NIST Publishes Draft Update to Cybersecurity Framework | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

NIST Publishes Draft Update to Cybersecurity Framework

January 12, 2017
by Heather Landi
| Reprints
Click To View Gallery

The National Institute of Standards and Technology (NIST) has published proposed updates to the Framework for Improving Critical Infrastructure Cybersecurity—also known as the Cybersecurity Framework.

Considered the federal gold standard for cybersecurity, the NIST Cybersecurity Framework provides guidance to healthcare organizations and other industries on reducing cybersecurity risks.

The updated framework provides new details on managing cyber supply chain risks, clarifying key terms, and introducing measurement methods for cybersecurity, according to NIST.

The Cybersecurity Framework was published in February 2014 following a collaborative process involving industry, academia and government agencies, as directed by a presidential executive order. The original goal was to develop a voluntary framework to help organizations manage cybersecurity risk in the nation’s critical infrastructure, such as bridges and the electric power grid, but the framework has been widely adopted by many types of organizations across the country and around the world. The Cybersecurity Enhancement Act of 2014 calls for NIST to continue its work on the framework.

The 2017 draft Framework for Improving Critical Infrastructure Cybersecurity Version 1.1 incorporates feedback since the release of framework version 1.0, and integrates comments from the December 2015 Request for Information as well as comments from attendees at the Cybersecurity Framework Workshop 2016 held at the NIST campus in Gaithersburg, Maryland.

“We wrote this update to refine and enhance the original document and to make it easier to use,” Matt Barrett, NIST’s program manager for the Cybersecurity Framework, said in a statement. “This update is fully compatible with the original framework, and the framework remains voluntary and flexible to adaptation.”

To assist users wanting to apply the framework to cyber supply chain risk management, the authors developed a vocabulary so all organizations working together on a project can clearly understand cybersecurity needs. Examples of cyber supply chain risk management include a small business selecting a cloud service provider or a federal agency contracting with a system integrator to build an IT system.

In the renamed and revised “Identity Management and Access Control” category, the draft clarifies and expands the definitions of the terms “authentication” and “authorization.” Authors also added and defined the related concept of “identity proofing.”

“In the update we introduce the notion of cybersecurity measurement to get the conversation started,” Barrett said. “Measurements will be critical to ensure that cybersecurity receives proper consideration in a larger enterprise risk management discussion.”

The deadline to send comments on the draft Framework for Improving Critical Infrastructure Cybersecurity Version 1.1 is April 10, 2017 and comments can be submitted to cyberframework@nist.gov.

 

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More

Topics

News

Study will Leverage Connecticut HIE to Help Prevent Suicides

A new study will aim to leverage CTHealthLink, a physician-led health information exchange (HIE) in Connecticut, to help identify the factors leading to suicide and to ultimately help prevent those deaths.

Duke Health First to Achieve HIMSS Stage 7 Rating in Analytics

North Carolina-based Duke Health has become the first U.S. healthcare institution to be awarded the highest honor for analytic capabilities by HIMSS Analytics.

NIH Releases First Dataset from Adolescent Brain Development Study

The National Institutes of Health (NIH) announced the release of the first dataset from the Adolescent Brain Cognitive Development (ABCD) study, which will enable scientists to conduct research on the many factors that influence brain, cognitive, social, and emotional development.

Boston Children's Accelerates Data-Driven Approach to Clinical Research

In an effort to bring a more data-driven approach to clinical research, Boston Children’s Hospital has joined the TriNetX global health research network.

Paper Records, Films Most Common Type of Healthcare Data Breach, Study Finds

Despite the high level of hospital adoption of electronic health records and federal incentives to do so, paper and films were the most frequent location of breached data in hospitals, according to a recent study.

AHA Appoints Senior Advisor for Cybersecurity and Risk

The American Hospital Association (AHA) has announced that John Riggi has joined the association as senior advisor for cybersecurity and risk.