๐Ÿ’ก

This post was written 3 years ago, it may be out of date, my opinion might have changed, and/or the writing may be embarrassingly bad. Read with caution.

NIST Cybersecurity Framework

Fall/2021 โ€“ 1 min read

AWS has a huge library of fantastic resources. This post highlights the recently updated whitepaper aligning the NIST Cybersecurity Framework to AWS.

AWS has a huge library of fantastic resources. This post highlights the recently updated whitepaper aligning the NIST Cybersecurity Framework to AWS.

โ€œNIST Cybersecurity Framework, Aligning to the NIST CSF in the AWS Cloudโ€, does exactly what the subtitle promises.

This paper aligns the NIST CSF to the AWS Cloud.

I call out a few more details in the Twitter thread belowโ€ฆ

Tweet 1/5 ๐Ÿ‘‡ Next tweet

today I'm taking a look at "NIST Cybersecurity Framework, Aligning to the NIST CSF in the AWS Cloud" which...um...aligns @NISTcyber's framework with @awscloud designs

PDF ๐Ÿ“: https://d1.awsstatic.com/whitepapers/compliance/NIST_Cybersecurity_Framework_CSF.pdf?did=wp_card&trk=wp_card

๐Ÿงตโ˜๏ธ #cloud #infosec

Tweet 2/5 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

read the thread unrolled at https://t.co/LKnrxH9Sp0

yesterday's thread is up at https://markn.ca/2021/reactive-systems-on-aws/

๐Ÿงตโ˜๏ธ #cloud #infosec #devops

Tweet 3/5 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

the structure of the paper ๐Ÿ“‘ is simple. a few use cases and then best practices by @nistcyber CSF core function:

- identify - protect - detect - respond - recover

...and finally an alignment of @awscloud services with the framework

๐Ÿงตโ˜๏ธ #cloud #infosec

Tweet 4/5 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

the use cases are handy, but really ANYONE can benefit from looking at the framework. it's right on pg 3, @nistcyber CSF is "a simple-yet-effective construct" for your security efforts

it looks at practice, outcomes, and controls

๐Ÿงตโ˜๏ธ #cloud #infosec

Tweet 5/5 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

as an aside, @nistcyber has documented the framework thoroughly. you can check it out at https://www.nist.gov/cyberframework

at that site, you'll find the framework, a "new to framework" guide, and material for learning specific aspects of the CSF

๐Ÿงตโ˜๏ธ #cloud #infosec