Measuring Security With Kpis Nist Framework
Question :
Create a report for the upper management of your chosen enterprise about the cyber security status using a set of KPIs associated with the four elements above and the four capability tiers described in detail in the NIST Framework.
Answer :
There are five functions – identity, protect, detect, respond, and recover. Under each function, lies several categories, and under each category, there are sub-categories. And then there are informative references that indicate the common standards and practices for critical infrastructure (Teodoro et al, 2015)
The first KPI is associated with Asset management. The company should not have any unidentified devices that are connected with the internal network. Currently, the organization does not have appropriate understanding about the devices that are connected within the internal network. Another KPI is related to access control, where the organization should have complete control over the individuals who have the access to different aspects of the data within the organization. Currently, the organization has access controls for the employees and each employee has his or her own username and password. However, there is a common occurrence of a situation where employees often share their credentials with other employees, which might be a problem. Another KPI is regarding continuous monitoring of security, wherein it is expected that the organization should be continuously monitored to detect any security issues. The current organization does not have any systems in place that continuously detects any intrusion and security loopholes. There is no implementation systems that can actively check on these aspects. It is likely to create challenges for the organization if security issues. In the past, the organization utilized log files to identify the problem, which was post-attack. Active monitoring could have throttled the threat before it could harm, but it is still lacking. Another KPI is the presence of appropriate communication channels should something suspicious occurs so that prompt actions can be taken. However, it has been found that the organization’s bureaucratic work style does not facilitate prompt response. So it can be said that organization is not performing well on this KPI as well. Another KPI is associated with recovery and improvements, where the organization is expected to make appropriate recovery planning and execute in when needed in an effective and time-bound manner. Recovery planning aspect of the organization is done if there is an attack but the execution aspect suffers severely. The actions that are required to be taken are not done in a timely manner. This impacts the ability of the organization in handling issues in a timely manner.
it can be said that the organization is expected to have appropriate risk management process along with the integrated program for awareness. However, it seems that there is substantial lacking on this aspect. Very few people are aware about the right actions that need to take in order to ensure that the security issues do not occur. There is very less awareness on IT security aspects. There is no formal risk management practices. Things are handled on ad hoc basis. Thus, it can be said that the organization is currently at Partial Tier (Aoyama et al, 2017).
The organization is failing on most of the KPIs that have originated from NIST framework. It can be said that there is a need to revamp most of the organizational aspects whether it is regarding inducting fresh talents, improving the existing infrastructure, or training the employees. There is a very strong need to do in depth assessment to understand the goals and needs of the organization and implement required resources. It these are not done in a timely manner, then there is huge possibility that the customers’ data may get compromised, and it will not only expose customers to security and privacy risks, it will also impact the reputation of the organization among the consumers, who would not want to come back to this organization to use its services. Improving these security aspects is likely to increase the trust of the customers for the organization and they would not get scared and run away.