Skip to content

Menu

ChannelsPublishersSubscribe
LexBlog, Inc. logo
LexBlog, Inc. logo
ProductsSub-MenuBlogsPortalsTwentySyndicationMicrositesResource Center
Join
Search
Close
Join the Movement. Blog 4 Good

NIST releases latest version of its Cybersecurity Framework

By Kim Gold (US) & Robert Kantrowitz (US)
April 19, 2018
EmailTweetLikeLinkedIn
Cybersecurity
Cybersecurity

On April 16, 2018, the National Institute of Standards and Technology (NIST) unveiled Version 1.1 of its widely known Cybersecurity Framework, which incorporates changes based on feedback collected through comments, questions, and workshops held in 2016 and 2017.

The Cybersecurity Framework aims to focus on industries vital to national and economic security, including energy, banking, communications, and defense, and provides a universal structure that can be tailored to varied methods of cybersecurity by compiling effective standards, guidelines, and practices into one framework.

The new version includes updates on:

  • authentication and identity;
  • self-assessing cybersecurity risk;
  • managing cybersecurity within the supply chain; and
  • vulnerability disclosure.

The Cybersecurity Framework is voluntarily adoptable by large and small entities across all industries, and it can assist organizations address privacy issues related to customers, employees, patients, and other parties.

The Cybersecurity Framework is particularly beneficial to the healthcare industry. Many healthcare entities, such as research institutions, have successfully implemented the standards set forth in the Cybersecurity Framework to help them comply with HIPAA. While the HIPAA Security Rule does not require use of the Cybersecurity Framework, many covered entities and business associates have adopted the Cybersecurity Framework to enhance their cybersecurity programs and implement appropriate security measures to protect ePHI.

Continued engagement and collaboration with stakeholders will progress as the Cybersecurity Framework further develops. It “will need to evolve as threats, technologies and industries evolve,” said Matt Barrett, program manager for the Cybersecurity Framework. To further assist companies, NIST plans to release an updated companion document, the Roadmap for Improving Critical Infrastructure Cybersecurity, which will elaborate on key areas of development, alignment, and collaboration. Additionally, NIST will host a webcast explaining the Cybersecurity Framework on April 27, 2018, at 1 p.m. Eastern time, and a Cybersecurity Risk Management Conference on November 6-8, 2018, in Baltimore, Maryland. Detailed information on the conference will soon be available on the NIST website.

Photo of Kim Gold (US) Kim Gold (US)
Read more about Kim Gold (US)Email Kim's Linkedin Profile
Photo of Robert Kantrowitz (US) Robert Kantrowitz (US)
Read more about Robert Kantrowitz (US)Email Robert's Linkedin Profile
  • Posted in:
    Privacy & Data Security
  • Blog:
    Data Protection Report
  • Organization:
    Norton Rose Fulbright
  • Article: View Original Source

Stay Connected

Facebook LinkedIn Twitter RSS
Real Lawyers

Company

  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service

Products

  • Products
  • Blogs
  • Portals
  • Twenty
  • Syndication
  • Microsites

Support

  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center

New to the Network

  • Redefined Blog
  • Global Trade Law Blog
  • The Quick Take
  • Consumer Privacy World
  • Energy Law Report
Copyright © 2021, LexBlog, Inc. All Rights Reserved.
Powered By LexBlog