On May 11, 2017, the Executive Branch of the United States government (i.e., the White house) issued a new executive order on “Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure.” With several drafts available prior to the final release, this order contained few real surprises. Based on some of the media coverage, the reaction from the general cybersecurity community appears to be generally positive. Much of this support seems to be focused on the provisions of the order that focus on improving cybersecurity in various branches of the government.
However, given that the title of the order explicitly references “infrastructure cybersercurity,” it is important to recall that the majority of the national infrastructure is owned and operated by the private sector. While an executive order can direct government departments and resources, its impact on private companies is less clear.
It is for this reason that the focus on the NIST Cybersecurity Framework (CSF) is particularly important. NIST created the Framework as a response to the earlier Executive Order 13636, which was issued in February 2013. Since then, they have offered a range of supplemental guides and other tools to help promote adoption of the Framework in both the public and private sector. Most recently, NIST issued a Request for Comment (RFC), asking stakeholders for ideas on how to improve the Framework in a planned update called “Framework 1.1”. Their initial analysis of the responses received identified several specific themes, ranging from broadening the focus beyond critical infrastructure to the need for more attention on measurement.
If the focus of the framework is extended beyond critical infrastructure, and if much of this new emphasis is placed on government systems, then what does this mean for private sector asset owners? Do they currently have what they need from the Framework and its associated documents to guide them in securing their systems? If not, what other information or guidance may be required?
It is important that the authors of the Framework never intended to create any sort of standard. Although the initial executive order called for “… a set of industry standards and best practices to help organizations manage cybersecurity risks,” the authors chose to focus on the need to provide “…organization and structure to today’s multiple approaches to cybersecurity by assembling standards, guidelines, and practices that are working effectively in industry today.” Rather than trying to define a standard, the Framework references those standards and practices planned or already in place, mapping them to specific portions of an effective cybersecurity response.
Those standards have continued to evolve since the Framework was published four years ago, providing a valuable reference source for the specific requirements that must be met for ensuring security of critical systems. While it may be true that much remains to be done to coordinate and consolidate the response in the government sector, those in the private sector should not be distracted by this. They should continue to apply the Framework as a means of organizing their efforts. If and when the Framework is enhanced to address areas such as metrics and measurement, this new information can then be used to improve existing programs.