{"id":7759,"date":"2023-03-09T13:51:09","date_gmt":"2023-03-09T12:51:09","guid":{"rendered":"https:\/\/www.iprog.it\/blog\/?p=7759"},"modified":"2023-03-09T13:51:13","modified_gmt":"2023-03-09T12:51:13","slug":"nist-framework","status":"publish","type":"post","link":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/","title":{"rendered":"NIST Framework"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large is-resized\"><a href=\"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF.jpeg\" rel=\"lightbox[7759]\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-940x520.jpeg\" alt=\"\" class=\"wp-image-7760\" width=\"444\" height=\"245\" srcset=\"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-940x520.jpeg 940w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-620x343.jpeg 620w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-300x166.jpeg 300w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-768x425.jpeg 768w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-1536x849.jpeg 1536w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-2048x1132.jpeg 2048w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF-624x345.jpeg 624w\" sizes=\"auto, (max-width: 444px) 100vw, 444px\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The National Institute of Standards and Technology (NIST) is a non-regulatory agency of the United States Department of Commerce. Its main mission is to promote innovation and industrial competitiveness in the country by advancing technology, developing standards, and providing technical support to industry, government agencies, and other stakeholders. In this article, we will discuss the NIST cybersecurity framework, which is a set of guidelines for managing and reducing cybersecurity risks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is the NIST Cybersecurity Framework?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The NIST Cybersecurity Framework (CSF) is a voluntary set of guidelines, best practices, and standards that organizations can use to manage and reduce their cybersecurity risks. The framework was created in response to Executive Order 13636, which called for the development of a framework to improve the cybersecurity posture of critical infrastructure sectors in the US.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The framework is designed to be flexible, scalable, and adaptable to different industries, organizations, and cybersecurity risk profiles. It consists of three main components: the Core, Implementation Tiers, and Profiles.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/wheel_pie.png\" rel=\"lightbox[7759]\"><img loading=\"lazy\" decoding=\"async\" width=\"220\" height=\"220\" src=\"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/wheel_pie.png\" alt=\"\" class=\"wp-image-7761\" srcset=\"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/wheel_pie.png 220w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/wheel_pie-176x176.png 176w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/wheel_pie-60x60.png 60w, https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/wheel_pie-150x150.png 150w\" sizes=\"auto, (max-width: 220px) 100vw, 220px\" \/><\/a><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The Core:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Core is the heart of the framework and provides a set of activities and outcomes that organizations can use to manage and reduce their cybersecurity risks. It consists of five functions: <strong>Identify, Protect, Detect, Respond, <\/strong>and<strong> Recover<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each of these functions is broken down into categories and subcategories that provide more detailed guidance on how to achieve the desired outcomes. For example, the Identify function includes categories such as Asset Management, Business Environment, and Risk Assessment, while the Protect function includes categories such as Access Control, Awareness and Training, and Data Security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Implementation Tiers:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Implementation Tiers provide a way for organizations to assess and communicate their cybersecurity risk management posture. There are four tiers: Partial, Risk Informed, Repeatable, and Adaptive. Each tier represents a level of cybersecurity risk management maturity, with the Adaptive tier being the most advanced.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Profiles:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Profiles component allows organizations to tailor the framework to their specific cybersecurity risk management needs. A profile is a collection of categories and subcategories from the Core that an organization selects and implements based on its unique risk profile, business objectives, and regulatory requirements<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Benefits of the NIST Cybersecurity Framework:<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The NIST CSF provides several benefits to organizations that adopt and implement it. Some of the key benefits include:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Improved cybersecurity risk management: The framework provides a structured and comprehensive approach to managing and reducing cybersecurity risks.<\/li><li>Greater alignment with regulatory requirements: The framework aligns with many existing cybersecurity regulations and standards, such as HIPAA, PCI DSS, and ISO 27001.<\/li><li>Better communication and collaboration: The framework provides a common language and framework for discussing and communicating cybersecurity risks and risk management strategies.<\/li><li>Increased efficiency and cost-effectiveness: The framework helps organizations prioritize their cybersecurity investments and resources, resulting in increased efficiency and cost-effectiveness.<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Conclusion:<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The NIST Cybersecurity Framework is a valuable resource for organizations of all sizes and industries looking to improve their cybersecurity posture. By adopting and implementing the framework, organizations can better manage and reduce their cybersecurity risks, align with regulatory requirements, improve communication and collaboration, and increase efficiency and cost-effectiveness.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The National Institute of Standards and Technology (NIST) is a non-regulatory agency of the United States Department of Commerce. Its main mission is to promote innovation and industrial competitiveness in the country by advancing technology, developing standards, and providing technical support to industry, government agencies, and other stakeholders. In&#8230; <a href=\"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":7760,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2259],"tags":[],"class_list":["post-7759","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sicurezza-informatica"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIST Framework - iProg<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"NIST Framework - iProg\" \/>\n<meta name=\"twitter:description\" content=\"Introduction The National Institute of Standards and Technology (NIST) is a non-regulatory agency of the United States Department of Commerce. Its main mission is to promote innovation and industrial competitiveness in the country by advancing technology, developing standards, and providing technical support to industry, government agencies, and other stakeholders. In... Read more &raquo;\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF.jpeg\" \/>\n<meta name=\"twitter:creator\" content=\"@flexkid1\" \/>\n<meta name=\"twitter:site\" content=\"@iprogblog\" \/>\n<meta name=\"twitter:label1\" content=\"Scritto da\" \/>\n\t<meta name=\"twitter:data1\" content=\"Diego\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tempo di lettura stimato\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minuti\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/\"},\"author\":{\"name\":\"Diego\",\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/#\\\/schema\\\/person\\\/048c8acb70f8a33f1498675ab9db41a3\"},\"headline\":\"NIST Framework\",\"datePublished\":\"2023-03-09T12:51:09+00:00\",\"dateModified\":\"2023-03-09T12:51:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/\"},\"wordCount\":509,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/NIST-CSF.jpeg\",\"articleSection\":[\"Sicurezza Informatica\"],\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/\",\"url\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/\",\"name\":\"NIST Framework - iProg\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/NIST-CSF.jpeg\",\"datePublished\":\"2023-03-09T12:51:09+00:00\",\"dateModified\":\"2023-03-09T12:51:13+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/#\\\/schema\\\/person\\\/048c8acb70f8a33f1498675ab9db41a3\"},\"inLanguage\":\"it-IT\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/sicurezza-informatica\\\/nist-framework\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/NIST-CSF.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/NIST-CSF.jpeg\",\"width\":2483,\"height\":1373},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/\",\"name\":\"iProg\",\"description\":\"perch\u00e9 reinventare la ruota?\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"it-IT\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/#\\\/schema\\\/person\\\/048c8acb70f8a33f1498675ab9db41a3\",\"name\":\"Diego\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"it-IT\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bf8084effa4627f8e50af0d50d06b0677e4a9de5e895e347c0590ad5696fdfc9?s=96&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bf8084effa4627f8e50af0d50d06b0677e4a9de5e895e347c0590ad5696fdfc9?s=96&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bf8084effa4627f8e50af0d50d06b0677e4a9de5e895e347c0590ad5696fdfc9?s=96&r=g\",\"caption\":\"Diego\"},\"description\":\"Google+\",\"sameAs\":[\"http:\\\/\\\/it.linkedin.com\\\/in\\\/diegocaridei\\\/\",\"https:\\\/\\\/x.com\\\/flexkid1\",\"http:\\\/\\\/www.youtube.com\\\/channel\\\/UCjQ2z1ygV9tv55QAc2q3JHA\"],\"url\":\"https:\\\/\\\/www.iprog.it\\\/blog\\\/author\\\/flexkid\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIST Framework - iProg","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/","twitter_card":"summary_large_image","twitter_title":"NIST Framework - iProg","twitter_description":"Introduction The National Institute of Standards and Technology (NIST) is a non-regulatory agency of the United States Department of Commerce. Its main mission is to promote innovation and industrial competitiveness in the country by advancing technology, developing standards, and providing technical support to industry, government agencies, and other stakeholders. In... Read more &raquo;","twitter_image":"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF.jpeg","twitter_creator":"@flexkid1","twitter_site":"@iprogblog","twitter_misc":{"Scritto da":"Diego","Tempo di lettura stimato":"4 minuti"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/#article","isPartOf":{"@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/"},"author":{"name":"Diego","@id":"https:\/\/www.iprog.it\/blog\/#\/schema\/person\/048c8acb70f8a33f1498675ab9db41a3"},"headline":"NIST Framework","datePublished":"2023-03-09T12:51:09+00:00","dateModified":"2023-03-09T12:51:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/"},"wordCount":509,"commentCount":0,"image":{"@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/#primaryimage"},"thumbnailUrl":"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF.jpeg","articleSection":["Sicurezza Informatica"],"inLanguage":"it-IT","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/","url":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/","name":"NIST Framework - iProg","isPartOf":{"@id":"https:\/\/www.iprog.it\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/#primaryimage"},"image":{"@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/#primaryimage"},"thumbnailUrl":"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF.jpeg","datePublished":"2023-03-09T12:51:09+00:00","dateModified":"2023-03-09T12:51:13+00:00","author":{"@id":"https:\/\/www.iprog.it\/blog\/#\/schema\/person\/048c8acb70f8a33f1498675ab9db41a3"},"inLanguage":"it-IT","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/"]}]},{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/www.iprog.it\/blog\/sicurezza-informatica\/nist-framework\/#primaryimage","url":"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF.jpeg","contentUrl":"https:\/\/www.iprog.it\/blog\/wp-content\/uploads\/2023\/03\/NIST-CSF.jpeg","width":2483,"height":1373},{"@type":"WebSite","@id":"https:\/\/www.iprog.it\/blog\/#website","url":"https:\/\/www.iprog.it\/blog\/","name":"iProg","description":"perch\u00e9 reinventare la ruota?","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.iprog.it\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"it-IT"},{"@type":"Person","@id":"https:\/\/www.iprog.it\/blog\/#\/schema\/person\/048c8acb70f8a33f1498675ab9db41a3","name":"Diego","image":{"@type":"ImageObject","inLanguage":"it-IT","@id":"https:\/\/secure.gravatar.com\/avatar\/bf8084effa4627f8e50af0d50d06b0677e4a9de5e895e347c0590ad5696fdfc9?s=96&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/bf8084effa4627f8e50af0d50d06b0677e4a9de5e895e347c0590ad5696fdfc9?s=96&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bf8084effa4627f8e50af0d50d06b0677e4a9de5e895e347c0590ad5696fdfc9?s=96&r=g","caption":"Diego"},"description":"Google+","sameAs":["http:\/\/it.linkedin.com\/in\/diegocaridei\/","https:\/\/x.com\/flexkid1","http:\/\/www.youtube.com\/channel\/UCjQ2z1ygV9tv55QAc2q3JHA"],"url":"https:\/\/www.iprog.it\/blog\/author\/flexkid\/"}]}},"views":610,"_links":{"self":[{"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/posts\/7759","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/comments?post=7759"}],"version-history":[{"count":1,"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/posts\/7759\/revisions"}],"predecessor-version":[{"id":7762,"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/posts\/7759\/revisions\/7762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/media\/7760"}],"wp:attachment":[{"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/media?parent=7759"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/categories?post=7759"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.iprog.it\/blog\/wp-json\/wp\/v2\/tags?post=7759"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}