Subscribe

Ukraine Crisis Resource Center

NIST Seeking Input on Potential Cybersecurity Framework Update

March 10, 2022

The National Institute of Standards and Technology (NIST) has published an RFI (87 Fed. Reg. 9,579) seeking stakeholder input on two major cybersecurity fronts:

  1. the "use, adequacy, and timeliness" of NIST's existing Cybersecurity Framework (CSF), and
  2. current and anticipated "supply chain-related cybersecurity needs," for NIST’s National Initiative for Improving Cybersecurity in Supply Chains (NIICS).

The RFI response deadline is April 25, 2022.

Regarding the CSF, NIST has asked organizations to identify the major benefits and drawbacks they have realized in implementing the CSF since its publication in April 2018. While NIST has yet to announce plans to formally update the CSF, NIST's RFI notes that since the CSF's publication, much has "changed in the cybersecurity landscape in terms of threats, capabilities, technologies, education and workforce." Along the same lines, NIST also recognizes that there is an increased "availability of resources to help organizations better manage cybersecurity risk."

NIST has compiled a non-exhaustive list of possible topics to be addressed in stakeholder comments on the CSF. Primary subjects include the following:

  • the benefits of the CSF and how to measure those benefits;
  • challenges to using the CSF;
  • areas of the CSF that should be changed or removed; and
  • if NIST does change the CSF, would backwards compatibility problems arise.

NIST is also seeking stakeholder input on how organizations use the CSF with "other risk management resources," such as those published by NIST or other organizations. Topics in this category on which NIST is seeking input include:

  • organizations' use of non-NIST frameworks together with the CSF;
  • how to encourage international adoption of the CSF; and
  • new terms or concepts for inclusion in NIST's Online Informative References Program.

Regarding the NIICS, NIST is seeking information, generally, on (1) what cybersecurity gaps organizations are encountering in managing supply chains, (2) how organizations have been addressing these gaps, and (3) the steps NIST could take to help organizations in this effort. NIST writes that stakeholder comments “will inform the direction of the NIICS,” which the organization has explained is part of NIST’s broader effort to fulfill the Biden administration’s May 12, 2021, Executive Order (14028) on Improving the Nation’s Cybersecurity. NIICS-related topics that NIST has identified for comment include:

  • the major cybersecurity challenges of supply chain risk management that the NIICS might address;
  • the approaches and tools that organizations currently use to manage cybersecurity-related risks in supply chains;
  • present gaps in cybersecurity supply chain risk management, whether these appear in NIST resources or otherwise;
  • how cybersecurity supply chain risk management could be addressed in an updated CSF.

RFI comments will inform NIST as it seeks to bolster the CSF and NIICS in response to significant developments in both the cybersecurity landscape and organizations’ cybersecurity resource offerings since 2018. In particular, NIST’s RFI targets stakeholder feedback on the interoperability of the CSF, and organizations’ related, diverse needs in securing supply chains.

For more information, please contact the professional(s) listed below, or your regular Crowell & Moring contact.

Evan D. Wolff
Partner – Washington, D.C.
Phone: +1.202.624.2615
Email: ewolff@crowell.com
Alexander Urbelis
Senior Counsel – New York
Phone: +1.212.895.4254
Email: aurbelis@crowell.com
Garylene (Gage) Javier, CIPP/US
Associate – Washington, D.C.
Phone: +1.202.654.6743
Email: gjavier@crowell.com

Ukraine Crisis Contacts

Antitrust

Shawn R. Johnson
Partner – Washington, D.C.
Phone: +1.202.624.2624
Email: srjohnson@crowell.com

Learn more about our Antitrust & Competition practice.

Aviation

Eileen M. Gleimer
Partner – Washington, D.C.
Phone: +1.202.624.2840
Email: egleimer@crowell.com

Learn more about our Aviation practice.

Corporate

Bryan Brewer
Partner – Washington, D.C.
Phone: +1.202.624.2605
Email: bbrewer@crowell.com
Jennifer K. Grady
Partner – New York
Phone: +1.212.530.1893
Email: jgrady@crowell.com
Frederick (Rick) Hyman
Partner – New York
Phone: +1.212.803.4028
Email: fhyman@crowell.com
Richard J. Lee
Partner – New York
Phone: +1.212.530.1937
Email: rlee@crowell.com
Scott Lessne
Senior Counsel – Washington, D.C.
Phone: +1.202.624.2597
Email: slessne@crowell.com
Timothy E. Lin
Partner – New York
Phone: +1.212.530.1921
Email: tlin@crowell.com
Kevin Rubinstein
Partner – New York
Phone: +1.212.530.1818
Email: krubinstein@crowell.com
Cathryn Williams
Partner – London
Phone: +44.20.7413.1345, +44.07775.900050
Email: cewilliams@crowell.com

Learn more about our Corporate & Transactional practice.

Cybersecurity

Evan D. Wolff
Partner – Washington, D.C.
Phone: +1.202.624.2615
Email: ewolff@crowell.com
Alexander Urbelis
Senior Counsel – New York
Phone: +1.212.895.4254
Email: aurbelis@crowell.com

Learn more about our Privacy & Cybersecurity practice.

Financial Services

Carlton Greene
Partner – Washington, D.C.
Phone: +1.202.624.2818
Email: cgreene@crowell.com
Andrew J. Knight
Partner – London
Phone: +44.20.7413.1366
Email: aknight@crowell.com
Richard J. Lee
Partner – New York
Phone: +1.212.530.1937
Email: rlee@crowell.com
Michael D. Mann
Partner – Washington, D.C.
Phone: +1.202.261.2990
Email: mmann@crowell.com
Andrew M. Martin
Partner – London
Phone: +44.20.7382.4890
Email: amartin@crowell.com
William Q. Orbe
Partner – New York
Phone: +1.212.530.1850
Email: worbe@crowell.com
Gregory Gennady Plotko
Partner – New York
Phone: +1.212.530.1924
Email: gplotko@crowell.com

Learn more about our Financial Services practice.

Government Affairs

James G. Flood
Partner – Washington, D.C.
Phone: +1.202.624.2716
Email: jflood@crowell.com
Kate Beale
Senior Policy Director – Washington, D.C.(CMI)
Phone: +1.202.508.8997
Email: KBeale@crowell.com

Learn more about our Government Affairs practice.

Government Contracts

Robert J. Sneckenberg
Partner – Washington, D.C.
Phone: +1.202.624.2874
Email: rsneckenberg@crowell.com
Peter Eyre
Partner – Washington, D.C.
Phone: +1.202.624.2807
Email: peyre@crowell.com
Laura J. Mitchell Baker
Counsel – Washington, D.C.
Phone: +1.202.624.2581
Email: lbaker@crowell.com
Christopher D. Garcia
Counsel – Washington, D.C.
Phone: +1.202.688.3450
Email: cgarcia@crowell.com
Rina M. Gashaw
Associate – Washington, D.C.
Phone: +1.202.624.2827
Email: rgashaw@crowell.com
Allison Skager
Associate – Los Angeles
Phone: +1.213.310.7957
Email: askager@crowell.com

Learn more about our Government Contracts practice.

Global Mobility

Nicole Janigian Simonian
Partner – Los Angeles, Shanghai
Phone: +1.213.310.7998
Email: nsimonian@crowell.com

Learn more about our Global Mobility practice.

Insurance

Laura Foggan
Partner – Washington, D.C.
Phone: +1.202.624.2774
Email: lfoggan@crowell.com

Learn more about our Insurance / Reinsurance practice.

International Trade/Sanctions/Export Control

John B. Brew
Partner – Washington, D.C.
Phone: +1.202.624.2720
Email: jbrew@crowell.com
Caroline E. Brown
Partner – Washington, D.C.
Phone: +1.202.624.2509
Email: cbrown@crowell.com
Carlton Greene
Partner – Washington, D.C.
Phone: +1.202.624.2818
Email: cgreene@crowell.com
Robert Holleyman
Partner and C&M International President & CEO – Washington, D.C.
Phone: +1.202.624.2505
Email: rholleyman@crowell.com
Michelle J. Linderman
Partner – London
Phone: +44.20.7413.1353
Email: mlinderman@crowell.com
Jeffrey L. Snyder
Partner – Washington, D.C.
Phone: +1.202.624.2790
Email: jsnyder@crowell.com
David (Dj) Wolff
Partner; Attorney at Law – Washington, D.C., London
Phone: +1.202.624.2548, +44.20.7413.1368
Email: djwolff@crowell.com
Robert Clifton Burns
Senior Counsel – Washington, D.C.
Phone: +1.202.688.3448
Email: cburns@crowell.com

Learn more about our International Trade practice.

International Dispute Resolution

Meagan T. Bachman
Partner – Washington, D.C.
Phone: +1.202.624.2722
Email: mbachman@crowell.com
Ian A. Laird
Partner – Washington, D.C.
Phone: +1.202.624.2879
Email: ilaird@crowell.com
John L. Murino
Partner – Washington, D.C.
Phone: +1.202.624.2663
Email: jmurino@crowell.com
Laurence Winston
Partner – London
Phone: +44.20.7413.1333
Email: lwinston@crowell.com

Learn more about our International Dispute Resolution practice.

Labor & Employment

Sadina Montani
Partner – Washington, D.C.
Phone: +1.202.508.8875
Email: smontani@crowell.com

Learn more about our Labor & Employment practice.

Technology & Brand Protection

Andrew J. Avsec
Partner – Chicago
Phone: +1.312.840.3260
Email: aavsec@crowell.com
Virginia Wolk Marino
Partner – Chicago
Phone: +1.312.840.3228
Email: vmarino@crowell.com

Learn more about our Technology & Brand Protection practice.

Tax

S. Starling Marshall
Partner – New York
Phone: +1.212.895.4263
Email: smarshall@crowell.com
Irina Pisareva
Partner – New York
Phone: +1.212.803.4067
Email: ipisareva@crowell.com

Learn more about our Tax practice.

Force Majeure

Bryan Brewer
Partner – Washington, D.C.
Phone: +1.202.624.2605
Email: bbrewer@crowell.com
Allyson McKinstry
Partner – New York
Phone: +1.212.803.4061
Email: amckinstry@crowell.com
Scott L. Winkelman
Partner – Washington, D.C.
Phone: +1.202.624.2972
Email: swinkelman@crowell.com
Laurence Winston
Partner – London
Phone: +44.20.7413.1333
Email: lwinston@crowell.com

White Collar

Michael K. Atkinson
Partner – Washington, D.C.
Phone: +1.202.624.2540
Email: matkinson@crowell.com
Michael J. Gunnison
Senior Counsel – Doha
Email: mgunnison@crowell.com

Learn more about our White Collar & Regulatory Enforcement practice.