Policies, Standards, and Procedures
The objective of the NIST CSF is to reduce the overall cyber risk for an organization. We reviewed the six functions of the CSF Coreand the NIST RMF in the last chapter. While we may think that the CSF is only meant for IT risk, it is also meant to reduce organizational risk. The RMF reflects this by going deep into the structure of organizational cyber risk.
The NIST RMF consists of several NIST Special Publications (SP) and the Federal Information Processing Standard (FIPS). This series of documents helps organizations to create cybersecurity programs that encompass risk reduction, incident response, and research. In this instance, we specifically looked at SP 800-37, SP 800-39, and FIPS 199. With these in mind, we learned how to implement, or at least start, a risk management program.
In this chapter, we will look at the development and enforcement of policies, standards, and procedures. Policies, Standards, and Procedures (PSP) are probably...