CMU5XX-INFOSEC
Information Security for Industry
Session 8: The NIST Cyber Security Framework
Learning Objectives
- Explain the history, purpose, and structure of the NIST CSF.
- Deconstruct the five Core Functions: Identify, Protect, Detect, Respond, Recover.
- Map technical security controls to specific NIST subcategories.
- Utilize NIST Implementation Tiers to assess organizational maturity.
- Develop Current and Target Profiles to guide strategic security investments.
Seminar Structure (3 Hours)
Part 1: The Core Framework (1.5 hrs)
- Why NIST CSF? (The Rosetta Stone of Security)
- The Five Core Functions
- Task 1: Mapping Controls to the Core
Part 2: Tiers and Profiles (1.5 hrs)
- Assessing Maturity via Implementation Tiers
- Building a Target Profile
- Task 2: Developing a Target Profile
Part 1: The Core Framework
Duration: 1.5 Hours
Why the NIST CSF?
Created by the US National Institute of Standards and Technology to protect critical infrastructure.
- It provides a common language that both deeply technical engineers and non-technical board members can understand.
- It is not prescriptive. It doesn't tell you to buy a specific firewall; it tells you that you need a capability to "Protect" the network boundary.
- It acts as a translation layer, mapping high-level business goals down to specific technical standards (like ISO 27001 or COBIT).
The Five Core Functions
The highest level of abstraction. A lifecycle for managing risk.
- Identify: Understand what you have (Asset Management, Risk Assessment).
- Protect: Implement safeguards to ensure delivery of services (Access Control, Encryption, Training).
- Detect: Identify the occurrence of a cybersecurity event (Intrusion Detection, Log Monitoring).
- Respond: Take action regarding a detected incident (Containment, Mitigation).
- Recover: Restore capabilities impaired by the incident (Backups, Disaster Recovery).
Categories & Subcategories
Drilling down into the details.
- Each Function is broken down into Categories (e.g., Protect → Access Control (PR.AC)).
- Categories are broken down into Subcategories, which are specific outcomes. (e.g., PR.AC-1: Identities and credentials are managed.)
- Informative References: The framework then points to specific industry standards (like CIS Controls or ISO 27001) that explain exactly how to achieve PR.AC-1.
Introduction to Task 1
Security analysts must be able to categorize technical controls within the framework to identify gaps in coverage.
We will map real-world security technologies to the NIST CSF Core Functions.
Task 1: Mapping Controls to the Core
Timing: 45 minutes
Map the following four security controls/technologies to their primary NIST Core Function (Identify, Protect, Detect, Respond, Recover):
- A daily automated backup of the primary database sent to an off-site server.
- An automated script that disables user accounts immediately when HR changes their status to "Terminated".
- A Security Information and Event Management (SIEM) system analyzing firewall logs for anomalous traffic spikes.
- A configuration management database (CMDB) tracking all installed software versions.
Justify your mapping for each.
15 Minute Break
Please return promptly for Part 2.
Part 2: Tiers and Profiles
Duration: 1.5 Hours
Implementation Tiers (Maturity)
How rigorously is the organization managing its cybersecurity risk?
- Tier 1 (Partial): Reactive. Security is ad-hoc, undocumented, and relies on individual heroic efforts.
- Tier 2 (Risk Informed): Risk management practices are approved by management, but not implemented organization-wide.
- Tier 3 (Repeatable): Policies are formally established, implemented consistently, and updated regularly.
- Tier 4 (Adaptive): Continuous improvement. Active threat hunting. Adapting to changes in the threat landscape before an incident occurs.
Current vs Target Profiles
The mechanism for driving strategic change and securing budgets.
- Current Profile: An honest assessment of the organization's current capabilities mapped against the NIST subcategories. (e.g., "We currently have no endpoint detection capability - Detect is a gap.")
- Target Profile: The desired state of the organization based on its business goals and risk appetite. (e.g., "We want a fully managed EDR solution implemented within 12 months.")
- The Gap Analysis: The difference between the Current and Target profiles creates the roadmap and justifies the budget.
The Budget Conversation
Using the framework to secure funding.
- CFOs do not want to fund "more security." They want to fund "moving from a Tier 1 reactive state to a Tier 3 repeatable state in the 'Detect' function to meet compliance."
- The framework visually demonstrates to the board that the company is over-invested in "Protect" (Firewalls) but critically under-invested in "Recover" (Backups).
Introduction to Task 2
Performing a gap analysis requires evaluating business requirements and selecting the appropriate subcategories to prioritize.
We will draft a Target Profile to address a specific business vulnerability.
Task 2: Developing a Target Profile
Timing: 50 minutes
A regional bank has suffered several severe ransomware infections because employees keep clicking malicious attachments. Their Current Profile shows heavy investment in "Recover" (they restore from backups well) but near zero investment in "Protect" and "Detect".
- Select two specific NIST Categories (e.g., PR.AT - Awareness Training, DE.AE - Anomalies and Events) that should be prioritized in their Target Profile.
- For each chosen Category, propose one specific technical or administrative project required to achieve the Target Profile.
- Draft a one-sentence justification explaining to the board why funding these two projects will reduce the frequency of ransomware incidents.
Summary & Next Steps
- The NIST CSF is the global standard for organizing and measuring a cybersecurity program.
- It forces organizations to recognize that "Protect" is only one-fifth of the equation. You must assume breach and invest equally in Detect, Respond, and Recover.
Next Week: Enterprise Roles & Security Governance (The CISO and the Board)