What is NIST CSF 2.0 and how it can help protect your business in the digital age

Share on facebook
Share on twitter
Share on linkedin

In today's world, where businesses are heavily supported by digital systems, cybersecurity is no longer a concern only for companies' technology teams, but has become a point of attention for the company as a whole. Having information or systems breached generates huge impacts on businesses, the image and reputation of companies, and can even cause losses to their customers. There are many cases of cyber attacks that have already been publicized in the media, and an even greater number of cases that have not been made public, despite all the efforts made by companies to keep their environments safe. This is because developing a cybersecurity strategy is a complex task that requires considering a series of factors, such as:

  • Data is the treasure of the digital world

This is an old statement, and it becomes increasingly true as businesses become based on digital platforms. The increase in the value of data naturally causes the number of theft attempts to intensify, and the levels of sophistication of attacks rise daily to circumvent the rules and technologies that are developed to contain them. Now, not all data has the same value and the same importance for the company, so the ideal would be to separate the wheat from the chaff, and employ protection and availability strategies according to the degree of importance of the data for the business. Although the logic of the reasoning makes sense, this is a task that is far from simple to carry out on a day-to-day basis in companies.

  • The area that the company needs to protect expands every day

In the not-so-distant past, IT security teams had to worry about ensuring that the perimeter of their data centers was protected against malicious access. But this scenario has changed significantly in the last decade, due to the evolution of public clouds, the growing adoption of co-location environments, and user mobility. Each of these items contributes significantly to expanding the perimeter that the company needs to protect. In addition to expanding the perimeter, many modern business applications have elements running in several different environments (the front-end runs on cloud A, the database on cloud B, and the back-end on on-premises servers, for example ). This means that, first, it is important to understand application architectures to understand application dependency relationships, and second, it is necessary to define a security strategy that serves the application in a uniform way, regardless of the environment where each part of it operates. reside.

  • The digital world, at the end of the day, is entirely supported by system codes

In this sense, the primary question is to understand how much these codes protect or expose us. Being very realistic, we don't have much control or in-depth knowledge about what's behind the codes. Cases have already been reported in which hackers injected malicious code into programs that, in theory, undergo strict quality controls. In many cases, hackers take advantage of vulnerabilities in software codes as gateways, which is why companies are constantly concerned about asking their users to keep their codes updated. If this is already complicated in the context of individuals, who can say in the business context where we have hundreds, thousands of systems and users.

  • The multiplicity and diversity of access by users

In many cases, users access corporate systems from multiple different devices. Workstation, notebook, cell phone, tablet, personal cell phone, personal notebook. If, on the one hand, the flexibility of using different devices brings more agility, on the other, it increases security vulnerability points. Each new device represents a new point of attack that needs to be addressed. But beyond the issue of the device is the user's understanding of their role in the company's cybersecurity strategy. It is ineffective to have a plan that addresses issues related to technology, if the user clicks on links that arrive in their email without due attention, or if they use open and “free” Wi-Fi networks when they are at the airport or at the cafe.

  • What we see on the public web is a small part of the total web world

If the volume of information and threats is large in the public domain environment of the web, it is even greater and more obscure in the worlds of the dark web and deep web. What type of information about the company or its main stakeholders circulates in this underground? How is this information obtained and used? Does the company need to have this concern? In theory yes, as we know that at the end of the day, it is precisely in this underworld where the largest volume of information trafficking occurs.

  • The disciplines and technologies involved in the cybersecurity scenario are numerous.

Here we are talking, according to the Momentum's CYBER SCAPE report in 27 different disciplines, with hundreds of companies, without considering the Storage and Backup disciplines, which today are a fundamental part of cybersecurity plans. Understanding the multiple disciplines and multiple solutions that each manufacturer has is neither a simple nor an easy task.

Given this scenario, the big question that remains is: how to create a cybersecurity plan that is aligned with the company's strategies and realities, and that is capable of mitigating the risks of attacks as much as possible and that guarantees an effective and quick recovery, in cases where mitigation mechanisms are not sufficient to block an attack?

Unfortunately, there is no definitive answer to this question, but there are methodologies, such as NIST CyberSecurity Framework, which can help companies structure a plan for this difficult mission – if you want to know NIST CSF in more depth, it's worth exploring the website https://www.nist.gov/cyberframework.

In the case of Columbia Integração, we adopted the NIST CSF as the framework to help our clients in the development and execution of their cybersecurity strategies, as it is a highly recognized framework in the market, due to its scope, adaptability and completeness. NIST CSF 2.0 is a set of guidelines developed by the United States National Institute of Standards and Technology (NIST) to assist organizations in managing and reducing their cyber risks. It is based on existing standards, guidelines and practices, and is flexible and scalable and can be adapted to the needs of organizations of all sizes and sectors.

The first version of the framework, CSF 1.0, was published in February 2014, in response to Executive Order 13636: “Improving Critical Infrastructure Cybersecurity, published the previous year. This Executive Order established the need to create a cybersecurity framework that would help protect US critical infrastructures, based on collaboration between government agencies, private companies and academic entities. In 2018, the framework underwent its first revision, with version CSF 1.1 being published, which made the framework more useful and inclusive for all types of organizations. In February 2024, the most recent version of the framework was published, version 2.0, which we will talk about in more detail throughout the text.

Very briefly, the NIST CSF 2.0 framework has 6 pillars at its core, as shown in the figure:

Below we will summarize each of the pillars.

GOVERNMENT: The GOVERN pillar is where the cybersecurity risk management strategy, expectations and policies are established, communicated and monitored. This pillar addresses topics such as:

  • Understanding and mapping specific cybersecurity needs
  • Development of a customized cybersecurity risk strategy.
  • Establishment of risk management policies
  • Development and communication of organizational cybersecurity practices
  • Establishment and monitoring of supply chain cybersecurity management
  • Implementation of supervision mechanisms and continuous checkpoints.

IDENTIFY: In the IDENTIFY pillar, the organization's current cybersecurity risks are understood, and the following points are addressed:

  • Identification of critical business processes and the assets that comprise them
  • Maintaining inventories of hardware, software, services and systems
  • Documentation of information flows
  • Identification of threats, vulnerabilities and risks to assets
  • Lessons learned are used to identify improvements

PROTECT: In the PROTECT pillar, this is where we establish safeguard mechanisms to manage the organization's cybersecurity risks. The following topics are addressed here:

  • Access management
  • User training
  • Device protection and monitoring
  • Protection of sensitive data
  • Software management and maintenance
  • Establishment of backup policies

DETECT: In the DETECT pillar, we define detection and analysis mechanisms for possible attacks and security compromises. In general, we address the following activities:

  • Continuous monitoring of networks, systems and physical environments to detect potentially adverse events
  • Determination and analysis of impacts and scope of adverse events
  • Sharing information about adverse events with authorized people and tools

RESPOND: In the RESPOND pillar, actions related to the handling of cybersecurity incidents are carried out. Among the activities contained in this pillar, we have:

  • Executing the incident response plan once the incident is declared
  • Categorizing and prioritizing incidents, and escalating or elevating them as needed
  • Collecting incident data and preserving its integrity and provenance
  • Notification to internal and external stakeholders about incidents and sharing of information, in accordance with the policies established by the company
  • Containment and eradication of incidents

RECOVER: In the RECOVER pillar, assets and operations affected by the cybersecurity incident are restored.

  • Understanding roles and responsibilities in recovery
  • Executing the recovery plan
  • Double checking the recovered data
  • Communication with internal and external stakeholders.

In addition to the framework's CORE structure, NIST CSF 2.0 has two other components, CSF ORGANIZATIONAL PROFILES and CSF TIERS.

The CSF ORGANIZATIONAL PROFILES describes the company's current and desired cybersecurity posture in terms of the CSF CORE deliverables. The interesting part of the framework is that it considers total customization of the plan, depending on the specific context of the company, its segment, its objectives and expectations. Also very relevant is the fact that the framework considers a continuous review of the plan, as it takes into account the possibilities for changes in the company and the entire cybersecurity environment over time. And finally, we have the CSF TIERS, which can be used by companies to inform their current and desired profile. TIERS characterize an organization's rigor in relation to risk governance and cybersecurity management practices. The TIERS classification is as follows:

  • TIER 1 – Partial: The application of the cybersecurity risk strategy is carried out on a timely basis, when necessary, and is not formally based on objectives or threat environments.
  • TIER 2 – Risk Informed: Risk management practices are approved by management, but may not be established as organizational policy. Prioritization of cybersecurity and protection activities is determined by considering business requirements, company risk objectives, or threat environment.
  • TIER 3 – Repeatable: The company's risk management practices are formally approved and expressed as company policies. Risk policies, processes and procedures are defined, implemented and reviewed. Cybersecurity practices are regularly updated, based on the application of risk management processes to business requirements, threats and the technological environment.
  • TIER 4 – Adaptive: There is a broad organizational approach to cybersecurity risk management that uses policies, processes and procedures to address potential cybersecurity events. The relationship between cybersecurity risks and organizational objectives are clearly understood and considered in decision-making. Executives monitor cybersecurity risks in the same way they monitor financial risks or any other type of risk to which the company is exposed. The company's budget is based on an understanding of the current and anticipated risk environment and risk tolerance. Cybersecurity risk management is part of the company's organizational culture.

As we can see, NIST CSF 2.0 provides a very useful guide for companies to use in formulating their cybersecurity strategies, to increase the security and resilience of their digital business environment. Columbia Integração has an extensive portfolio of services, solutions and partners that can help your company in the design and execution of its cybersecurity journey.

Do you want to know a little bit more? Contact us.

CONTACT US

CONTACT US