TheCyberNews
Resource

NIST (National Institute of Standards and Technology)

Updated: Recently

Overview

NIST is a non-regulatory agency of the United States Department of Commerce. In the cybersecurity world, they are most famous for creating the NIST Cybersecurity Framework (CSF). This framework is a voluntary set of guidelines, best practices, and standards designed to help organizations manage and reduce their cybersecurity risk.

Why It Matters

If you are an IT professional or a business owner, NIST is your ultimate blueprint for building a secure company. It moves security away from being a “checklist of software to buy” and turns it into a strategic lifecycle based on five core functions:

  1. Identify: Understand what critical assets you own.
  2. Protect: Put safeguards in place (like MFA and Firewalls).
  3. Detect: Ensure you have tools to spot a hacker if they break in.
  4. Respond: Have a plan for exactly what to do when a breach occurs.
  5. Recover: Have backups ready to restore operations.
  • The NIST Cybersecurity Framework (CSF 2.0): The definitive guide to organizing a corporate security program.
  • National Vulnerability Database (NVD): The official U.S. government repository of standards-based vulnerability management data, representing the master list of all known CVEs.