NIST releases its Risk Management Framework 2.0
By MYBRANDBOOK
The National Institute of Standards and Technology posted the newest update to its Risk Management Framework.
“RMF 2.0 is the first framework in the world to address security, privacy, and supply chain risk in an integrated manner - at the organization, mission/business process, and system levels,” NIST Fellow Ron Ross wrote in a Twitter post.
RMF 2.0’s full name is the NIST Special Publication 800-37 Revision 2, Risk Management Framework (RMF) for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy.
NIST said RMF 2.0 adds a step called Prepare and includes seven major objectives.
Prepare is intended to help organizations facilitate effective communication between executives and employees. It also guides users to enable enterprise-wide identification of privacy and security controls, reduce complexity of IT systems and applications, eliminate unnecessary functions and, ultimately prioritize resources for high value assets and protect those accordingly.
NIST listed the seven objectives of the Risk Management Framework -
1. Provide closer linkage and communication to top executives and governance-level employees and the rest of the organization
2. Create critical risk management preparatory activities at all necessary levels
3. Show how the NIST Cybersecurity Framework can be aligned with the RMF
4. Include privacy risk management in the RMF
5. Promote trustworthy secure systems by aligning the RMF with NIST framework for engineering such secure systems
6. Integrate supply chain risk management concepts into the RMF
7. Enable organizations to generate a “control selection approach” as a complement to NIST SP 800-53 Revision 5 consolidated control catalog.
“By achieving the above objectives, organizations can simplify RMF execution, employ innovative approaches for managing risk, and increase the level of automation when carrying out specific tasks,” NIST added.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
TEJAS NETWORKS INDIA PVT. LTD.
SECUREYE SERVICES PVT. LTD.
DIGISOL SYSTEMS LTD.
TATA CONSULTANCY SERVICES
Icons Of India : MUKESH D. AMBANI
Mukesh Dhirubhai Ambani is an Indian businessman and the chairman and ...
ICONS OF INDIA : VINAY SINHA
Vinay Sinha is the Managing Director of Sales for the India Mega Regio...
Icons Of India : Kumar Mangalam Birla
Aditya Birla Group chairman Kumar Mangalam Birla recently made a comeb...
RailTel Corporation of India Limited
RailTel is a leading telecommunications infrastructure provider in Ind...
STPI - Software Technology Parks of India
STPI promotes and facilitates the growth of the IT and ITES industry i...
UIDAI - Unique Identification Authority of India
UIDAI and the Aadhaar system represent a significant milestone in Indi...
Indian Tech Talent Excelling The Tech World - PADMASREE WARRIOR, Founder, President & CEO - Fable
Padmasree Warrior, the Founder, President, and CEO of Fable, is revolu...
Indian Tech Talent Excelling The Tech World - Shantanu Narayen, CEO- Adobe Systems Incorporated
Shantanu Narayen, CEO of Adobe Systems Incorporated, is renowned for h...
Indian Tech Talent Excelling The Tech World - Sundar Pichai, CEO- Alphabet Inc.
Sundar Pichai, the CEO of Google and its parent company Alphabet Inc.,...