NIST - National Institute of Standards and Technology

Agency within the U.S Department of Commerce - develops cybersecurity standards, guidelines, and best practices

Guideline or Resource

Purpose

NIST Special Publication 800-101

provides guidelines on Computer Forensic Tool Testing (CFTT); outlines methods for testing digital forensic tools to ensure they work as intended 

NIST Special Publication 800-86 

offers guidance on integrating forensic analysis into incident response; defines processes and tools for digital evidence collection

NIST Special Publication 800-53

provides a catalog of security and privacy controls for federal information systems, including digital forensics considerations

NIST Digital Forensics Framework (DFF) 

guides the acquisition, analysis, and presentation of digital evidence in compliance with NIST's standards and practices

NIST National Software Reference Library (NSRL) 

provides a repository of software, file profiles, and hash values for use in digital forensic investigations; helps identify known files 

NIST Cybersecurity Framework (CSF) 

provides guidelines for performing security testing and assessments, which are often used in forensic investigations 

NIST Special Publication 800-115

    GPS data helps establish location at the time of a crime; supports alibis or proves presence at a crime scene 

NIST Forensic Tool Testing Reports 

provides results and findings from the testing of various forensic tools to evaluate their accuracy and reliability 

NIST RMF (Risk Management Framework)

  1. Categorize - what systems are utilized, their function, and potential impact → perform Risk Assessment for each system

    • Federal Information Processing Standards (FIPS) 199: categorize the impact (low, medium, high) of the compromise of CIA

      • ex. Confidentiality (high), Integrity (high), Availability (medium): Overall (high)

    • NIST SP 800-60: a catalog of information types and recommended categorizations

  2. Select - choosing appropriate security controls based on the categorization of systems

    • NIST SP 800-53: security controls and enhancement catalog

  3. Implement - integrate chosen security controls into the system

  4. Assess - test chosen security controls for effectiveness at mitigating risk

    • NIST SP 800-53A: provides guidelines for assessing the effectiveness of security controls (practical guidance that should be tailored to each business)

      • ex. impact levels for: HR data, healthcare data, payment data, etc

  5. Authorize - decide whether changes to system (implemented controls) are acceptable and should be committed

    • Security Authorization Package: formal set of documents and evidence used by an Authorizing Official (AO) to decide if a system is acceptable to use from a security risk perspective

      • Ensure all risks are identified, assessed, and accepted

      • DECISION = are the risks associated with the system acceptable within the context of risk appetite and business goals

  6. Monitor - continuously monitor systems for effectiveness

    • Businesses should adapt continuous monitoring and ongoing authorization to keep up with changing environments

Federal and Industry Regulations

  • Federal Information Security Act (FISMA):

  • Health Insurance Portability and Accountability Act (HIPPA):

  • Payment Card Industry Data Security Standard (PCI DSS):

NIST CSF (Cybersecurity Framework)

Created in response for a standardized cybersecurity framework that would not implement more regulation on businesses

Core

Pillars of effective cybersecurity strategy

Govern - create an administrative system for cybersecurity management

Identify - determine possible outcomes and risks

Protect - prevent potential problems from happening

Detect - detect issues as they arise

Respond - implement corrective actions as needed

Recover - create a plan to correct any issues that could arise from risks

Tiers

Represents how well a business’s practices map onto the CSF

Tier 1: Partial - limited awareness of cybersecurity

Tier 2: Risk-Informed - awareness but lacks organized ways to implement cybersecurity

Tier 3: Repeatable - has cybersecurity baselines that they can recreate

Tier 4: Adaptive - has a comprehensive view of cybersecurity and the means to deal with challenges

*Not all organizations need to strive to be adaptive, only highly complex organizations or ones that deal with critical data

Profile

Aligns the CSF framework with the business’s goals and practices

Current Profile - represents the cybersecurity outcomes that the organization can achieve with the current setup

Target Profile - represents the cybersecurity outcomes that the organization wants to be able to meet

*Each profile is unique to each organization and depends on the industry, which regulations apply, risk appetite, etc.

NIST SP 800-53

Framework for selecting and implementing security controls

*Originally made for federal agencies but is now more widely used

  • Control Catalog - comprehensive list of controls designed for a wide range of cybersecurity risks

  • Control Enhancements - modifications to base controls for higher security

  • Control Assessments - ensure controls are implemented correctly and are effective

Control Families:

  • Access Control (AC)

  • Audit and Accountability (AU)

  • Incident Response (IR)

  • Risk Assessment (RA)

  • System and Communications Protection (SC)

  • (more)