Live data from Hacker News

Understanding Cybersecurity Frameworks: NIST, ISO, and More

thefinalhop.com

31–40 of 52 posts

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#31
post #11
post #5

Earlier quoted context omitted.

They're a pervasive indicator of performative security that intersects with serious practice in very few places. By a wide margin, their most impactful designed purpose is to sell security products and services.

Problem for companies is clients will ask for this or that certification (a due diligence checkbox they have little control over). Also unless you’re a big co., there is no way a service provider will let small co. customer interview the security and development teams and let you audit their security practices, etc. So at that point a known low bar is better than an unknown unset bar.

That's true, but it's vitally important that companies satisfying "framework" requirements for sales enablement understand why they're doing it:

1. They should adopt frameworks only when there's certainty that the revenue coming in from the sales they enable justifies the expense of performing the framework.

2. They should minimize the scope of work they do to satisfy the framework, keeping a clear head about the fact that these are sales enablement tasks, not security program tasks.

3. They should design and execute a real security program independent of the frameworks, being careful not to let the real program get led around by the framework compliance tasks, which are unrelated to security.

The real danger with these frameworks is that people don't do (3), but rather use the framework as a runbook for building a security practice. That's a terrible idea with a terrible track record, because frameworks aren't designed to security your company, but rather to document what a consortium of IT security people, largely from huge companies with diffuse, unaccountable security teams, happen to be doing.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#32
post #25

Lol this article was 100% generated by chat gpt... I know because I've asked very similar questions..

Yeah, this entire website is a pretty clear ai content farm. From the stable diffusion profile images to the twitter with 27k followers and no engagement.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#33
post #2

No, no to all of this.

I was hoping for a more nuanced take from you, @tptacek. However, this deserves more thought than “no, no to all of this.” Speaking from experience 1.) At their worst - many industry-prescribed standards act to move liability from the poor Visa of the world onto smaller businesses. For example, being visa in this scenario - Why should I develop a better solution to credit card/identity theft? We have PCI!! I can even…

Seems like this thread misses regulatory expansion as a business goal. Compliance is the standardized language you use to communicate the great security you do to your customers, and their customers. It removes barriers to adoption. It also opens the door to billions in market access.

It is not a punitive act, it is a business imperative.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#34
post #28

We can tell how good these cybersecurity frameworks are by seeing how hard it is to breach the organizations certified at the highest levels such as SolarWinds [1], Equifax [2], Trend Micro [3][4], Cisco [5], and so many more. It is so utterly ridiculous that anybody cares about these standards when literal clown shows get full marks. The sign of a good standard is one that effectively and accurately predicts outcome…

It should get slightly better now that companies will be held accountable for breaches and data leaks.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#35
post #16

Earlier quoted context omitted.

> Being compliant within any of those frameworks does not make an organization secure. I've gotten into breathless arguments with "cyber experts" who really don't understand this simple point. I've met people in industry who literally think that "filling out the paperwork and having a risk committee accept risks or prioritize a schedule to get into compliance" equals "our systems are now secure". It's a massive self-…

I’ve really been of the opinion as of late that if we took just a small fraction of the time and manpower we waste on pedantic security framework adherence and put it towards training actual staff to and experts to be better cybersecurity professionals, we’d be better off.

I agree with this notion. The issue is you need the security attestation and certifications to give folks in the sales cycle the warm fuzzies. These pedantic measures are directly a pathway to sales enablement and revenue. The actual securing and maturity work is a side benefit.

On the other side of the coin, if a vendor does not have paperwork and evidence to support their programs - how does one as a purchaser or security reviewer verify? Organizations only act truthful to an extent that benefits them. Quality of audits and supporting paperwork is a real mixed bag. Unless you’re an Amazon you’re not going to get the chance to audit your vendors and sub processors outside of reviewing this type of documentation.

The entire process is broken.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#36
post #31
post #11

Earlier quoted context omitted.

Problem for companies is clients will ask for this or that certification (a due diligence checkbox they have little control over). Also unless you’re a big co., there is no way a service provider will let small co. customer interview the security and development teams and let you audit their security practices, etc. So at that point a known low bar is better than an unknown unset bar.

That's true, but it's vitally important that companies satisfying "framework" requirements for sales enablement understand why they're doing it: 1. They should adopt frameworks only when there's certainty that the revenue coming in from the sales they enable justifies the expense of performing the framework. 2. They should minimize the scope of work they do to satisfy the framework, keeping a clear head about the fac…

Absolutely nailed it with this take. This summarizes the sales enablement piece perfectly.

Unfortunately business benefit is easiest to quantify from a sales enablement perspective as opposed to a security program perspective. Agree wholeheartedly you need to do (3) to actually move the needle on security.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#38
post #13

Earlier quoted context omitted.

The other bad thing they do is encourage technologists who aren't security subject matter experts to invest in programs and tools that aren't valuable, either at their current state or, in some cases, ever. They create the impression that there is an important checklist of things that most companies need to have, and if such a checklist exists, not one of these frameworks captures it.

Yeah, unfortunately a lot of checkboxes only serve to expand the attack surface in many cases.

> a lot of checkboxes

Yeah, I'm self taught on this stuff, but I've started to think that's not all bad. I literally downloaded every one of the NIST 800 series, the FIPS series, the CNSSIs, all of it, and went through everything to figure out what connected with what. Most of it is pretty damn obvious. You should secure your internet-facing servers, sanitize inputs, never hold actual passwords in a database, use some form of 2FA, etc.

But there are a lot of dudes with degrees in "cyber-something" or "IT something" who lord over me with their government-bestowed positional authority (I'm just the clinical informatics physician with an undergrad in physics from a top school and teach machines to diagnose disease, trying to deploy things to actually save lives, so what the fuck could I possibly know about the dark arts of cybersecurity? "Oh, god, here he is talking to us about numbers again, borrrringgggg. I bet he's going to ask us when the GPUs are going to be on contract. Again. Like, bro, we'll get to it. Later.")

Come to find out a lot of these fuckwads speed-click through their ATO checklists. Shockingly, the timestamps on the checkboxes are all on the Thursday afternoon before the Tuesday "surprise" inspection that happens the same week of the year every time, run by the guy who they used to work for at the last gig.

And then the guys actually trying to get shit done get drowned by the 50 fucking drones who all show up to the weekly meetings and pipe up with their 30 seconds worth of input. And the guy trying to actually deploy product spends the rest of the week establishing that the drone didn't actually know what the fuck was going on in the meeting and just blurted something out at the appropriate moment, relying on the last 30 seconds of banter to guide his statements.

Not that I'm bitter or anything...

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#39
The fundamentals of these frameworks are not inherently bad. The main problem is that they are treated as the checkbox solution that should be implemented regardless of context.

If you take your IT security work seriously you will in most cases already fulfill the requirements stipulated in the frameworks, and if you are setting out to get started with more structured approach they are a good place to start.

What cannot be understated however is the need for context, IT security is a set of choices that determine where you will have exposure and those business risk. For any business these will be different, as regulation and value creation differs. Exactly as any other risk management, but for some reason this does seem difficult for most to understand.

Re: Understanding Cybersecurity Frameworks: NIST, ISO, and More

#40

My personal take on the land of cyber security frameworks - and especially security standards - is that a good security team should be able to read through a list of controls (e.g. those in NIST 800-171) and express a reasoned opinion on each one with respect to the company's security posture. They are fantastic tools for reminding you what things you might have overlooked and driving a discussion about how your orga…

Welcome to the government.

Positive change starts with someone acting on the thought "it doesn't have to be this way."

Fatalism and cynicism are comfortable because they don't ask you to do anything.

Cynicism is ultimately resigned consent.

How many security professionals here have actually sent a thought out letter to their congressperson or the NIST directly? How many people who express the negativity in this thread have tried to e-mail someone in a position of institutional authority or a tech related think tank? How many people have given government service a try? How many people have waited for a security catastrophe and then e-mailed someone who might be able to change policy? How many people have looked up a law and tried to reverse engineer who wrote it and who can influence it?

How many people have tried and failed?

When everyone thinks like yourself, it becomes a self fulfilling prophecy.

Post reply on HN