Checking the Checkboxes: NIST Cybersecurity Framework
23 Sep 2019•5 min read
Blog/Checking the Checkboxes: NIST Cybersecurity Framework
Checklists are widely recognized as important tools for many professions. Atal Gawande, a surgeon and the author of The Checklist Manifesto: How to Get Things Right, writes about checklists used in medicine and aviation to achieve better and safer results by ensuring that all necessary steps in a process, no matter how small, are completed. The checklist principle can by applied technology in K-12 schools and specifically to the area of cybersecurity.
Cybersecurity issues are regularly in the news, as illustrated by the number of incidents (681 at the time of this post) reported on the K12 Cyber Incident Map. The quantity of incidents increases each year, and it is the responsibility of the school district technology leader to ensure that either these incidents do not happen in the first place, or that the impact on people, time, and money is lessened. For many of the same reasons that medicine and aviation professionals adopted checklists, technology leaders should consider adopting a checklist like the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), which provides the functions, categories, and subcategories to form a high-level checklist of cybersecurity measures needed at an organizational level. The 5 major functions of the framework are Identify, Protect, Detect, Respond, and Recover and there are 23 categories and 108 sub-categories. This is the ultimate checklist for cybersecurity.
The checklist is complex, and several organizations provide free resources to help technology leaders to understand and apply the framework. The Center for Internet Security (CIS) has a set of tools, controls, and benchmarks that can be used to help identify, protect, detect, respond and recover. CIS SecureSuite provides free membership to schools that include tools, resources, and webinars. The Multi-State Information Sharing & Analysis Center (MS-ISAC) is also available through CIS, and it provides advisories and notifications, webcasts, malicious domains/ip reports, and awareness/education materials.
To give you a headstart, here is a checklist of items that you can use to begin the process of learning more about the NIST Cybersecurity Framework, so you can start checking the checkboxes and make an impact on your school environment.
Cybersecurity Crisis Response Groups: How They Can Keep your District Secure
In the event of a cyber incident, who ya gonna call? Unfortunately, the Ghostbusters can’t help you here. But your friends and peers sure can. See how a cybersecurity crisis response group can keep your
Duane Shaffer
Director of Technology Services, Learning Technology Center
Cybersecurity
4 Cybersecurity Tips for School Staff & Students
Each October, the US recognizes Cybersecurity Awareness Month, a multi-week opportunity for everyone – including K-12 school districts – to recommit themselves to protecting digital networks and data. Here are a few quick tips to
Eric Muckensturm
IT Strategy Manager, Cybersecurity, Learning Technology Center
CybersecurityData PrivacySOPPA
Stay Ahead of Tomorrow’s Digital Threats at SecurED Schools
At SecurED Schools, you can take the first step toward addressing new vulnerabilities and securing your district’s digital future. Take a peak at this year’s schedule, which includes over 40 local, state, and national experts
Sam Fishel
Digital Content Manager, Learning Technology Center