
Using NIST for Security and Risk Assessment
by Thomas P. Dover
No club is reading this yet — be the first to start one
This book describes how NIST Special Publications (SP) 800-171r2 (Protecting Controlled but Unclassified Information in Nonfederal Systems and Organizations), SP.800-172 (Enhanced Security Requirements for Protecting Controlled Unclassified Information) and SP.800-172A (Assessing Enhanced Security Requirements for Controlled Unclassified Information) can be used to evaluate the cybersecurity posture of Information (IT) or Operation Technology (OT) systems and supporting frameworks. It will demonstrate that baseline security requirements outlined in SP.800-171r2 and SP.800-172/172A for the protection of Controlled Unclassified Information (CUI) can be applied to any information system requiring data protection.
It further presents the application of NISTIR 8228 to OT system assessment in order to determine relative compliance with recommended standards. This approach allows organizations to evaluate the level of risk an IoT device poses to information systems. It also reviews the current state of IoT cybersecurity and privacy protection using historical and current industry guidance & best-practices; recommendations by federal agencies; NIST publications; Executive Orders (EO) and federal law. Similarities and differences between IoT devices and “traditional” (or classic) Information Technology (IT) hardware will be offered along with challenges IoT poses to cybersecurity and privacy protection.
An explanation of how these NIST publications align with information security and how this alignment suffices for evaluating an IT environment security will be given along with the process and procedure for performing such evaluation.
A practical approach for applying NIST Special Publications (SP) and Internal Reports (NISTIR) to the security assessment of Information (IT) and Operational (OT) systems. Methodology addresses assessing security of systems containing Confidential but Unclassified Information (CUI) or Internet of Things (IoT) technology.Discuss Using NIST for Security and Risk Assessment with other readers
Join or start a book club for Using NIST for Security and Risk Assessment on Readfeed. Live chat, shared reading progress, and AI discussion questions — free to get started.
Frequently asked questions
How do I join a book club for Using NIST for Security and Risk Assessment?
Sign up free on Readfeed, then browse public clubs or start your own club with Using NIST for Security and Risk Assessment as the current read. Invite friends with a share link and discuss together with live chat and AI discussion questions.
Can I discuss Using NIST for Security and Risk Assessment with other readers online?
Yes. Readfeed book clubs let you chat live, share progress, and join discussions about Using NIST for Security and Risk Assessment with readers worldwide — whether your club is virtual, in-person, or hybrid.
Is Readfeed free?
Yes. Creating an account and joining book clubs is free. Sign up to find readers who love the same books and start discussing today.