Live data from Hacker News

Understanding Cybersecurity Frameworks: NIST, ISO, and More

thefinalhop.com

11–20 of 52 posts

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#11
post #5
post #3

Earlier quoted context omitted.

What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)

They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.

Problem for companies is clients will ask for this or that certification (a due diligence checkbox they have little control over). Also unless you’re a big co., there is no way a service provider will let small co. customer interview the security and development teams and let you audit their security practices, etc. So at that point a known low bar is better than an unknown unset bar.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#12
post #5
post #3

Earlier quoted context omitted.

What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)

They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.

> By a wide margin, their most impactful designed purpose is to sell security products and services

The cyber causality dilemma - which came first, the vendor or the framework?

I think there's some use for the framework to make people think about which controls and concepts might work for a given situation, but certainly they need the real world to be examined in parallel to be useful

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#13

My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…

The other bad thing they do is encourage technologists who aren't security subject matter experts to invest in programs and tools that aren't valuable, either at their current state or, in some cases, ever. They create the impression that there is an important checklist of things that most companies need to have, and if such a checklist exists, not one of these frameworks captures it.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#14
post #7

Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.

These frameworks don’t guarantee security, but there is a stark difference between companies that do this and those who don’t. Companies that follow these frameworks are at least attempting to be secure.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#15
post #5
post #3

Earlier quoted context omitted.

What are alternatives you would suggest to these frameworks? (I am also deeply skeptical of these frameworks, but don’t have a strong argument against them, and they seem pervasive in the security industry)

They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.

You know these are the floor of what you should do, not the ceiling.

If a big company can’t explain why they aren’t doing the bare minimum defined in a framework, that’s a red flag.

There are open source solutions for the majority of controls in these frameworks. It isn’t 1995.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#16
post #7

Being compliant within any of those frameworks does not make an organization secure. It's a good place to start, and will make the auditors happy, but assuming that (compliance equals secure) is a huge mistake.

> Being compliant within any of those frameworks does not make an organization secure.

I've gotten into breathless arguments with "cyber experts" who really don't understand this simple point. I've met people in industry who literally think that "filling out the paperwork and having a risk committee accept risks or prioritize a schedule to get into compliance" equals "our systems are now secure".

It's a massive self-serving industry incentivized to enrich itself and not secure systems. If they were successful at designing, deploying, and maintaining secure systems, there wouldn't be an industry.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#17

My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…

Welcome to the government.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#18
post #15
post #5

Earlier quoted context omitted.

They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.

You know these are the floor of what you should do, not the ceiling. If a big company can’t explain why they aren’t doing the bare minimum defined in a framework, that’s a red flag. There are open source solutions for the majority of controls in these frameworks. It isn’t 1995.

My argument is that they're lower than the floor, which makes using them to try to detect the floor dangerous.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#19
post #2

No, no to all of this.

I was hoping for a more nuanced take from you, @tptacek. However, this deserves more thought than “no, no to all of this.”

Speaking from experience

1.) At their worst - many industry-prescribed standards act to move liability from the poor Visa of the world onto smaller businesses. For example, being visa in this scenario - Why should I develop a better solution to credit card/identity theft? We have PCI!! I can even help sell training out of the goodness of my heart! This, of course, stagnates the industry, both through lost leaders thinking this piece of paper will protect them or to the parasitic cottage industries that capitalize on the fact nobody knows better and takes what could have been an investment in solving fundamental security problems. Ultimately accountability goes back to Visa / SWIFT and whatever body that cba’d on fixing the problem they created.

HOWEVER

2.) At their best many of these standards invite operational rigor required when you want to move past the “3 people in a basement” stages of your startup and have to make grown-up decisions if someone is hit by a train. Furthermore, security is often considered a cost center; attaining specific certifications can be one of the few indirect ways to attribute as a measurable product differentiator in whatever space you’re in.

The author's argument that these frameworks are a decent place to start to work on the comprehensive “cyber security” strategy is excellent for the neophyte looking to understand better one of the many elements that go into running a security program, but it’s far from comprehensive. It’s sad to think, but sometimes these compliance-driven certifications often become one of the few forcing functions you have as a security engineer/leader to get someone to do something that closely resembles the right thing. I’m sure many roll their eyes reading this comment, but - I’ve had countless interactions with engineers who could give less of a shit if their product is insecure just as long as they can ship it on time and be offline by 4, and my only option is to get the legal department to chase them because we will fail an audit if they don’t change course.

Either way. I’d recommend anyone reading the article to have an open mind to understanding many of these frameworks, what they are used for, and how you might use them effectively until we figure out something better. Don’t just cargo cult “standards r bad”, “Jira is dumb”. Try to ask the broader question of why they are needed in the first place.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#20
NIST CSF = The encyclopedia which breaks security down into as many areas/steps/sections as possible. If you are planning a 500-person security department, this is how you give them all something to do. The idea is to accomplish the task with manpower rather than elegance. CSF itself is mostly just a pointer to NIST 800-53. For truly large-scale operations it can be an ok fit, but for most organizations it is overkill that your cyber-insurance vendor will still expect you to do. Otherwise, best used as a reference not a guide.

ISO 27001 = Not super familiar with this one.

COBIT = The management/process focused version of NIST CSF. Great if you have an executive suite CTO, CISO, CRiskO, CPrivacyO, and want to coordinate their efforts in a program that divides responsibilities among them and associated committees. Includes maturity modeling, which gives it a +1, but it is distant from anything technology related. Instead, it is all about which committees should be formed to decide on risk management strategies etc...

PCI-DSS = You'll do this one because VISA makes you do it. Much more actionable than NIST or COBIT, but it depends on the third-party auditor who is issuing your attestation of compliance. "Your label maker has it's default password?" = audit finding.

CIS18 Controls = The most actionable/lightweight framework now that they have incorporated maturity levels (aka implementation groups). Not as thorough as NIST or COBIT. Well implemented, CIS18 is enough for most organizations provided they do not have a specific security standard or requirement in their industry.

Post reply on HN