<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The New Math: DoD Estimates Costs for Implementing NIST SP 800-171B in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/The-New-Math-DoD-Estimates-Costs-for-Implementing-NIST-SP-800/m-p/23934#M1403</link>
    <description>&lt;P&gt;The Initial Public Draft (IPD) for&amp;nbsp;&lt;EM&gt;&lt;A href="https://csrc.nist.gov/publications/detail/sp/800-171b/draft" target="_blank" rel="noopener"&gt;NIST Special Publication (SP) 800-171&lt;STRONG&gt;B,&lt;/STRONG&gt;&lt;/A&gt;&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations: Enhanced Security Requirements for Critical Programs and High Value Assets&lt;/EM&gt; was&amp;nbsp;released today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This standard represents additional security control requirements to protect&amp;nbsp;Controlled Unclassified Information (CUI) in nonfederal systems and organizations when the CUI is part of a critical program or high value asset. Basically, all of the Advanced Persistent Threat (APT) related controls where removed from the original standard and put here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What makes this call for public comment different is that the DoD has provided a &lt;A href="https://csrc.nist.gov/CSRC/media/Publications/sp/800-171b/draft/documents/sp800-171B-and-dod-cost-estimate-request-for-comments.pdf" target="_blank" rel="noopener"&gt;Cost Analysis&lt;/A&gt;&amp;nbsp;for implementing the controls. The document is "enlightening" as to how DoD thinks. Network isolation costs are estimated more than the long-term costs of running a Security Operations Center, go figure that one out...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, this is all about being proactive and shutting down the Defense Industrial Base. Booyah! It remains to be seen whether or not these "estimates" are reasonable and the controls in fact are the best ones to protect CUI from "&lt;STRONG&gt;the APT&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ps.&amp;nbsp;@&lt;SPAN class="login-bold"&gt;&lt;A href="https://community.isc2.org/t5/user/viewprofilepage/user-id/89787937" target="_self"&gt;SamanthaO_isc2&lt;/A&gt;&amp;nbsp;we really need a "Location" for "Standards" discussions. Can you make that happen? Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:14:25 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2023-10-09T09:14:25Z</dc:date>
    <item>
      <title>The New Math: DoD Estimates Costs for Implementing NIST SP 800-171B</title>
      <link>https://community.isc2.org/t5/Tech-Talk/The-New-Math-DoD-Estimates-Costs-for-Implementing-NIST-SP-800/m-p/23934#M1403</link>
      <description>&lt;P&gt;The Initial Public Draft (IPD) for&amp;nbsp;&lt;EM&gt;&lt;A href="https://csrc.nist.gov/publications/detail/sp/800-171b/draft" target="_blank" rel="noopener"&gt;NIST Special Publication (SP) 800-171&lt;STRONG&gt;B,&lt;/STRONG&gt;&lt;/A&gt;&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations: Enhanced Security Requirements for Critical Programs and High Value Assets&lt;/EM&gt; was&amp;nbsp;released today.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This standard represents additional security control requirements to protect&amp;nbsp;Controlled Unclassified Information (CUI) in nonfederal systems and organizations when the CUI is part of a critical program or high value asset. Basically, all of the Advanced Persistent Threat (APT) related controls where removed from the original standard and put here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What makes this call for public comment different is that the DoD has provided a &lt;A href="https://csrc.nist.gov/CSRC/media/Publications/sp/800-171b/draft/documents/sp800-171B-and-dod-cost-estimate-request-for-comments.pdf" target="_blank" rel="noopener"&gt;Cost Analysis&lt;/A&gt;&amp;nbsp;for implementing the controls. The document is "enlightening" as to how DoD thinks. Network isolation costs are estimated more than the long-term costs of running a Security Operations Center, go figure that one out...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, this is all about being proactive and shutting down the Defense Industrial Base. Booyah! It remains to be seen whether or not these "estimates" are reasonable and the controls in fact are the best ones to protect CUI from "&lt;STRONG&gt;the APT&lt;/STRONG&gt;".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ps.&amp;nbsp;@&lt;SPAN class="login-bold"&gt;&lt;A href="https://community.isc2.org/t5/user/viewprofilepage/user-id/89787937" target="_self"&gt;SamanthaO_isc2&lt;/A&gt;&amp;nbsp;we really need a "Location" for "Standards" discussions. Can you make that happen? Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:14:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/The-New-Math-DoD-Estimates-Costs-for-Implementing-NIST-SP-800/m-p/23934#M1403</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:14:25Z</dc:date>
    </item>
  </channel>
</rss>

