NIST Updates Cybersecurity Framework (CSF)
Client Alert | 1 min read | 01.18.17
Last week, the National Institute of Standards and Technology (NIST) issued a draft update to the Framework for Improving Critical Infrastructure, also known as the “Cybersecurity Framework” or CSF. This Version 1.1 update includes (i) a new section addressing measurement and demonstration of cybersecurity; (ii) considerations regarding Cyber Supply Chain Risk Management (SCRM) added throughout the CSF; and (iii) clarification of existing key terms and concepts.
The proposed additions regarding cybersecurity measurement are intended to “get the conversation started” and help companies map their business outcomes to their cyber risk management practices. The update aims to enable organizations to produce meaningful cyber risk information to use in enterprise-level risk management decisions, which can also be conveyed to dependents, partners and customers as applicable. Supply chain-focused updates are intended to bolster existing sections of the CSF as well as develop a common vocabulary for cyber supply chain risk management across industries and project types.
Version 1.1 of the CSF is intended to be “fully compatible” with the existing Version 1.0. Comments on Version 1.1 must be submitted by April 10, 2017, and NIST intends to publish a final Framework Version 1.1 in the fall of 2017.
Contacts
 - Partner, Crowell Global Advisors Senior Director - Washington, D.C.- D | +1.202.624.2698
 
- Washington, D.C. (CGA)- D | +1 202.624.2500
 
 
Insights
Client Alert | 13 min read | 10.30.25
Federal and State Regulators Target AI Chatbots and Intimate Imagery
In the first few years following the public launch of generative artificial intelligence (AI) in the autumn of 2022, litigation related to AI focused primarily on claims of copyright infringement. Suits revolved around allegations that the data on which AI models train, and/or the output they produce, infringe upon the intellectual property rights of others. (While some of these cases have settled or reached preliminary judgments, many remain ongoing.)
- Client Alert | 3 min read | 10.30.25 - Is Course Hero Heading to Summer School After Summary Judgment Loss? 
- Client Alert | 6 min read | 10.29.25 - Enhancing UK cyber security resilience and leadership engagement 
- Client Alert | 9 min read | 10.28.25 - Key Takeaways from a Consequential Month of Russia-Related Sanctions 
