FAIR Institute Blog

NIST Maps FAIR to the CSF - Big Step Forward in Acceptance of Cyber Risk Quantification

[fa icon="calendar"] Sep 13, 2019 9:01:00 AM / by Jeff B. Copeland

NIST CSF 1 1 LOGO copyToday marks a milestone in FAIR history as NIST has formally published FAIR as an Informative Reference to the NIST CSF, the most widely used cybersecurity framework in the U.S. This means that there is mapping between FAIR and the NIST CSF standard in the sections covering risk analysis and risk management.

The FAIR Institute has long since held that FAIR is a complementary standard to other information security frameworks. This is confirmation that organizations can be confident employing FAIR for their risk analyses alongside the other NIST CSF framework processes.

Jack Freund, PhD, co-author with Jack Jones of the FAIR book, Measuring and Managing Information Risk and Risk Science Director for RiskLens, has been working with NIST on behalf of the FAIR Institute to gain this recognition. Jack is also going to be moderating a panel discussion at the upcoming FAIR Conference, September 24-25, entitled “Building a Cybersecurity Program with a Risk Management Framework and FAIR.” This panel will have Kevin Stine, Chief of the Applied Cybersecurity Division of NIST, as well as Ian Amit, CSO of Cimpress (recently cited by NIST as a "success story" in integrating FAIR and NIST CSF), and will be a great opportunity to hear from people responsible for these standards and those that have implemented them.

The CSF is essentially a very thorough, step-by-step walk-through of defensive measures for cybersecurity, including risk assessment (RA) and risk management (RM).


An example of the mapping:


ID.RA-4 Potential business impacts and likelihoods are identified

Is mapped to:

FAIR Risk Taxonomy:

C13K - 3.5 - Forms of Loss

"The potential for loss stems from the value of the affected asset(s) and/or the liability it introduces to an organization..." 

And it goes on to discuss the six forms of loss, familiar concepts to FAIR users.

"As the adoption of the NIST CSF has taken hold," says Nick Sanna, President of the FAIR Institute, "users of the framework found themselves in need of prioritizing the many activities the framework recommends as best practices. They needed to justify investments to management and to ultimately meet the requirements for building an effective risk management program so that they can help an organization achieve an acceptable level of risk, cost-effectively. Cost-effective risk management is stated as a goal in the first page of the NIST CSF. FAIR brings that vision to fulfillment." 

Visit the NIST CSF website to see the new FAIR documentation in the Informative Reference Catalog.


NIST CSF and FAIR Integration at Cimpress Called “Success Story” by NIST

Webinar: Cimpress CSO Ian Amit Discusses NIST CSF-FAIR Integration

Learn about FAIR from the experts at the 2019 FAIR Conference - FAIRCON19 - September 24-25, National Harbor, MD, near Washington, DC. Get the details

Topics: FAIR, Risk Management

Jeff B. Copeland

Written by Jeff B. Copeland

Jeff is the Content Marketing Manager for RiskLens.

Register Now for FAIRCON19

Subscribe to Email Updates

Learn How FAIR Can Help You
Make Better Business Decisions

Recent Posts