WASHINGTON – Today, 91¿ì»îÁÖ welcomed the release by the National Institute of Standards and Technology (NIST) of a Request for Information (RFI) to consider Evaluating and Improving NIST Cybersecurity Resources: The Cybersecurity Framework and Cybersecurity Supply Chain Risk Management. The centerpiece of the proposed update would be a new version of NIST’s Framework for Improving Critical Infrastructure Cybersecurity, a voluntary, consensus-based tool grounded in international standards that helps organizations of all sizes bolster their cyber posture and manage cyber risks.
“We welcome NIST’s efforts to update its existing Cybersecurity Framework to reflect the evolving landscape of cybersecurity risks, technologies and resources and increasing its global compatibility,” said John Miller, Senior Vice President of Policy and General Counsel at 91¿ì»îÁÖ. “We appreciate NIST’s focus on more fully integrating cyber supply chain risk management efforts with both the existing Framework and other ongoing efforts, including other existing risk management frameworks, such as the Privacy Framework, and new efforts such as the National Initiative for Improving Cybersecurity in Supply Chains (NIICS). NIST’s proposed update is not only timely due to the rapid growth and increasing frequency of threats to critical infrastructure, but serves to reinforce the value of the Framework as a communication and education tool and central resource around which to orient and align numerous other ongoing cybersecurity and risk management efforts, including implementation of the Cybersecurity Executive Order. We are pleased that NIST is soliciting the views of industry and other stakeholders at the very beginning of this process, as it has done with previous versions of the Framework. We look forward to working with NIST to advance this effort in a timely manner to ensure that the new version continues to serve as an effective cybersecurity and cyber supply chain risk management tool for organizations.”