, you can bring in the RMF and give your organization a robust methodology to manage security and privacy risks."

The update has several other important objectives, including:

  • Integrating security and privacy into systems development.
  • Connecting senior leaders to operations. The RMF provides guidance on how an organization's senior leaders can better prepare for RMF execution, as well as how to communicate their protection plans and risk management strategies to system implementers and operators.
  • Incorporating supply chain risk management considerations. The RMF addresses growing supply chain concerns in the areas of counterfeit components, tampering, theft, insertion of malicious software and hardware, poor manufacturing and development practices, and other potential harmful activities.
  • Supporting security and privacy safeguards. The RMF update will provide organizations with a disciplined and structured process to select controls from the newly developed consolidated security and privacy control catalog in NIST's SP 800-53, Revision 5.

"It was imperative for us to figure out how these frameworks fit together. Many agencies are trying to follow both," said Ross, who said the privacy-enhanced RMF might be valuable to companies and organizations beyond the federal government, considering the high importance now being placed on privacy.

NIST is accepting comments from the public on the draft RMF until June 22, 2018. A final version will be issued in October 2018.

Product Showcase

  • Magid® D-ROC® GPD412 21G Ultra-Thin Polyurethane Palm Coated Work Gloves

    Magid’s 21G line is more than just a 21-gauge glove, it’s a revolutionary knitting technology paired with an advanced selection of innovative fibers to create the ultimate in lightweight cut protection. The latest offering in our 21G line provides ANSI A4 cut resistance with unparalleled dexterity and extreme comfort that no other 21-gauge glove on the market can offer! Read More

  • Matrix's OmniPro Vision AI Collision Avoidance System

    OmniPro Vision AI is a state-of-the-art collision avoidance system that features NIOSH award-winning Visual Artificial Intelligence (AI) technology. This highly accurate, powerful system identifies and alerts on pedestrians, vehicles and specified objects, ensuring safer facilities, mining operations and industrial sites. With its web-based cloud application, OmniPro Vision AI also logs and analyzes a wide range of data related to zone breach notifications. Operating without needing personal wearable devices or tags, OmniPro has visual and audible zone breach alerts for both operators and pedestrians. Read More

  • NoiseCHEK Personal Noise Dosimeter

    SKC NoiseCHEK is the easiest-to-use dosimeter available! Designed specifically for OEHS professionals, SKC NoiseCHEK offers the easiest operation and accurate noise measurements. Everything you need is right in your palm. Pair Bluetooth models to your mobile devices and monitor workers remotely with the SmartWave dB app without interrupting workflow. Careful design features like a locking windscreen, sturdy clip, large front-lit display, bright status LEDs, and more make NoiseCHEK the top choice in noise dosimeters. Demo NoiseCHEK at AIHA Connect Booth 1003. Read More

Featured

Artificial Intelligence