|
|
By Michael Ahmad
|
The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) is a set of best practices and recommendations developed to facilitate the identification, management, and reduction of cybersecurity risks to organizations. The CSF breaks down high-level cybersecurity outcomes into three levels of increasing detail (functions, subcategories, and categories) and provides supplemental resources to help organizations evaluate cybersecurity posture, determine areas of focus, and realize security objectives by leveraging implementation examples.
NIST introduced an additional core function with the release of CSF Version 2.0, which features a new aspect, Govern. Govern highlights the importance of leadership, strategy, and oversight in building resilient cybersecurity programs. This most recent revision also places a heightened emphasis on supply chain risks and privacy considerations compared to the previous version.
Texas RE encourages Responsible Entities to refer to the NIST Cybersecurity Framework Version 2.0 for more information on cybersecurity risk management.
