Technology Sectors

Market Sectors

NIST guide aims to set foundation for cyber risk assessment for infrastructure, law enforcement

NIST

The National Institute of Standards and Technology (NIST) released its final version of cyber risk assessment guidelines aimed at critical infrastructure entities, law enforcement and the military with information they need to secure their organization's information security and information technology infrastructures.

NIST intends the new risk assessment guidance released on Sept. 17 for leaders and executives at a variety of organizations, large and small, including financial institutions, health care providers, software developers, manufacturing companies, military planners and operators, and law enforcement groups.

The newest publication, the Guide for Conducting Risk Assessments, said NIST, completes the original series of five key computer security documents envisioned by the Joint Task Force -- a partnership of NIST, the Department of Defense, the Office of the Director of National Intelligence and the Committee on National Security Systems -- to create a unified information security framework for the federal government.

"Risk assessments are an important tool for managers," explains Ron Ross, NIST fellow and one of the authors of the newest guidance. "With the increasing breadth and depth of Cyber attacks on federal information systems and the U.S. critical infrastructure, risk assessments provide important information to guide and inform the selection of appropriate defensive measures so organizations can respond effectively to cyber-related risks."

Information technology risks include danger to the organization's operations (including, for example, missions and reputation), its critical assets such as data and physical property, and individuals who are part of or served by the organization, said the agency. In some cases, these risks extend to the nation as a whole, it said.

The newest release is a follow-up to a March 2011 NIST security release Managing Information Security Risk: Organization, Missions and Information System View (NIST Special Publication 800-39), that describes processes for managing information security risk for federal agencies and contractors. That process includes framing risk, assessing risk, responding to risk and monitoring risk over time, it said.

The Guide for Conducting Risk Assessments, focuses exclusively on risk assessment, which NIST said is the second step in the information security risk management process. The new guidance covers the four elements of a classic risk assessment: threats, vulnerabilities, impact to missions and business operations, and the likelihood of threat exploitation of vulnerabilities in information systems and their physical environment to cause harm or adverse consequences, it said.

"As the size and complexity of our collective IT infrastructure grows, we cannot protect everything we own or manage to the highest degree," says Ross. "Risk assessments show us where we are most at risk. It provides a way to decide where managers should focus their attention."

 

Upcoming Events

Event Details Dates of Event
SANS Austin 2013 May 19 - 24
DoD VA Healthcare Training Forum May 20 - 23
Transport and Logistics of Hazardous Material May 27 - 28
Southwest Microwave Seminar May 28 - 28
Border Management Southwest Summit May 29 - 31
Cyber Security Conference & Expo May 30 - 30
Mobile Device Security Summit 2013 May 30 - Jun 6
Security Analytics Summit 2013 May 30 - Jun 6
Cyber Security Conference & Expo May 30 - 30
Southwest Microwave Seminar May 30 - 30
SANS Malaysia @ MCMC 2013 Jun 3 - 8
2013 SIA Government Summit Jun 4 - 5
Southwest Microwave Seminar Jun 4 - 4
NCT: CBRNe Israel, 4 - 6 June 2013, Tel Aviv Jun 4 - 6
SEL Modern Solutions Power Systems Conference Jun 5 - 7
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21