Featured Video
This Week in Quality Digest Live
Operations Features
Lolly Daskal
There are two kinds of pain—one that just hurts you, and another that teaches you
Gary Bell
Create better products and designs while saving money and reducing scrap
Mike Richman
An interview with industrial statistician Doug Fair, part 2
Naphtali Hoff
In many cases the leader is doing something very different than delegating
Gwendolyn Galsworth
It’s the pet of the local team, and it’s called the past

More Features

Operations News
‘There is nothing worse than creating a solution and then looking for a problem to solve with it.’
High-performance, 3D metrology value accessible to all industries
Real value unlocked by new designs, and by speed and flexibility of operations
Designed to hold delicate round parts without distortion for vision inspection
Transforming a dysfunctional industry
IoT platform uncovers insights into tooling optimization to enhance machine reliability for customers
Why not be the one with your head lights on while others are driving in the dark?
The FDA wants medical device manufactures to succeed, new technologies in supply chain managment
A new path for local hardware connectivity

More News

NIST

Operations

NIST Updates Risk Management Framework to Incorporate Privacy Considerations

Helps organizations assess and manage risks to their information and systems

Published: Monday, June 11, 2018 - 12:01

Augmenting its efforts to protect the nation’s critical assets from cybersecurity threats as well as protect individuals’ privacy, the National Institute of Standards and Technology (NIST) has issued a draft update to its Risk Management Framework (RMF) to help organizations more easily meet these goals.

The RMF update, formally titled “Draft NIST Special Publication (SP) 800-37 Revision 2,” is a guidance document designed to help organizations assess and manage risks to their information and systems. Previous versions of the RMF were primarily concerned with cybersecurity protections from external threats. The updated version adds an overarching concern for individuals’ privacy, helping to ensure that organizations can better identify and respond to these risks, including those associated with using individuals’ personally identifiable information.

The update will interest federal agencies and contractors that do business with them, as it connects the RMF with NIST’s well-known Cybersecurity Framework (CSF), highlighting relationships that exist between the two documents.

“Until now, federal agencies had been using the RMF and CSF separately,” says NIST’s Ron Ross, one of the publication’s authors. “The update provides cross-references so that organizations using the RMF can see where and how the CSF aligns with the current steps in the RMF. Conversely, if you’re using the CSF, you can bring in the RMF and give your organization a robust methodology to manage security and privacy risks.”

In addition to the RMF-CSF alignment, the update has several important objectives, including:

Integrating security and privacy into systems development. Building security and privacy into information systems during the initial design stage is a major concern. The RMF also references NIST systems security engineering guidance at appropriate points, including NIST’s SP 800-160, which addresses the engineering of trustworthy secure systems.

Connecting senior leaders to operations. The RMF provides guidance on how an organization’s senior leaders can better prepare for RMF execution, as well as how to communicate their protection plans and risk management strategies to system implementers and operators.

Incorporating supply-chain risk management considerations. The RMF addresses growing supply chain concerns in the areas of counterfeit components, tampering, theft, insertion of malicious software and hardware, poor manufacturing and development practices, and other potential harmful activities that can affect an organization’s systems and systems components.

Supporting security and privacy safeguards. The RMF update will provide organizations with a disciplined and structured process to select controls from the newly developed consolidated security and privacy control catalog in NIST’s SP 800-53, Revision 5.

Aligning the RMF with other NIST guidance and publications will provide clarity for federal agencies, which are required to implement multiple frameworks. Although adhering to the CSF is voluntary for private companies, its use for the federal government is mandatory under Executive Order 13800. Compliance with the RMF is mandatory for federal agencies in accordance with the Federal Information Security Modernization Act (FISMA). The RMF is also required and in widespread use in the Department of Defense and the intelligence community.

“It was imperative for us to figure out how these frameworks fit together,” says Ross. “Many agencies are trying to follow both.”

Ross added that the privacy-enhanced RMF might be valuable to companies and organizations beyond the federal government, considering how high profile the subject of privacy has become of late.

“Many folks are discovering how vulnerable they are with respect to their personal information and may begin to demand some standard level of protection,” he says. “If such a demand occurs, the government will be looking for clearly stated requirements for privacy, privacy safeguards, and a disciplined and structured process on how those controls could be applied. The timing of this publication could not be any better.”

NIST is accepting comments from the public on the draft RMF until June 22, 2018. A final version will be issued in October 2018.

Discuss

About The Author

NIST’s picture

NIST

Founded in 1901, The National Institute of Standards and Technology (NIST) is a nonregulatory federal agency within the U.S. Department of Commerce. Headquartered in Gaithersburg, Maryland, NIST’s mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life.