Skip to main content

Elevate

CMMC 2.0 – Extended-Release Dates Among Rule-Making Delays

DoD CMMC 2.0 Release

In this article, we look at factors affecting DoD CMMC 2.0 Release Date. Since its initial release in the fall of 2021, the original CMMC model (now referred to as CMMC 1.0) received pushback from smaller and medium-scale corporations who vocalized their opinion that a self-assessment should serve as appropriate for operators who are not handling sensitive CUI. As a result, early last November, the DoD announced that the newly released CMMC (Cyber Security Maturity Model Certification) security model would be receiving an immediate makeover to create a leaner and cleaner guideline, with the intention of creating a more collaborative relationship with the industry and creating increased opportunities for self-attestation for qualifying organizations. CMMC 1.0 (as it’s now known) has been officially retired and the replacement, CMMC 2.0, remains in the early stages of Rule-Making and initial review. In early February, a directive from Kathleen H. Hicks, Deputy Secretary of Defense, re-assigned the responsibility of the CMMC 2.0 away from the USD (A&S) and over to the DoD in order to establish united leadership and guidance for all cybersecurity interests and programs.  This week, both the DoD and the CMMC-AB held Town Halls to update the progress of CMMC 2.0. The CMMC-AB advised on continued available training for CMMC auditors wishing to become certified and enter the marketplace, mentioning that the 6th C3PAO was recently accepted into the marketplace and that currently, the applications for RPs, RPOs, and LTPs have doubled since February of 2021. The Delta training for CCP candidates who have completed CCP 1.0 courses was released on the 15th of February, and Delta training for Registered Practitioners (RPs) is expected to be released by March 1st. The training is anticipated to take 2-3 hours to complete.  The DoD Town Hall re-outlined the approved proposed adjustments that will be incorporated into the new model 2.0. This includes eliminating both Levels 2 and 4, which were considered “transition levels” and creating a leaner model with 3 tiers, Foundational, Advanced, and Expert. The DoD feels that the CMMC 2.0 addresses the self-assessment concerns which spurred the re-evaluation, which now had been adjusted to allow self-attestation for all companies who fall under Level 1.  Level 1 companies hold federal contracting information only, not critical programs or CUI. Companies included in the Level 2 designation and higher will be evaluated on a case-by-case basis to be considered for self-attestation for infrequent exceptions. There was mention as well that the removed control items from CMMC 1.0 could possibly be added back into the requirements for NIST 800-171. The main takeaways from the Town Hall updates are as follows:  Rulemaking is still in progress, but the finalization of the CMMC DFARS may take up to 2 years. (Last September the estimate was  9-24 months) As a result, an implementation may be pushed back and it could be as long as 3 years before CMMC is required in government contracts. Most Contractors (approx. 80,000) Level 2 and above possessing CUI will likely require a 3rd party assessment, this differs from the original thought that CMMC 2.0 would provide more opportunities for self-attestation.  What does all of this mean?  Despite the delay, while the DoD is working on Rule-Making, it is important to remember that all indications state that Level 2 or higher companies will still be expected to conform to the CMMC requirement for third-party attestation of compliance. Has your company determined if this third-party attestation is necessary for certification?  If so, keep in mind that even with the extended delay before we’ll see CMMC 2.0 certification requirements appear in RFPs, the rule’s forthcoming is inevitable and the preparation for this assessment can be intricate and time-consuming. In order to be as proactive as possible, conducting an objective Gap Assessment is an important first step towards assessment to be as confident as possible going into the CMMC 2.0 assessment by a certified C3PAO.   By calling Elevate, you can make the process of becoming compliant much less painful. Our Elevate professionals will prepare your firm for your formal assessment by a certified C3PAO with a thorough CMMC Gap Assessment with remediation advice. 

Is your Financial Institution aware of the FTC’s Final Rule Implemented in January 2022?

FTC Safeguards Rule 2022

In October of last year, in an effort to strengthen data security measures, the Federal Trade Commission (“FTC”) announced that there were plans to implement important updates in an effort to rejuvenate and modernize what is known as the Standards for Safeguarding Customer Information (‘‘Safeguards Rule’’). The Safeguards Rule provides a guideline for businesses to have information security processes in practice to prevent consumer harm and promote good business practices and healthy competition in the marketplace. This anticipated change was initiated and implemented due to the dramatically increased infiltration of virtual networks in so many aspects of everyday business and personal life, demanding increased security in the realm of information security. This, along with a drastic uptick in data breach incidents and large-scale cybersecurity threats and attacks, spurred the FTC to announce these imminent changes. As a result, effective January 10, 2022, the FTC issued a final rule (‘‘Final Rule’’) to amend the Standards for Safeguarding Customer Information (‘‘Safeguards Rule’’).  The recent changes were published in early December 2021 by the FTC and passed with a 3-2 vote.  Overall, the Final Rule maintains the roadmap originally outlined in the 2019 adaption of the same with notable amendments and clarifications as summarized below.  The Final Rule guidelines contain five main modifications from the existing Rule. Provides more detailed guidance on how to develop and implement specific aspects of an overall information security program, including access controls, authentication, and encryption. Risk Assessment requirements are clarified as well as employee training criteria. Second, it adds provisions designed to improve the accountability of financial institutions’ information security programs, such as by requiring periodic reports to boards of directors or governing bodies to increase awareness and involvement of senior management roles. It exempts financial institutions that collect data from 5.000 customers or less from certain requirements. It expands the definition of ‘‘financial institution’’ to include entities engaged in activities the Federal Reserve Board determines to be incidental to financial activities. This change adds ‘‘finders’’— companies that bring together buyers and sellers of a product or service within the scope of the Rule. Defines several terms and provides related examples in the Rule itself to provide an ease of reference, rather than invoke the need to the separate Privacy of Consumer Financial Information Rule (‘‘Privacy Rule’’).  As the Final Rule was implemented on January 10, 2022, now is the time to take action – your qualifying financial institution should ensure your organization has a satisfactorily documented consumer information security process in place.  This is where Elevate can help! We can do the legwork for you. Elevate is already familiar with GBLA and the Safeguard and Final Rules, and can assist in evaluating your company’s current information security system, perform a Risk Assessment, then advise on areas that need improvement, and provide a plan of action.

CMMC 2.0 Update – What Do These Changes Mean for Your Organization?

cmmc 2.0 update

CMMC 2.0 Update Three major changes were announced for CMMC: fewer security tiers, new level definitions and requirements, and allowance for “Plan of Action & Milestone” reports. Learn more about the DoD’s major changes to the CMMC program. Like everyone else in the world of federal compliance, we’ve been closely tracking the Cybersecurity Maturity Model Certification (CMMC) since the U.S. Department of Defense (DoD) shared its initial draft of the model in early 2020. The controversial certification program has simultaneously been praised for its potential to raise cybersecurity standards for DoD contractors and criticized for the cost to comply, which is seen as a burden for many small businesses that are executing federal contracts. Pairing Down the Scope The initial CMMC draft established five tiers of cybersecurity requirements for contractors. The tier with which a contractor needs to comply is based on the types of data they work with to execute federal contracts. With the CMMC 2.0 update there are now only three security tiers designed to simplify the program requirements: The CMMC 2.0 Update Removes Some Third-Party Assessment Requirements Under the new model, Level 1 contractors will no longer be required to get a third-party certification. Instead, they will follow a self-assessment protocol that can significantly reduce compliance costs for many contractors. These self-assessments will require an annual affirmation by company leadership. CMMC 2.0 Level 2 assessment requirements have also been updated allowing for self-assessments in some cases, instead of the required independent assessments. Under CMMC 2.0, third-party assessments will only be required for companies “supporting the highest priority programs.” To ensure compliance and avoid any penalties, many of which are significant, it’s highly recommended you hire a third-party assessor to complete your CMMC certification. A third-party assessment will help to accelerate your revenue and market growth to differentiate your business by providing your customers with the assurance that you have the necessary controls in place. Minimizing Barriers to Pass Assessment The self-assessments are just one part of the changes implemented to remove assessment barriers for contractors. Another key piece is the decision to allow “Plans of Action & Milestones” (POA&Ms) reports in certain cases. With these reports, contractors can pass an assessment even if they do not currently meet every security control required — provided their report properly outlines a plan of action, and deadlines, to meet those controls in the future. We expect the DoD to further refine the POA&M requirements for CMMC 2.0. Expect to see DoD requirements for findings to be resolved within 180 days and guidance on what may constitute a “showstopper” preventing a CMMC Certification. What’s Next? Overall, the changes implemented significantly streamline the requirements to comply with CMMC and remove a lot of barriers to compliance for smaller contractors. At this time, it appears that CMMC pilots and contract requirements will be temporarily suspended until the DoD finalizes these CMMC 2.0 changes. For contractors who are waiting in the wings, the wait continues. We continue to advise that companies prepare for CMMC by staying up to date with changes and announcements from the DoD, researching options for assessment partners (if a third-party assessment is still relevant to your company), and seeking compliance with the existing NIST 800-171 framework to give your company a leg up on eventual CMMC compliance. On November 4, 2021, the DoD announced several updates and changes with the introduction of “CMMC 2.0,” which clarifies how CMMC will be implemented. Elevate can make the process of becoming compliant much less painful by preparing your firm for your formal assessment by a certified C3PAO with a thorough CMMC Gap Assessment with remediation advice. Contact us today and let Elevate take the heavy lifting out of CMMC! Read the complete article by Tony Bai: https://a-lign.com/articles/blog-cmmc-2-0-updates/

Is the CMMC Leaning Towards Self Certification for 2022?

CMMC Self Certification

In this article, we the progress toward CMMC Self Certification. That is the question that everyone is placing a major bet on. Unfortunately, the CMMC has not offered much information on when they will be releasing the CMMC Certified Professionals training classes required to become CMMC Certified Professionals and Certified Assessors. According to the CMMC frequently asked questions classes were supposed to be authorized in mid-to-late summer 2021. To date, only four authorized C3PAOs are currently announced on Marketplace, and we still are yet to see what a successful CMMC audit entails. The good news is that since no audits have been completed, no company is yet to fail the DIBCAC ML3 assessment. Nonetheless, progress is still being made (at minuscule levels). Currently, there are 67 C3PAO Candidates pending CMMC ML3 Assessment. Background checks are in process and there are 45 approved Licensed Training Providers. Meanwhile, the list of Registered Practitioners (RP) and respective Registered Provider Organization (RPO) continues to grow. All signs are showing commitment to the CMMC and we are advising our clients to continue to prepare for some level of certification come 2022. Whether you are currently in the assessment process or you are considering becoming certified next year, we advise you to be familiar and compliant with the established CMMC Ethics. Based on the September CMMC Town Hall over 9 discrete allegations of improper conduct/conflict-of-interest and ethics violations by CMMC-AB Board members were addressed. As you can imagine, the CMMC is taking this very seriously and will no doubt emphasize compliance with the Code of Ethics for all board members as well as applicants going forward. Underlying the spirit of the CMMC are baseline principles that establish the high standards of honesty and integrity required to operate within the CMMC Ecosystem. The CMMC has taken great care to construct its Code of Ethics, which is intended to provide a guideline for acceptable business practices. This is applicable and expected for all entities that facilitate cyber security services both domestic and internationally and includes all major regulatory agencies and all entities wishing to successfully bid on any DoD contract requiring CMMC. The CMMC Code of Ethics is amplified and supported by the CMMC Code of Conduct, which outlines specific requirements in the following areas: • Promotion of Good Practices• Professional Representation• CMMC-COE Assignments• Regulations• Competencies• Client Interests• Sanctions• Ethics• Responsible Reporting Additionally, it’s important to remember that at this time, the CMMC does not allow for self-attestation of compliance. As more C3PAOs join the marketplace, a larger number of companies will be working towards becoming certified in order to remain viable contractors and continue to participate in bidding on all government contracts. Ensure yours is one of the initial organizations to achieve the status of being CMMC certified, assuring less competition when bidding DoD contracts that require CMMC. Keep in mind that preparation for this assessment can be intricate and time-consuming. In order to take the first step towards assessment, it is prudent to candidly evaluate your organization’s current level of cybersecurity by conducting a Gap Assessment. Elevate can make the process of becoming compliant much less painful by preparing your firm for your formal assessment by a certified C3PAO with a thorough CMMC Gap Assessment with remediation advice. Contact us today and let Elevate take the heavy lifting out of CMMC!

Are you ready to Attest to the 12/31/21 Federal Reserve Bank’s Security Standard?

New FedLine Standard

In this article, we discuss the New FedLine Standard. Starting December 31st, 2021, all institutions that use FedLine Advantage or FedLine Web are required to annually self-certify that their organization meets the Federal Reserve Bank’s security Standards.  Depending on the environment and tools used, institutions may have to certify to over 50 controls.  As with most modern security frameworks, the self-assessment is risk-based.  However, at the discretion of the Federal Reserve Bank, independent validation by third parties or internal audit functions may be required.   The requirements for the assurance program are outlined in the Federal Reserve Operating Circular No. 5.  The program is focused on reducing the risk of fraudulent payments being sent through the systems.  The scope of the program could extend not only to institutions but to potential service providers as well.   The Federal Reserve Bank has followed in the footsteps of the SWIFT (Society for Worldwide Interbank Financial Telecommunication) CSCF and has announced the development and implementation of a Security & Resiliency Assurance Program (“Assurance Program”). The assurance program is a collection of controls that stem from both the FedLine Advantage Security and Control Procedures and the FedLine Web Security and Control Procedures. Institutions can access these documents via the EUAC Center in FedLine Home. The self-assessment consists of the following steps: Click here for an overview of how to self-certify to the FedLine Solutions Security and Resiliency Assurance Program.  Need help in determining your institution’s scope and assessment of compliance with the Assurance Program?  We Can Help!  Our teams of IT Security and IT Compliance advisors can work with you to assess your internal environment, determine the scope of controls applicable to your institution, based on your risks, and perform a comprehensive review and validation of your controls’ in accordance with the Fedline SRAP guidelines.  Call us for more information to get your organization started on the way to compliance with the Federal Reserve Banks. 

PCI DSS v4.0 Update – Major Security Changes to the Payment Industry 

PCI DSS v4.0 Update

Rapid changes in how payments are made, seemingly constant technology upgrades, and the relentless pursuit of providing secure transactions are all driving the PCI DSS v4.0.  Originally scheduled for release in Q2 of 2021, the PCI Security Standards Council (SSC) has recently revised the PCI DSS v4.0 publication date to Q1 2022.  After three rounds of Request for Comments (RFC) and reviewing thousands of comments, we can expect a massive impact on the standard. Given the significance of this revision, a preview of the draft standard will be provided to Participating Organizations, QSAs, and ASVs sometime in January 2022.  While those involved in the review are not allowed to disclose the details, we do know that security is at the forefront. The primary drivers are: Meeting the payment industry’s security needs Providing flexibility and scalability to support evolving methodologies Making security a continuous process Enhancing security control validation methods While we don’t have specifics on the changes, we have been reassured that the 12 core PCI DSS requirements will fundamentally remain the same. Under similar standards, the requirements statements will be more “outcome-based”, the control objectives will be clear, and the guidance column will be enhanced. What do the primary drivers mean? Meeting the payment industry’s security needs – With new technologies like cloud computing and an increase in outsourcing of services, PCI will release additional guidance with cloud and third-party considerations, which will require companies to rethink and validate their own scope and approach. Ever-changing cyber risks will require additional protection of cardholder data (while at rest and in motion), additional anti-phishing and social engineering, more robust risk assessments, and stricter recommendations for authentication like multi-factor, yet adaptable to the various authentication options.  Finally, the Council has mentioned that when applicable, cloud technology will be considered in the new standard. Appendix A1 where guidance for the providers of shared hosting technology will also be considered. Providing flexibility and scalability to support evolving methodologies – Historically, secure companies had difficulty meeting defined or fixed requirements and often had to find compensating controls. These instances will be reduced by providing a customized approach. This includes tailored requirements and testing procedures. As an example, companies may secure networks differently, under a plethora of solutions, settings, and controls. The customized approach will enable companies to demonstrate how the risks and objectives are met, regardless of the solutions, settings, or controls in place. Making security a continuous process – The goal of the PCI DSS requirements has always been to design a secure and sustainable environment, following best practices. While some companies adopted this mindset, others are just focused on passing. We expect the new guidance to reinforce security as part of the business-as-usual, by requiring larger sample sizes, larger periods of coverage, or increased frequency of testing. Enhancing security control validation methods – Based on the customized approach within the methodology, PCI will align the validation methods. It seems straightforward, but the switch from assessing compensating controls (in the absence of standard requirements) to customized controls may require targeted risk assessments and testing procedures, developed by the QSA, and agreed upon by the business. It’s unclear how, but we can expect consistency in the SAQ and the AOC, in alignment with the methodology updates. Customization may be more suited for companies with secure and mature environments. Revised PCI DSS v4.0 Development and Transition Timeline When PCI DSS v4.0 is first released, v3.2.1 will remain active for an 18-month grace period, to allow for companies to gradually become compliant with baseline or immediate requirements. Additional requirements will be introduced under a phased approach, with dates in the future. “Future-dated” requirements are deemed to be “best practices” until the final date is reached. What this means to companies is that best practices should be assessed, but not fully implemented until the final date.  While don’t know the exact date of transition from “best practices” to required implementation for each of the new requirements, the timeline is expected to be between 2½ – 3 years after the transition period has expired. While organizations have plenty of time to implement the various phases of PCI DSS v4.0, a roadmap should be in place sooner rather than later. Embrace the change and stay tuned for updates on evolving requirements and process improvements.

Major Update – ISO/IEC 27002:2022 Published

ISO 27002 Major Update

In this article, we look at the ISO 27002 Major Update. A Brief History of ISO (ISO 27002 Major Update) The origins of the ISO 27001/2 standard go back more than 20 years stemming from the British Standard BS 7799 Part 1 and 2, first published in the late 1990s. In 2000, ISO adopted the ISO 17799 standard and then renumbered it to the current standard reference: ISO 27001/27002. In late 2013, the current standard ISO27001:2013 was published. While the name has changed a few times, the structure of this internationally revered set of control standards has remained intact until now: DIS 27002. Why is ISO Important? The rise in cyber-threats and the increased need for information security places emphasis on organizations concentrating efforts on protecting sensitive data by implementing the security standards provided by the International Organization for Standardization or specifically, ISO 27001/27002. ISO 27001 is a favored standard in establishing an Information Security Management Systems (ISMS), used in maintaining and managing technical, physical, and lawful controls. With over two decades as an established and predictable security control framework, the ISO 27001/27002 is finally getting a facelift. What are the Changes? Reorganization: The ISO 27002 major update will be a reorganization of the existing framework controls. The recognizable 14 control domain structure is no longer in use. This structure will be replaced by 4 chapters serving as the base for all framework controls. Each framework control will be classified as one of the following: organizational, people, technological, and physical. The recognizable 14 control domain structure is no longer in use. Control Reduction: Through a combination of consolidation and enhancement, the original total of 115 Annex A control has been reduced to 93. Many of the remaining controls have been revised, and the new protocol includes an introduction of 11 brand-new controls and one control was removed. Control Attributes: Each control will have 5 characteristics that will provide the ability to have alternate refined views, depending on the medium being utilized: a database, spreadsheet, or application. Do I Need to Update My ISMS? Not yet.  The ISO 27002 major update is just a Code of Practice.  This means you cannot certify against it.  However, it is also expected that the ISO 27001:2013 will be updated shortly after.  What You Need to Do Now: Now is the time to take notice of this action and have conversations on how these changes will impact your ISMS. While imminent changes are not going to be necessary – this year, it is important to look ahead and be prepared, as this might affect your company during your next re-certification time. The earliest that an organization would need to adopt and adhere to the updated framework would be one year after the new ISO 27001 code of practice has been approved and released, which is likely to occur towards the end of 2021/early 2022. The expectation is that the updated ISMS framework integration would coincide with the organization’s recertification date. There are significant alterations in the structure of the DRAFT DIS 27002, which will, in turn, impact the organization’s infrastructure, processes, and maintenance within the ISMS. Therefore, the earlier businesses can begin to analyze their existing ISMS protocol and compare this to the proposed changes in the ISMS, the smoother the transition when the time comes for recertification. For detailed information on how this change could impact your ISMS, Contact Your ISO Expert. Details on the Control Changes 4 New Control Chapters containing 93 controls: Chapter 5 Organization (37 controls) Chapter 6 People (8 controls) Chapter 7 Physical (14 controls) Chapter 8 Technological (34 controls) 5 Control Attributes: Control Type (preventive, detective, corrective) Information Security Properties (confidentiality, integrity, availability) NIST Cyber Security Concept (identify, protect, detect, respond, recover) Operational Capabilities (governance, asset management, physical security – 15 in total) Security Domains (governance and ecosystem, protection, defense, and/or resilience) 11 New Controls Added: Threat intelligence Information security for use of cloud services Information and communication technology (ICT) readiness for business continuity Physical security monitoring Configuration management Information deletion Data masking Data leakage prevention Monitoring activities Web filtering Secure coding 1 Control Removed: Removal of assets Various controls relating to the following 22 topics have been combined to reduce redundancy: Policies for information security Information security in project management User endpoint devices Inventory of information and other associated assets Acceptable use of information and other associated assets Information transfer Storage media Access control Authentication information Access rights Monitoring, review, and change management of supplier services Information security during disruption Identification of legal, statutory, regulatory, and contractual requirements Compliance with policies and standards for information security Information security event reporting Management of technical vulnerabilities Logging Installation of software on operational systems Application security requirements Security testing in development and acceptance Separation of development, test, and production environments Change management

Are You Ready for the 5-Tiered CMMC Framework this Fall?

CMMC Framework

Since November 30, 2020, the interim rule issued by the DoD initiated a 5-year phased rollout, introducing the new CMMC Framework Requirement in government RFPs, which builds upon the previous standard NIST 800-27001 by adding additional security controls. Matthew Travis, the freshly-minted CEO of the CMMC Accreditation Body, declared in April’s Town Hall that the 5-tiered CMMC Framework is ready for rollout.  Starting last winter, the DoD began stating the required CMMC level in the RFP with 15 contracts expected to see the change by the end of FY2021.  All DoD contractors and subcontractors will need to be certified to bid on DoD requests for proposals. Keep in mind, that self-assessment is no longer allowed.  Contractors must receive independent assessments from a qualified 3rd party assessor, or a C3PAO. Applications to become a C3PAO – an entity licensed to perform CMMC Assessments – are being received steadily with hopes to have a fully operational certification program by the latter part of 2021.  It is estimated that approximately 60% of all awarded contracts currently require the lowest CMMC Level 1 certification, which is considered “basic cyber hygiene” in contracts containing Federal Contract Information (FCI). Contractors who specifically create or access Controlled Unclassified Information (CUI), must qualify at the CMMC Level 3 which is considered “good cyber hygiene”.  Contractors having to comply at the highest level, CMMC Level 5 requirement, is far less likely.  The main focus of the advanced or progressive level is to protect CUI from Advanced Persistent Threats (APTs).  The CMMC certification is not optional. The program is designed to force companies doing business with the US Government to comply with a standard baseline of cybersecurity controls. To prepare for a 3rd party CMMC assessment, you should ensure your company has a documented System Security Plan and Plan of Action in place.  We recommend our four-phased approach for CMMC certification:  This is where Elevate can help! We can do the legwork for you. Elevate is already familiar with all tiers of the CMMC, and can assist in evaluating your company’s current System Security Plan (SSP) and Plan of Action and Milestones (POA&M), advise on areas that need improvement, and provide a plan of action to achieve CMMC readiness. Click here to learn more about our CMMC Readiness services. 

The Skinny on your SWIFT CSCF v2021 Independent Assessment

SWIFT CSCF v2021

Every year since, SWIFT has been building on its Customer Security Controls Framework (CSCF), continuously fighting against existing and emerging cyber threats.  But the fight is not over.  From self-attestation to organizing your independent assessment, here’s the skinny on what you need to keep your systems safe and in compliance for 2021.   What you need to look out for in v2021 The impacts of the CSCF v2021 are among some of the largest affecting technology systems in the banking and financial services industry, so it is essential to begin your assessment now. The CSCF v2021 is now composed of a maximum of twenty-two mandatory (22) and nine (9) advisory controls, depending on your architectural type. Not to mention, self-assessment will no longer suffice.  By December 31, 2021, all SWIFT institutions must have an independent assessment to support their self-assessed compliance with SWIFT CSCF v2021. Highlights of changes in CSCF v2021 include: Independent assessments may be performed by internal or external resources or some combination of both. The assessment should include a review of existing controls and their efficiency, and a confirmation that they support the customer’s compliance with the CSP control objectives.  The requirement is for an assessment, not an audit, so ensure your independent assessor is not charging you excessive audit fees.  Contact Us for a reasonable quote on an independent assessment fee or find us on the SWIFT directory of CSP assessment providers.   The three controls promoted to mandatory aim to protect and reduce potential vulnerabilities on critical interface components as well as critical systems where virtualization is being used more frequently. Next Steps to SWIFT CSCF v2021 Requirements The upcoming SWIFT Release’s requirements act as a catalyst for documenting the weaknesses in the structure and standards that underpin many IT systems. Often the more extensive the organization and the longer its IT history, the bigger challenges they face when updating its IT systems. As a result, organizations should take an approach that requires collaboration and strong leadership across the organization and a constant focus on improving cybersecurity controls to meet new requirements. A few considerations for the next steps are: How Can We Help? Elevate is listed as a CSP Assessment Provider in SWIFT’s official directory. We use our collective experience and in-depth knowledge of the CSCF to evaluate the risks associated with the SWIFT controls. Our team will work with you to perform a gap analysis of your SWIFT-related environment and provide a view of your controls’ current and desired state. The gap analysis can include testing controls to advise on their effectiveness and help you get ready for attestation. We will help your organization navigate the factors associated with implementing CSCF to become compliant. What is SWIFT The SWIFT system manages almost every international money and security transfer in the world.  The SWIFT system is a vast messaging network used by banks and other financial institutions to quickly, accurately, and securely send and receive money transfer-related information.  The system processes over 33 million transactions per day through its network.   SWIFT is a member-owned cooperative that provides safe and secure financial transactions for its members.  SWIFT membership consists of more than 11,000 institutions in over 200 countries.  Almost all forms of financial institutions from banks, to security dealers, to asset management companies, etc., are in some way using one or more SWIFT services.

Why You Should Care About NIST SP 800-53 Rev.5

NIST SP 800-53

In 2017, the National Institute for Standards and Technology (NIST) released an initial draft of the NIST SP 800-53 Rev. 5. Security and Privacy Controls for Information Systems and Organizations.  Three years later, on September 23, 2020, the NIST finally published revision number 5.  Both the public and private sectors rely on NIST guidance to provide a standardized approach to security assessment, authorization, and continuous monitoring for cloud products/services.  Specifically, this framework is key to achieving several certifications including FedRAMP, FISMA, CMMC, CMS EDE, and DE Pathway audits.  It’s only a matter of time before all IT security and privacy compliance/certifications will incorporate this new guidance (e.g. HITRUST, GDPR, CCPA, etc.). To set the tone, this revision (NIST SP 800-53 Rev. 5) is long overdue, as the last major update was over seven years ago in 2013. In fact, revision 5 should be renamed “The Renovation”, as both structural issues and technical content have been addressed within. The update represents a first-in-kind comprehensive catalog of privacy and security controls that is scalable to address organizations of all sizes and is as far-reaching to cover systems ranging from supercomputers to Internet of Things (IoT) devices.  The controls are systematic in nature to ensure that critical systems, components, and services are not only secured but have the resilience to defend not only the United States’ interest in both economic and national security threats but all enterprises in all industries. The following highlights the most significant changes to the framework: Controls are outcome-based (as opposed to impact-based): For those not familiar with revision 4, this may seem like wordsmithing. However, this change is by far the most impactful.  The control statement is now removed from the entity responsible for satisfying the control (e.g., people, process, system) – thereby allowing the outcome of the control (i.e., ability to protect/secure) to demonstrate effectiveness.  This is great news for organizations that struggle with privacy compliance (e.g. GDPR or CCPA).  Typically, the regulation around those laws serves more as guidance, leaving a lot of ambiguity for individual organizations to interpret their control effectiveness.  NIST 800-53 Rev. 5 provides substantially increased clarity around privacy controls.  For continuity purposes, Appendix C, Control Summaries provides a map between the new guidance and revision 4 by adding the “implemented by [entity]” column. Integration of privacy controls with security controls: Privacy takes a starring role in revision 5, with the intent of integrating privacy considerations into the system design and implementation process. Whereas revision 4 contained a separate appendix for privacy controls, revision 5 integrates privacy control families into existing security controls, as well as newly-created joint security and privacy controls. The unified consolidated control catalog allows controls to serve security and privacy risks from both an assurance and functional perspective.  Basically, the control catalog is more dynamic with the intent to reflect a holistic outcome of a single control that serves multiple purposes.  The control catalog also provides a summary and mapping tables. Increase of controls in Program Management: The Program Management (PM) control family includes 16 new controls – almost doubled from revision 4. This increase is primarily driven by the promotion of developing privacy programs to incorporate new privacy controls. Integrating supply chain risk management: A new Supply Chain Risk Management (SR) control family has been added. Also, elements of supply chain risk management have been integrated with cybersecurity approaches. This change impacts the Cybersecurity Framework and throughout all other control families to protect the procurement of system components, products, and services that support critical infrastructure and networks. The separation between the control selection process and the controls: the consolidated control catalog allows controls to be used on a stand-alone basis by different “communities of interest” (e.g. system engineers, security architects, enterprise architects, software developers, business owners, etc.). The intention is to allow collaboration among various stakeholders where process intersects and select from a unified control catalog to consistently manage risk throughout the organization. Created a comprehensive set of security and privacy control baselines: Control baselines have been carved out into a separate document: NIST SP 800-53B, Control Baselines for Information Systems and Organizations. There are three security control baselines for low, moderate, and high impact.  The privacy baseline is applied irrespective of the level of impact.  Also, the guidance provides working assumptions to assist organizations with the control selection process.  Finally, the guidance is designed to be scalable across various “communities of interest”, technologies, and various operating environments to promote widespread adoption. Enhanced content relationship descriptions: The description between requirements and controls as well as the difference between security and privacy controls have been enhanced to provide further clarification. The emphasis is on guiding the user on selecting versus implementing controls at the enterprise level or as part of the system development life-cycle. Incorporating new state-of-the-practice controls: To address the rapidly evolving cyber threats, new safeguards and countermeasures are added with a specific focus on protecting individuals’ privacy and personally identifiable information (PII). The new privacy controls focus on the latest threat intelligence and cyber-attack data (e.g., controls to support cyber resiliency, secure systems design, security and privacy governance, and accountability). Assigning senior IT management to the entire control family: The intent of this mandate is to assign accountability and ownership to each control and specifically to the control outcome. However, in practice, especially in project-based organizations, assigning one individual to own control that impacts multiple disciplines, products and projects may not be feasible. Expanding the definition of “systems”: To be more comprehensive of all privacy and security threats, the term “systems” was expanded from information systems to all systems including industrial or process control systems, cyber-physical systems, weapons systems, and the internet of things (IoT) devices. Removal of the word “Federal” from the title for broader adoption of the private sector: In efforts to promote widespread adoption by both the public and private sector, the word “Federal” has been removed from the title. While only federal systems require the NIST framework, the intent is to promote broader adoption by the private sector. Click here to get updates on additional supplemental NIST materials that will also be available soon, including: