NIST Updates Cybersecurity Framework (CSF)
Client Alert | 1 min read | 01.18.17
Last week, the National Institute of Standards and Technology (NIST) issued a draft update to the Framework for Improving Critical Infrastructure, also known as the “Cybersecurity Framework” or CSF. This Version 1.1 update includes (i) a new section addressing measurement and demonstration of cybersecurity; (ii) considerations regarding Cyber Supply Chain Risk Management (SCRM) added throughout the CSF; and (iii) clarification of existing key terms and concepts.
The proposed additions regarding cybersecurity measurement are intended to “get the conversation started” and help companies map their business outcomes to their cyber risk management practices. The update aims to enable organizations to produce meaningful cyber risk information to use in enterprise-level risk management decisions, which can also be conveyed to dependents, partners and customers as applicable. Supply chain-focused updates are intended to bolster existing sections of the CSF as well as develop a common vocabulary for cyber supply chain risk management across industries and project types.
Version 1.1 of the CSF is intended to be “fully compatible” with the existing Version 1.0. Comments on Version 1.1 must be submitted by April 10, 2017, and NIST intends to publish a final Framework Version 1.1 in the fall of 2017.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 5 min read | 09.02.26
DOJ’s Civil Rights Fraud Initiative Claims Another DEI-Related FCA Settlement
On Tuesday, August 25, 2026, the U.S. Department of Justice (DOJ) announced that Deloitte LLP and several of its subsidiaries agreed to pay, collectively, $21.5 million to resolve allegations that Deloitte violated the False Claims Act (FCA) by failing to comply with new anti-discrimination requirements incorporated into its federal contracts, by discriminating against employees and applicants on the basis of race and sex, and by allocating and seeking reimbursement for costs related to those practices under its federal government contracts. This resolution is the second of its kind under DOJ’s recently launched Civil Rights Fraud Initiative, following a similar settlement by IBM in April 2026.
Client Alert | 4 min read | 09.02.26
Client Alert | 7 min read | 09.02.26
OCC and FDIC Redefine “Unsafe or Unsound Practices”: The New Supervisory Framework for Banks
Client Alert | 4 min read | 09.02.26
The CSC Is Investigating: What Its New NIL Enforcement Memo Means for Institutions
