Assessing the Latest Draft Cybersecurity Executive Order

Posted on May 6, 2017 at 11:13 am

The latest draft version of the Trump administration’s cybersecurity executive order is similar to the previous version and lays out a plan to secure U.S. federal government and critical infrastructure IT that could have come out of the Barack Obama White House, including modernizing federal IT. “That fact that they are focusing on IT modernization […]


NIST work on framework update quietly proceeds amid hubbub over Trump cyber agenda

Posted on May 1, 2017 at 11:22 am

The National Institute of Standards and Technology is diligently reviewing the nearly 130 comments from industry and other groups on a draft update to the framework of cybersecurity standards, as it prepares an analysis of that input in advance of a highly anticipated public meeting this month. That meeting will likely set the course and […]


Industry raises concerns with NIST approach to supply-chain risks in cyber framework update

Posted on April 26, 2017 at 11:23 am

Industry groups across sectors are raising concerns with various aspects of the National Institute of Standards and Technology’s approach to managing supply-chain risks in a proposed update to the voluntary framework of cybersecurity standards. Specifically, groups say the NIST plan fails to take into account the interconnectedness of vendor services and downplays the potential effect […]


Congress returns, but the real cybersecurity action is taking place off the Hill

Posted on April 24, 2017 at 11:26 am

Lawmakers return to Capitol Hill this week with a few cybersecurity items on the agenda for the upcoming legislative work period, while the most significant efforts in the coming months may be taking place at the White House and at the National Institute of Standards and Technology’s campus in suburban Maryland. “On the congressional front, […]


Business lobby pushes back on NIST Framework measurement plans

Posted on April 13, 2017 at 11:29 am

Business lobbying groups are pushing back on plans by federal scientists to add third-party measurement of cybersecurity to a voluntary framework designed to help private companies improve its defenses against hackers, cybercriminals and online spies. A draft proposed revision of the National Institute of Standards and Technology’s Cybersecurity Framework, to be known as version 1.1, […]


Internet Security Alliance: Framework metrics would help businesses prioritize efforts

Posted on April 12, 2017 at 11:31 am

The Internet Security Alliance is calling for metrics that allow businesses to prioritize their cybersecurity efforts based on the National Institute of Standards and Technology cybersecurity framework, while stressing the need for NIST and other agencies to continue promoting the voluntary, public-private partnership approach to cybersecurity. The comments come in response to a request for […]


Metrics abound, but who should be required to measure cyber effectiveness remains a key question

Posted on March 13, 2017 at 11:35 am

The government has suggested many ways to use metrics to measure the effectiveness of cybersecurity investments, but who should be using these measurement tools – and whether doing so should be required – remains open questions that will affect the scope and movement of these plans. Industry remains somewhat divided on the role of metrics, […]


Latest Executive Order Draft Promotes Risk-Based Approach

Posted on March 8, 2017 at 11:37 am

The latest version of the draft of a cybersecurity executive order from the Donald Trump White House would direct the federal government to take a risk-based approach to IT security and hold cabinet secretaries and agency heads responsible for the security of their organizations’ IT assets. The draft executive order also would require federal agencies […]


House bill requiring cyber audits by NIST could overhaul agency’s role

Posted on March 2, 2017 at 11:50 am

Having the National Institute of Standards and Technology audit other federal agencies’ cybersecurity practices is not a matter of NIST “stepping up” its game, as House Science Chairman Lamar Smith (R-TX) said this week – rather it would be a matter of dramatically redefining NIST’s role and relationship with other federal entities. The Science panel’s […]


Bill Seeks Metrics for NIST Cybersecurity Framework

Posted on February 28, 2017 at 11:42 am

Legislation calling on the National Institute of Standards and Technology to develop outcome metrics to demonstrate the effectiveness of the NIST Cybersecurity Framework is scheduled to be considered – and likely amended – at a markup session of the House Science, Space and Technology Committee on March 1. The measure, known as the NIST Cybersecurity […]