What has NIST done for me lately?

GovCloud Founder and Veteran’s 360 Showcased in US Veteran’s Magazine

By G C Network | June 13, 2014

Kevin L. Jackson, CEO and Founder of GovCloud Network, LLC, was showcased in US Veteran’s Magazine for his work with Veteran’s 360, a San Diego, California non-profit. With more than…

Cloud Environment Can Enable Fast, Secure Collaboration among Industries, Nations

By G C Network | June 4, 2014

NCOIC’s Kevin Jackson to present new process for creating interoperability via a cyber-secure multi-cloud environment at cloud computing conferences in the U.S. and China WASHINGTON—June 4, 2014—Cyber-secure cloud computing can…

The Federal Government Journey to Cloud Computing: Lessons Learned

By G C Network | June 3, 2014

[Republished from”On The FrontLines” magazine “Cloud Computing in Government: Lesson’s Learned” issue. Download the full 20 page issue online at https://digital.onthefrontlines.net/i/319551 ) In February 2011, Vivek Kundra announced the “Cloud…

Cloud Computing In Government Lesson’s Learned From On The FrontLines Magazine

By G C Network | May 29, 2014

Congratulations to my friends at “On The FrontLines Magazine” for an EXCELLENT presentation of important operational and managerial cloud computing transition lessons. This issues showcases cloud computing leaders from government…

From “Boots on the Ground” To “Heads in the Cloud,” Non-Profit aims to offer Cloud Training & business services to Corporate IT and HR teams.

By G C Network | May 28, 2014

From “military dedication” to “civilian success,”Veterans 360 Services is approaching the challenging transition of military service to civilian life with an innovative, focused and all-inclusive, 360 degree, process of education…

ICH Agile Cloud Consortium Completes Successful Event

By G C Network | May 22, 2014

Thank you to all that participated in yesterday’s ICH Agile Cloud Service Catalog event.    ICH Agile Cloud is an industry-wide effort targeted at developing an open and inclusive cloud service…

ICH Releases Agenda for Agile Cloud Service Catalog Session

By G C Network | May 20, 2014

The Agile Cloud consortium’s second event will occur on May 21, 2014 at TIA Headquarters in Arlington, VA. This event will focus on development of the Agile Cloud Environment Service…

PDNS Offers “Anchor” Cloud Services to Agile Cloud Consortium

By G C Network | May 14, 2014

Private Digital Network Services (PDNS) and partners will provide its national, Private Digital Network (PDN) core and a suite of highly sought after services to the Interoperability Clearinghouse Agile Cloud effort. Its…

ICH/ITAAC Announces Second Agile Cloud Environment Event

By G C Network | May 7, 2014

The 2nd Agile Cloud Environment event will be held on May 21, 2014 at TIA Headquarters. This event will focus on development of the Agile Cloud Environment Service Catalog. The…

Interoperability Clearinghouse Launches “Agile Cloud” Collaboration

By G C Network | April 28, 2014

Last Wednesday, Maj Gen, USAF (Ret) John T. Brennan, Interoperability Clearinghouse (ICH) Executive Director, kicked off the Agile Cloud collaboration. This industry-wide effort is targeted at developing an open and…

According to a study, 82 percent of federal IT professional respondents reported that they were using the NIST (National Institute of Standards and Technology) cybersecurity framework to improve their security stance. The survey also demonstrated that the document is being used as a stepping stone to a more secure government. When I first read this, my immediate reaction was a resounding, “So what!” These results tell me that US Federal Government agencies are using US Government guidance to do their US Government job. Isn’t that what you would expect? Making an impression on me would require a study across multiple industry verticals. If other industries were voluntarily using the NIST Framework, that would be saying something!

Wouldn’t you know it, but such an independent study was actually conducted earlier this year. In March of 2015, the National Cybersecurity Institute did a study of Chief Information Security Officers across multiple industries. This survey not only looked into cybersecurity practices of the US government and military, but it also delved into the security practices of other verticals including Energy/Utilities, Consulting, Information Technology and Banking/Finance. When asked about the specific security standards or frameworks their organization used, 53.1 percent of the respondents cited NIST! This response level was higher than those recorded for Information Technology Infrastructure Library (ITIL), ISO/IEC (International Organization for Standardization/International Electrotechnical Commission) HIPPA (Health Insurance Portability and Accountability Act of 1996), COBIT (Control Objectives for Information and Related Technology) and CMM (Capability Maturity Model). Yes, that impressed me.

When Paul Christman, vice president of federal for Dell Software was interviewed by FedScoop, a leading online publication that covers the US Government market, he said the framework is “just good policy”.

“It applies to schools, universities, hospitals, [the Defense Department], [the Intelligence Community], and civilian agencies. The document doesn’t say ‘This is how the government should protect the government,’ ‘This is how a bank should protect a bank.’ NIST was really trying to say ‘This wasn’t a government program or mandate;’ it’s just good practice.” Kent Landfield, director of standards and technology policy at Intel Security, echoed this sentiment saying that his company was able to fit the NIST recommendations nicely into the information technology security evaluation process as a whole.

And as if NIST had planned to stage an encore performance, two new standards – 800-173, Cloud-Adapted Risk Management Framework: Guide for Applying the Risk Management Framework to Cloud-based Federal Information Systems, and 800-174, Security and Privacy Controls for Cloud-based Federal Information Systems – are currently being drafted for released. According to Dr. Michaela Iorga, senior security technical lead for cloud computing at NIST, these new frameworks are designed to overlay and elaborate upon already-existing standards that lay out the basics for cloud architecture and security. Iorga also suggests that federal organizations should also use FedRAMP, CSA’s Security, Trust and Assurance Registry (STAR), and other certification and authorization programs to make decisions about cloud computing.

With all this new knowledge in my head, I really gained a new appreciation for NIST. The agency seems to be really taking a lead on protecting cyberspace across the board. As the economic value of our collective digital economy gains in importance, this relatively small agency has placed itself at the vanguard of cybersecurity and is truly living up to its mission:

To promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life.

Thank you NIST!

(This post was written as part of the Dell Insight Partners program, which provides news and analysis about the evolving world of tech. Dell sponsored this article, but the opinions are my own and don’t necessarily represent Dell’s positions or strategies.)

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS – © Copyright Kevin L. Jackson 2016)

This blog has been verified by Rise: Re9cb99744b65eb009b71a970003c015e

This blog has been verified by Rise:  Re9cb99744b65eb009b71a970003c015e

This blog has been verified by Rise: Re9cb99744b65eb009b71a970003c015e
Follow me at https://Twitter.com/Kevin_Jackson
Posted in

G C Network