TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

NIST Releases Version 2.0 of Landmark Cybersecurity Framework

53 pointsby adrian_mrdabout 1 year ago

4 comments

badrabbitabout 1 year ago
I get why it exists but it turns companies into box checking machines. I haven&#x27;t read this new version so my skepticism may be unwarranted but hackers are not going to refrain from attacking because that&#x27;d go against NIST. A lot of the things that are best practice in the industry as a result of adapting to newer attacker techniques and capabilities are not covered by NIST. The problem then is anyone working on those countermeasures is working on stuff that has no value to execs who just want to know how compliant you are with NIST.<p>The CSF like ATT&amp;CK is just a tool, it can be abused or used properly and if you are a small company with no idea where to start with security or measure your posture it&#x27;s a good tool. But as a measuring stick of checkboxes, I can&#x27;t say I&#x27;m a big fan.
overstay8930about 1 year ago
Something else for IT people to ignore and then pikachu face when they get crypto locked because their 90 day password rotations didn&#x27;t work.
评论 #39544293 未加载
评论 #39543827 未加载
grumpyinfosecabout 1 year ago
GRC non-sense like this is really the cornerstone of cybersecurity. It seems like dumb boxchecking but these domains are the tools that we use to define, measure and most importantly sell security to management &#x2F; main IT &#x2F; users. The technical side is more sexy but then you discover that wack-a-moling the hot sploit of the week didn&#x27;t really build your posture beyond the low hanging fruit.
gatesbillzabout 1 year ago
The new Governance layer should help check the boxes.