Tools to help with new NIST framework

Promontory provides tools to exploit the new US cyber-security standards that help financial businesses defend against third party risks

  • 10 years ago Posted in

A new Web-based tool to assist companies in using a new cyber-security framework released by the National Institute of Standards and Technology (NIST) has just been announced by the Promontory Financial Group.

The company, headquartered in the USA capital, Washington, D.C., claims to be the world’s foremost expert in financial risk, regulation, and compliance. It helps companies and governments around the world manage complex risk and meet their regulatory challenges.

“Regulators have recently noted the potential for third-party vendors to represent a weak link in an institution’s overall information-security system”

The `Framework for Improving Critical Infrastructure Cyber-security’ was developed by NIST as directed in a February 2013 executive order in the USA that called for a voluntary, risk-based framework incorporating industry-leading practices and standards. Supervisors are likely to draw upon the framework when conducting examinations and updating their examination procedures.

It is widely expected to become a critical component of any rigorous cybersecurity program in both financial and nonfinancial institutions.

"Many firms with high-performing cyber-risk management functions are already using elements of the framework internally,” said Earl Crane, a senior principal at Promontory. “However, they are now starting to use the framework to communicate their requirements and hold accountable their vendors, third-party service providers, and outsourced operations.”

The flexible, Web-based Cyber-risk Assessment Tool allows financial institutions to identify, manage, and report on cyber-security risk, consistent with existing regulatory frameworks. The software, designed by industry experts and former compliance examiners, can be used to guide a company as it uses the NIST framework to improve its cyber-risk management programs and assess the cyber-security of third parties.

“Regulators have recently noted the potential for third-party vendors to represent a weak link in an institution’s overall information-security system,” Crane said. “We believe this is the first tool to use the framework to manage vendor cyber-risk and reduce third-party risk exposure.”

Though the NIST cyber-security framework is voluntary, it is already seen as emerging as one of the most important blueprints for cyber-risk management in regulated and non-regulated companies. Its existence helps companies use the framework in a robust, well-documented, and user-friendly way.

Fifty-three percent of technology companies say they need a cloud strategy for emerging...
New state-of-the-art data centre features Vultr’s first AMD GPU supercompute cluster.
Only a quarter (25%) think their approach to the cloud is carefully considered and successful.
Moving to AWS Cloud will enable The Co-operative Bank to adopt cutting edge IT Infrastructure.
The global airline group will upgrade the value of its data and get its AI & generative AI ready...
Barracuda Networks’s award-winning Email Protection and Cloud Backup security solutions will be...
Leading company in renewables to leverage HPE’s unique turnkey AI infrastructure solution to...
The four-year project extension focuses on cloud transformation and enhanced operational efficiency...