The NIST Risk Management Framework

5/22/2019

The NIST Risk Management Framework

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

1

About me...

Joe Klein, CISSP...

Computer Scientist, MITRE Fellow, IPv6 Forum

International Speaker Inventor - Soon to be Author Auditor ? Assessor? Pen Tester ? Red Team Chief Security Officer ? IDS/Firewall geek - OSINT Dad and Granddad - Defcon Goon jsklein@ @JoeKlein KD4HAX

5/22/2019

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

2

Legal Disclosure

The author's affiliation with MITRE is provided for identification purposes only, and is not intended to convey or imply MITRE's concurrence with, or support for, the positions, opinions, or viewpoints expressed by

the author.

5/22/2019

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

3

RISK Management ? After the Fact

5/22/2019

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

4

Why Risk Management is Important

Government contractor can be sued under the False Claims Act when it misrepresents its compliance with cybersecurity-related contractual obligations, in this case SP 800-171 controls as required under the FAR/DFARS.

Reference:

5/22/2019

Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

5

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download