NIST and FTC
The five core functions of the NIST Cybersecurity Framework can be used by businesses to establish or enhance a data security program, examine current data security procedures, or communicate data security requirements to stakeholders. The Framework’s five core functions can also be used as a model by businesses of all sizes to conduct risk assessments and mitigation. And as the FTC’s enforcement actions demonstrate, businesses might have better protected the information of their customers if they had adhered to basic security procedures, such as those outlined in the Framework.
Additionally, given that the FTC’s enforcement actions are in line with the core functions of the Framework, businesses should read Start with Security, a publication from the FTC that outlines the lessons learned from the agency’s data security cases and offers helpful advice for lowering cybersecurity risks. The nation’s cybersecurity standard will be raised...