This is the introductory post in a series exploring how security ratings can address key aspects of the National Institutes of Standards and Technology’s (NIST) Framework for Improving Critical Infrastructure Cybersecurity. The purpose of these posts is to outline how security and risk professionals can leverage Bitsight’s ratings to drive better risk management through the lens of the NIST framework.
While the mega-breaches affecting retailers, healthcare organizations, and others continue to grab headlines, some cyber security threats and vulnerabilities are largely overlooked. One such issue is the security problems that affect our nation’s critical infrastructure. This infrastructure includes all virtual and physical assets and systems that are crucial to daily functioning of our way of life, or, as the Department of Homeland Security puts it, “We know it as the power we use in our homes, the water we drink, the transportation that moves us, and the communication systems we rely on to stay in touch with friends and family.”
Though it is hard to quantify the full extent of cyber threats to critical infrastructure, one Ponemon survey found that 70% of critical infrastructure firms had been breached in the last year. In order to address these issues, government officials and agencies government official and agencies have been looking for solutions to the growing problem of data security within the nation’s critical infrastructure. In February 2013, President Obama signed Executive Order 13636, mandating that all entities that fall within the nation’s critical infrastructure must adhere to a new cybersecurity framework put forth by National Institute of Standards and Technology (NIST). This framework provides five key core framework functions along with more specific categories that provide references to best practices from other guidelines, such as the Control Objectives for Information and Related Technology (COBIT), the ISA99 Industrial Automation and Control Systems Security, among others.