24. NIST 800-53 Flashcards
NIST 800-53
NIST 800-53 Rev. 5
Security and Privacy Controls for Infomration Systems and Organisations
- Detailed security controls for US Federal systems
- How to guides on ceate, operate and maintain security systems
- Comprehensive risk based approach to info Sec
- US government make this framework for their own systems
NIST 800-53
Exam Tip
Need to know high level publication;
Why, when, where, how, what
NIST 800-53
Public sector systems
Highly customizable framework
- Although NIST 800-53 rev 5 is for federal systems, it is customizable
- It is useful therefore for public sector systems
- Can select and implement controls, conduct risk assessements etc..
- pick and chose risk controls based on organisations risk appetite
NIST 800-53
Risk based approach
Organisation wide
Has a risk based approach to info sec
- looks at entire lifecycle - System, people, processes
- Does not focus purely on technical
NIST 800-53
Aligns with other NIST frameworks
- RMF - Risk Management Framework
- CSF - Cybersecurity Framework
NIST 800-53
Control Families
Specific aspect of security and privacy
- 20 control families in the publication i.e. AC = access control
NIST 800-53
Control Classes
- Management
- Operational
- Technical
- Management - strategic and tachnical level i.e. risk assessment, security planning, program management, policies
- Operational - day to day procedures i.e. controls related to personnel security, incident response, contingency planning
- Technical - Hands on technical focused i.e. access control, audit logs, system integrity
NIST 800-53
Baseline Controls
Minimum Level of Security
- Suggestions for basline levels based on the impact level
- i.e. low impact level, implement controls that are suitable for that system
- Select baseline controls based on risk tolerance, modify them to our needs, add organisation measures
NIST 800-53
Privacy Controls
New to Rev. 5
Included in revision 5
NIST 800-53
Outcome based approach
New to Rev. 5
This is the goal you want to achieve
This is how you get there
- provides flexibility to the organisation needs and risk tolerance
NIST 800-53
Supply Chain Management
New to Rev. 5
Source of major risk
- Companies use outsourcing and offshoring more
- Making the organisation aware of the risk associated with suppliers
- Monitor supplier security practices
- Plan for contingency if there is supply chain disruption
NIST 800-53
Protection against insider threats
New to Rev. 5
Threats from;
1. Employees
2. Contractors
3. Anyone inside who has access to data