NIST - National Institute of Standards and Technology
Agency within the U.S Department of Commerce - develops cybersecurity standards, guidelines, and best practices
Guideline or Resource | Purpose |
NIST Special Publication 800-101 | provides guidelines on Computer Forensic Tool Testing (CFTT); outlines methods for testing digital forensic tools to ensure they work as intended |
NIST Special Publication 800-86 | offers guidance on integrating forensic analysis into incident response; defines processes and tools for digital evidence collection |
NIST Special Publication 800-53 | provides a catalog of security and privacy controls for federal information systems, including digital forensics considerations |
NIST Digital Forensics Framework (DFF) | guides the acquisition, analysis, and presentation of digital evidence in compliance with NIST's standards and practices |
NIST National Software Reference Library (NSRL) | provides a repository of software, file profiles, and hash values for use in digital forensic investigations; helps identify known files |
NIST Cybersecurity Framework (CSF) | provides guidelines for performing security testing and assessments, which are often used in forensic investigations |
NIST Special Publication 800-115 | GPS data helps establish location at the time of a crime; supports alibis or proves presence at a crime scene |
NIST Forensic Tool Testing Reports | provides results and findings from the testing of various forensic tools to evaluate their accuracy and reliability |
NIST RMF (Risk Management Framework)
Categorize - what systems are utilized, their function, and potential impact → perform Risk Assessment for each system
Federal Information Processing Standards (FIPS) 199: categorize the impact (low, medium, high) of the compromise of CIA
ex. Confidentiality (high), Integrity (high), Availability (medium): Overall (high)
NIST SP 800-60: a catalog of information types and recommended categorizations
Select - choosing appropriate security controls based on the categorization of systems
NIST SP 800-53: security controls and enhancement catalog
Implement - integrate chosen security controls into the system
Assess - test chosen security controls for effectiveness at mitigating risk
NIST SP 800-53A: provides guidelines for assessing the effectiveness of security controls (practical guidance that should be tailored to each business)
ex. impact levels for: HR data, healthcare data, payment data, etc
Authorize - decide whether changes to system (implemented controls) are acceptable and should be committed
Security Authorization Package: formal set of documents and evidence used by an Authorizing Official (AO) to decide if a system is acceptable to use from a security risk perspective
Ensure all risks are identified, assessed, and accepted
DECISION = are the risks associated with the system acceptable within the context of risk appetite and business goals
Monitor - continuously monitor systems for effectiveness
Businesses should adapt continuous monitoring and ongoing authorization to keep up with changing environments
Federal and Industry Regulations
Federal Information Security Act (FISMA):
Health Insurance Portability and Accountability Act (HIPPA):
Payment Card Industry Data Security Standard (PCI DSS):
NIST CSF (Cybersecurity Framework)
Created in response for a standardized cybersecurity framework that would not implement more regulation on businesses
Core
Pillars of effective cybersecurity strategy
Govern - create an administrative system for cybersecurity management
Identify - determine possible outcomes and risks
Protect - prevent potential problems from happening
Detect - detect issues as they arise
Respond - implement corrective actions as needed
Recover - create a plan to correct any issues that could arise from risks
Tiers
Represents how well a business’s practices map onto the CSF
Tier 1: Partial - limited awareness of cybersecurity
Tier 2: Risk-Informed - awareness but lacks organized ways to implement cybersecurity
Tier 3: Repeatable - has cybersecurity baselines that they can recreate
Tier 4: Adaptive - has a comprehensive view of cybersecurity and the means to deal with challenges
*Not all organizations need to strive to be adaptive, only highly complex organizations or ones that deal with critical data
Profile
Aligns the CSF framework with the business’s goals and practices
Current Profile - represents the cybersecurity outcomes that the organization can achieve with the current setup
Target Profile - represents the cybersecurity outcomes that the organization wants to be able to meet
*Each profile is unique to each organization and depends on the industry, which regulations apply, risk appetite, etc.
NIST SP 800-53
Framework for selecting and implementing security controls
*Originally made for federal agencies but is now more widely used
Control Catalog - comprehensive list of controls designed for a wide range of cybersecurity risks
Control Enhancements - modifications to base controls for higher security
Control Assessments - ensure controls are implemented correctly and are effective
Control Families:
Access Control (AC)
Audit and Accountability (AU)
Incident Response (IR)
Risk Assessment (RA)
System and Communications Protection (SC)
(more)