25. NIST 800-37 Rev 1 & 2 Flashcards
NIST 800-37 Rev 1 & 2
Tier 3:
Information Systems
- NIST 800-53 is found at Tier 3
- 6 step process for risk management lifecycle
NIST 800-37 Rev 1 & 2
7 major objectives updated in Rev 2.
- Provide closer linkage between risk management process and activities of C-suite
- Institutionalise critical risk management all risk management levels
- Demonstrate how NIST CSF can be aligned with RMF
- Integrate privacy risk management processes
- Promote/Develop trustworthy secure software and systems
- Integrate security-related supply chain risk management (SCRM)
- Organisation generated control selection approach to traditional baseline control selection
NIST 800-37 Rev 1 & 2
To provide closer linkage and communication between the risk management processes and activities at the C-suite
7 major objectives updated in Rev 2
- Senior Management Supports Initiative
- 2 way communication
NIST 800-37 Rev 1 & 2
To institutionalize critical risk management preparatory activities at all risk management levels.
7 major objectives updated in Rev 2
NIST 800-37 Rev 1 & 2
To demonstrate how the NIST Cybersecurity Framework [NIST CSF] can be aligned with the RMF and implemented using established NIST risk management processes
7 major objectives updated in Rev 2
Provides Defense in Depth
NIST 800-37 Rev 1 & 2
To integrate privacy risk management processes into the RMF to better support the privacy protection needs for which privacy programs are responsible
7 major objectives updated in Rev 2
NIST 800-37 Rev 1 & 2
To promote the development of trustworthy secure software and systems
7 major objectives updated in Rev 2
NIST 800-37 Rev 1 & 2
To integrate security-related, supply chain risk management (SCRM) concepts into the RMF
7 major objectives updated in Rev 2
Supply Chain Management is critical
- plans in place for mitigation i.e. when Datacenter breaks
- How to get back to normal operations
- Ensure redundancy for the things we need
NIST 800-37 Rev 1 & 2
To allow for an organization-generated control selection approach to complement the traditional baseline control selection approach and support the use of the consolidated control catalog in NIST Special Publication 800-53, Revision 5
7 major objectives updated in Rev 2
Make risk management processes more efficient, more effective, more cost effective
- Implement security in design
- Privacy requirements are in initial design i.e. SDLC
NIST 800-37 Rev 1 & 2
Cyber Security Framework
Ties all connecting frameworks / applications together