Date Published: January 2017
Comments Due: April 10, 2017 (public comment period is CLOSED)
Email Questions to: cyberframework@nist.gov
On January 10, 2017, NIST released proposed updates to the Cybersecurity Framework. This draft Version 1.1 of the Cybersecurity Framework seeks to clarify, refine, and enhance the Framework, making it easier to use. Updates were derived from feedback NIST received since the publication of Cybersecurity Framework Version 1.0, including responses to a December 2015 Request for Information (RFI), Views on the Framework for Improving Critical Infrastructure Cybersecurity, and discourse at Cybersecurity Framework Workshop 2016. More information can be found at the Cybersecurity Framework site.
See the "Note to Reviewers on the Update and Next Steps" on pp. ii-iii for additional review guidance.
Access Control; Audit and Accountability; Awareness and Training; Configuration Management; Contingency Planning; Identification and Authentication; Incident Response; Maintenance; Media Protection; Personnel Security; Physical and Environmental Protection; Planning; Program Management; Risk Assessment; Assessment, Authorization and Monitoring; System and Communications Protection; System and Information Integrity; System and Services Acquisition
Publication:
Draft Cybersecurity Framework v1.1 (with markup)
Supplemental Material:
Draft Cybersecurity Framework v1.1 (no markup) (pdf)
Draft Cybersecurity Framework v1.1 Core (xls)
Cybersecurity Framework Draft v1.1 homepage (other)
Document History:
01/10/17: White Paper (Draft)
12/05/17: White Paper (Draft)
04/16/18: White Paper (Final)
Security and Privacy
audit & accountability; awareness training & education; contingency planning; maintenance; risk assessment; system authorization
Applications
cybersecurity framework
Laws and Regulations
Comprehensive National Cybersecurity Initiative; Cybersecurity Enhancement Act; Executive Order 13636; Homeland Security Presidential Directive 7