×

NIST- National Institute of Standard and technology

This security standard or framework was founded in 1901 and designed to protect data. It consists of several guidelines that help companies protect government data and establish standards and technology applied to the science and technology industries.

The National Institute of Standard and Technology is the oldest science lab in the United States (part of the U.S. Department of Commerce) which has a major impact on the public and private sectors of the business.

NIST provides a level of uniformity that provides a standard of data safety insurance. NIST has a five-step process that provides surety to this security standard. With these steps, NIST can be applied to a system.

  1. Identity – This identification function manages cyber security risks to people, systems, assets, capabilities, and data in an effective cyber security program. This function identifies physical and software assets, organization business environment, vulnerabilities, internal and external threats to organizational resources, and supply chain management strategies (including risk tolerance, constraints, priorities, and assumptions that support risk decisions in managing supply chain risk). Business context-related cyber security risks, identifying risk, establishing risk management strategies, and finding resources that support critical functions.
  2. Protect – This protection function of NIST safeguards the delivery of critical infrastructure services: Implementation of procedure and process to manage and maintain the protection of asset and information system, physical and remote access of system. It protects remote maintenance activities, security, and security resilience, including organizational policies, agreements, and procedures. The protection function is implemented for the protection of identity management.
  3. Detect – Detect function finds the anomalies and some of the activities used to identify the occurrence of a cyber-security event promptly. All the events with their potential impacts are detected and understood. It also has capabilities that monitor cyber security events and provide preventive measures, including physical and network activities. 
  4. Respond – After detecting a cyber security incident, the respond function in NIST takes action and executes the response planning process during and after an incident. Respond function does:
    - Analyses the incident and provides an effective response
    - Manage all the communication during and after an event with internal and external stakeholders.
    -Support recovery activities and perform migration activities
    -Determine the impact of incidents
  5. Recover – To reduce the impact of a cyber-security event/ attack recovery function is implemented to restore the impaired services or capabilities due to a cyber security event. It maintains and renews plans for resilience that implement improvements with recovery plans and procedures to recover the system.            

NIST is taken as a gold standard for creating a cyber-security program. This framework provides users with a top-level security management tool, including a uniform set of rules and guidelines for an organization that help access cyber security risks across the business.

The best method to protect data with NIST compliance standards is to use a compliant file sharing solution because it helps organizations build and n improve their cyber security posture.

So NIST framework objective is to provide a framework that handles risk and vulnerabilities and protect an accurate inventory of assets that help users prioritize cyber security investments and decisions taken by the board of director and senior management. With the help of NIST stakeholders, the board of directors or senior management communicate with each other. Different types or versions of NIST are:

NIST SP 800-53NIST SP 800 was published in 1990 to address every aspect of information security, especially cloud security. It is widely used in the private sector and is a security benchmark for U.S. government agencies.  
NIST 800-115This standard is known as Technical Guide to Information Security Testing and Assessment and is also an important standard for accessing the I.T. system.
NIST SP 800-71Cybercriminals frequent attack the government contractors due to their proximity to federal information systems. Subcontractors and government manufacturers use this I.T. security framework to bid on state and federal business opportunities. The U.S. government has set this framework by the U.S. Department of defense regarding contractor compliance with the security framework. NIST SP 800-71 framework is related to NIST SP 800-53; therefore, it is possible to build a crosswalk between both standards, but NIST SP 800-71 is more generalized and used as a secure base for some organizations by using additional controls included in NIST SP 800-53.
NIST CSFThis NIST framework was also developed to improve critical cyber security to address U.S. critical infrastructure, food supplies, health care delivery, and water supplies, including energy production, communication, and transportation. These essential industries maintain a high level of preparedness, and for this NIST CSF framework was developed under executive order 13636, released in February 2013. It deals with risk management and analysis. It works on the five phases of risk management, i.e., identity, protect, detect, respond and cover, which require the support of senior management. This framework is utilized by both the private and public sectors.   
NIST SP 1800 SeriesIt complements the series of standards and framework NIST  SP 800 focuses on how to apply and implement standard-based cyber security technologies in real-world applications. It provides examples of specific capabilities and their implementation by modular guidance for organizations of all kinds and sizes. It tells the method of approaching multiple products to achieve the desired results based on experience. It also defines the need for component and installation, integration, and configuration information, due to which organizations easily replicate the process itself. 

Conclusion: National Information Security Technology standard is a U.S.-based agency that works in the cyber security field and publishes cybersecurity-related standards. Different countries across the globe follow NIST standards.


Related Topics

Cyber Attackers

An attacker can be a single person or a group of individuals with goals, motivation, and capabilities. As a coin has two faces same attackers have, some attacker does attack...

5 minutes read.

Email Spoofing

Introduction Email spoofing is a technique related to phishing email attacks where an attacker uses an email header to forge the email to target the victim. Emails are created with a...

8 minutes read.

Role of artificial engineering in cyber security

Introduction In dealing with and surviving in the digital era, cyber security is the major requirement in protecting confidential data and providing integrity and availability of data. Cyber security is designed...

10 minutes read.

Cyber Security Identity and Access Management

Identity and access management is a framework of business processes that provide a facility for digital Identity. It is also abbreviated as IAM. Its main work is to provide restricted...

6 minutes read.

PCI DSS Standard

Payment cards like credit and debit were designed to ease the payment option for the user whenever, wherever they pay; even when they don't have enough credit, they can pay...

5 minutes read.

Jobs and roles in cyber security

Cyber security is one of the booming careers and desired fields in the cyber industry. Cyber security is a vast ocean of knowledge and a big domain that consists of...

7 minutes read.

Canary in Cyber security

Introduction Cyber security is meant to provide security to the cyber/ internet/ IT world. It aims to secure the organization against cyber-attacks by using various security products. Not just data, applications...

5 minutes read.

Types of security policies

Policies act as a protection field for the business, organization, and individual users to allow them and protect their rights. Security policies are meant to provide security for the technology...

9 minutes read.

FINRA

Introduction Payment cards need PCI DSS standard for security, but apart from it, there are other financial services like share market, stocks, bonds, etc. require security. So, for this, security experts...

9 minutes read.

Eavesdropping attack in cyber security

Introduction Eavesdropping is a technique of finding someone's conversation details for personal benefit. When an ongoing communication between two people is interrupted, or a third person tries to listen to that...

6 minutes read.

Applications of cyber security

Cyber security terms define the process of safeguard implemented on the device that working in a network (online) is safe and secure. In this digital era, personal and private networks,...

4 minutes read.

Identification of security vulnerability

To remove vulnerabilities and make the business strong, it is necessary to identify the security vulnerabilities because if we know the ways of identification and easily handle the risk of...

4 minutes read.

What is Phishing?

Introduction Cyber security always tries to protect organizations or individuals from cyber-attacks by improving itself according to the latest trend and technologies. Still, some easiest and cheapest ways are used by...

11 minutes read.

Importance of cyber security in education sector

Education is the necessity of human beings and the most prominent and growing industry in businesses and commercial establishments everywhere. Educational institutes are increasingly fast, and with the merger of...

6 minutes read.

Functions of Cyber Security

Let’s learn about the Cybersecurity Framework's five Functions that are the key pillars of wholistic and successful cyber security programs. These five functions result from the highest level of abstraction...

3 minutes read.

Cyber Security job qualifications

Requirements and Responsibilities for Cybersecurity Entry-Level Jobs The thread to the network and computer are increasing rapidly every day with the internet and technology. Cyber attackers compromise large companies' confidential information...

3 minutes read.

Digital signature

A signature is the authoritative power of a person and is done on paper. Before digitization, a signature done by a human physically by hand was given preference, whereas the...

11 minutes read.

Cyber Criminals

Every day, we hear about multiple cyber-crimes that occur in our surroundings, executed and accomplished by criminals named cybercriminals. Cyber-criminal is one the type of criminal; the only difference is...

4 minutes read.

Cyber security tools

Cyber security is an essential part of the internet industry to protect confidential data and financial records, and a system needs security. Cyber security analysts provide various tools to keep...

16 minutes read.

Difference between Spoofing and Phishing

Spoofing – A cyber-attack in which the attacker tries to steal the identity of a legitimate user and act as another person. Spoofing is a type of identity theft used...

3 minutes read.