How Does the Cybersecurity Framework Manage Risk?

651 views
February 22, 2017
by
RSAC Cybersecurity
YouTube video player
How Does the Cybersecurity Framework Manage Risk?

TL;DR

The Cybersecurity Framework gives public and private organizations a common language for managing security risk and connecting cybersecurity decisions with operational and business priorities. Its identify, protect, detect, respond, and recover structure supports conversations among security teams, executives, government, contractors, and marketers, while broader adoption reflects the need for an integrated approach rather than a single technical solution.

Transcript

Good afternoon, everybody. Um, we're, uh, extremely fortunate that, uh, about a year ago, the president, uh, s- had a commission on enhancing cybersecurity, and, um, it-- one of its mission was to make detailed recommendations to strengthen cybersecurity in both the public and the private sector. And we're fortunate to have two members, uh, of the ... Read More

Key Insights

  • Cybersecurity is a nonpartisan issue according to the commission’s members, who said political affiliation was not apparent in their discussions even though the chair and vice chair came from different political parties.
  • The commission’s recommendations form an integrated package because cybersecurity has no single remedy. Neglecting some actions in favor of supposedly more important measures can make the overall result less effective.
  • The Cybersecurity Framework provides a common language for describing security problems, planned responses, measurements, and current conditions. That shared vocabulary helps different groups discuss risk without relying on identical institutional backgrounds.
  • Framework adoption can improve communication between government and the private sector because both sides frequently use different terminology. Applying the same risk-management framework gives them a stronger basis for coordination.
  • The framework’s core consists of identify, protect, detect, respond, and recover. These functions can be examined at a technical level or summarized for people outside cybersecurity roles.
  • Cybersecurity risk management is most useful when it is integrated with an organization’s operational and business priorities. Most organizations exist to provide products or services, not merely to become secure.
  • Industry input led the framework’s development, with contributions coming from multiple sectors across the United States and around the world. This collaborative process helped make the framework applicable to varied organizational settings.
  • The framework supports conversations beyond security departments, including discussions about governance, strategic direction, contract requirements, and marketing capabilities. Its structure translates specialist concerns into terms that broader enterprise stakeholders can use.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the main purpose of the Cybersecurity Framework?

The Cybersecurity Framework provides a common language for understanding cybersecurity problems, deciding what actions to take, measuring current conditions, and discussing progress. It helps security specialists communicate with executives, operational teams, government representatives, and private-sector organizations. Its broader purpose is to integrate cybersecurity risk management into an organization’s governance, strategy, contracts, operations, and primary mission.

Q: Why did commission members support broader framework adoption?

Commission members supported broader adoption because the framework can bridge differences in terminology among government, private companies, and other sectors. Both Herbert Lin and Joe Sullivan said their views became more favorable during the commission process. They saw value in using a shared approach to risk management, particularly when organizations with different professional languages must coordinate their cybersecurity decisions and priorities.

Q: Why is there no single solution for cybersecurity?

The commission described cybersecurity as a problem that must be addressed on many fronts through an integrated package of actions. Its members rejected the idea that one recommendation could solve the problem by itself. They argued that omitting some measures to concentrate only on apparently more important ones can reduce the quality of the overall result, making coordinated implementation essential.

Q: How does the framework connect security with business goals?

The framework connects security with business goals by treating cybersecurity as part of enterprise risk management instead of an isolated technical activity. Organizations generally exist to sell products or provide services, rather than simply to be secure. The framework enables leaders to consider security alongside operations, governance, strategy, contractual requirements, and the organization’s fundamental mission when making risk decisions.

Q: What are the five core functions of the framework?

The framework’s five core functions are identify, protect, detect, respond, and recover. Together, they organize cybersecurity activities in a form that specialists can discuss at a detailed level while leaders and other non-specialists can understand at a higher level. This layered structure allows the same framework to support technical planning, enterprise governance, risk conversations, and communication across organizational roles.

Q: How was the cybersecurity commission organized?

President Obama chartered the commission to develop recommendations that could guide the next president’s cybersecurity efforts. It contained twelve people, including a Democratic chair and a Republican vice chair, as described in the panel. Members came from government, academia, business leadership, and legislative backgrounds. Participants characterized its deliberations and recommendations as independent, collaborative, and nonpartisan.

Q: How did industry contribute to the framework?

Industry led the framework’s development through input from multiple sectors across the United States and around the world. According to Donna Dodson, that process produced a core structure capable of supporting conversations beyond security departments. The framework can therefore inform cybersecurity requirements in contracts, the marketing of relevant capabilities, organizational governance, enterprise strategy, and detailed discussions among security professionals.

Q: Why is communication a major cybersecurity challenge?

Communication is difficult because security professionals often speak effectively with other specialists but rely on acronyms and terminology that may not work for executives, operational teams, government bodies, or private companies. The framework addresses this challenge by organizing cybersecurity risk into shared functions and concepts. It lets technical details roll up into understandable categories that other parts of an organization can use.

Summary & Key Takeaways

  • President Obama’s commission assembled twelve members from government, academia, business, and the legislature to produce independent, nonpartisan cybersecurity recommendations for the next president. Participants described the resulting report as an integrated package of strategic and tactical actions, emphasizing that cybersecurity requires coordinated work across many fronts rather than one dominant remedy.

  • Commission members became more supportive of the Cybersecurity Framework after hearing perspectives from different sectors. They concluded that its major value is a common language for describing risks, planned actions, measurements, and organizational progress. Shared terminology can also reduce communication barriers between government and private-sector organizations that otherwise approach security differently.

  • Industry input from across the United States and around the world shaped the framework. Its core functions, identify, protect, detect, respond, and recover, provide enough detail for security specialists while remaining understandable to organizational leaders. This structure helps integrate cybersecurity risk management with governance, contracts, marketing, operations, and an enterprise’s primary mission.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚