All NIST articles

  • /img/field/image/cybermazehome
    Article

    Understanding NIST’s new Risk Management Framework

    2019-02-08T11:15:00Z

    NIST’s new Risk Management Framework—used with the agency’s Cybersecurity Framework—offers companies direction in integrating cyber-security, privacy, and supply-chain risk management.

  • Article

    Interpreting the new NIST Cybersecurity Framework

    2018-05-01T12:45:00Z

    The National Institute of Standards and Technology has published an update to its widely adopted Cybersecurity Framework, implementing significant revisions.

  • Blog post

    NIST seeks comment on cyber-security framework update

    2017-01-25T14:15:00Z

    A leading framework for addressing cyber-security is getting an update, and the National Institutes of Standards and Technology is looking for input. Tammy Whitehouse reports.

  • AuditTechBackground
    Blog post

    CAQ: Audit’s role in cyber-security exams

    2016-09-15T20:45:00Z

    Public company auditors are suggesting that companies voluntarily submit to an independent cyber-security examination separate from the existing financial statement audit. Tammy Whitehouse explores a new process for examining and reporting on a company’s cyber-security risk management.

  • Article

    How to Simplify Cyber-Security Controls Amid Abundant Laws

    2015-07-14T11:30:00Z

    By now every compliance officer has already heard the warning that it’s a matter of when you suffer a cyber-security breach, not if. Then comes compliance with breach disclosure rules—and those demands are becoming as perplexing as the cyber-threat itself. Overwhelmed, compliance officers are seeking ways to navigate these demands ...

  • Article

    Eliminating Cyber-Threats From the IT Supply Chain

    2015-04-28T12:15:00Z

    Image: The longer a global supply chain grows, the less assurance corporations have in the integrity and security of their products and operations. Now NIST is trying to pierce that fog with new guidance, and compliance officers in the private sector might want to take notice. “Cyber-supply chain risk management ...

  • Article

    Smarter Assessments of Cyber-Risk

    2015-01-27T11:45:00Z

    Image: Every compliance and audit executive wants to manage cyber-security risks. That assumes, however, that the whole organization agrees on what a cyber-security risk is. Taxonomies do exist to build a more disciplined approach to cyber-security. Try to take all steps to manage all such risks, and “it’s going to ...

  • Article

    COSO Tacks Toward Cyber-Security

    2015-01-27T10:45:00Z

    As cyber-security works its way onto the corporate board agenda, COSO is suggesting ways that its frameworks for internal control and risk management can be a starting point for companies to anticipate fast-emerging risks. “Just as the board is responsible for enterprise risk management, this is very similar,” says Mike ...

  • Blog post

    Another Step Forward in Tackling Cyber-Security Risk

    2014-12-29T21:15:00Z

    Image: Dec. 31—COSO’s Internal Control — Integrated Framework talks a good game about being useful beyond financial reporting risks, but Compliance Week Editor Matt Kelly has always wondered how that works in practice. Then came a nifty piece of guidance: a taxonomy of operational risks in cyber-security, published by the ...

  • Blog post

    Bank CEOs, Boards Get Another Batch of Cyber-Security Help

    2014-12-17T13:15:00Z

    Bank CEOs and boards have a fresh batch of cyber-security guidance to evaluate. On Wednesday, The Conference of State Bank Supervisors released “Cybersecurity 101: A Resource Guide for Bank Executives,” a document that collects industry-recognized standards and best practices that are currently used within the financial services industry.