Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Steve_Walker
Participant
Jump to solution

Compliance Check for NIST Cybersecurity Framework (CSF) 1.1 or 2.0

Does any one have a compliance check for NIST Cybersecurity Framework (CSF) 1.1 or 2.0 that could be imported into my compliance module?

Running R81.20.

Thanks -

Steve

0 Kudos
1 Solution

Accepted Solutions
Corinne_Vakulen
Employee
Employee

Hi Steve,

There are different 'flavors' of NIST frameworks. 'NIST CSF' is a high-level framework focused on risk management. The NIST frameworks we have mapped (i.e. NIST SP 800-53, NIST SP800-82, NIST 800-41, NIST 800-171 etc...) are actually detailed set of security controls for specific industries. NIST CSF provides a comprehensive set of best practices for organizations to follow, while NIST SP 800-53 for example, provides specific security controls that must be implemented.

If you can be more specific on the NIST framework you are looking for, we might be able to help.

TX

Corinne

View solution in original post

0 Kudos
7 Replies
the_rock
Legend
Legend

Not sure if below would have it...

Andy

https://community.checkpoint.com/t5/Compliance/bd-p/Compliance

0 Kudos
the_rock
Legend
Legend

@Steve_Walker I see few NIST listed there.

0 Kudos
(1)
Steve_Walker
Participant

Thanks - I'll dig around and see.

Steve

0 Kudos
the_rock
Legend
Legend

Apologies Steve, I did not go through all of them myself, but Im sure its most likely listed there.

Best,

Andy

0 Kudos
Corinne_Vakulen
Employee
Employee

Hi Steve,

There are different 'flavors' of NIST frameworks. 'NIST CSF' is a high-level framework focused on risk management. The NIST frameworks we have mapped (i.e. NIST SP 800-53, NIST SP800-82, NIST 800-41, NIST 800-171 etc...) are actually detailed set of security controls for specific industries. NIST CSF provides a comprehensive set of best practices for organizations to follow, while NIST SP 800-53 for example, provides specific security controls that must be implemented.

If you can be more specific on the NIST framework you are looking for, we might be able to help.

TX

Corinne

0 Kudos
Steve_Walker
Participant

Corinne - Thanks for the information.  I was looking for this as it came up in an SOW for a security assessment we were hoping to do this summer.  We ended up going with a different vendor, so this is no longer needed at this time.

Steve

0 Kudos
Corinne_Vakulen
Employee
Employee

Good luck Steve and don't hesitate to contact us again.

Corinne

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.