Three years after President Barack Obama issued an executive order to improve the cybersecurity of critical infrastructure, the guiding document behind the majority of those efforts in both the public and private sector is due for an update, so long as it’s done correctly.
That was the general sentiment of government and industry stakeholders on a proposed update to the Framework for Improving Critical Infrastructure Cybersecurity, a two-year-old document that sets the standard for securing infrastructure — from power plants to banking — from the effects of cyberattacks.
Download: Analysis of Cybersecurity Framework RFI Responses
The National Institute of Standards and Technology (NIST), which created the document, put out a request for information in December asking organizations to respond with how they use the framework and what changes they’d like to see. NIST received more than 100 responses to the RFI and used those comments for their analysis.
“We received 105 comments from a diverse group that included local, state national and international governments, a cross section of the critical infrastructure community and a number of other types of organizations,” said Matthew Barrett, program manager for the framework.
Barrett pointed out that the number of comments actually belies the breadth of perspective offered by the responses.
“The responses actually represent thousands of organizations because a large number of industry organizations submitted comments on behalf of all of their member companies,” he said. “These comments provide strong input for the framework’s future and revealed that the number of organizations using the framework is growing.”
NIST researchers split into groups to analyze the responses and consolidated the comments into 10 themes, summarized below. The full analysis can be found in the download link above.
Framework update timeline: There were diverse comments on whether an update is necessary or desirable.
Update to framework content: Many respondents had specific suggestions of ways to update and expand the framework.
Update process: The framework should be updated through a collaborative process and with minimal disruption to current industry use.
Framework governance: Respondents are comfortable with NIST’s continued leadership in the framework process, though transition should be considered at a later date.
Optimal industry leadership: Any possible future steward of the framework should be a respected, internationally recognized, neutral third-party organization.
Industry resources: Industry resources are useful but additional guidance is needed, especially for small and medium-sized businesses.
Challenges in sharing best practices: There is a need for additional sharing of best practices surrounding the use of the framework.
Regulation: Many users of the framework say that regulation is a necessary consideration in the development of their cybersecurity programs and caution about the potential negative impact of additional regulatory requirements.
International Alignment: The framework is gaining traction internationally but still needs continued outreach.
Awareness: Much progress has been made in spreading framework awareness but more is still needed.
NIST will be going over these responses and proposed changes to the framework at a set of workshops in Gaithersburg, Maryland, on April 6 and 7.




