Tools to help with new NIST framework

Promontory provides tools to exploit the new US cyber-security standards that help financial businesses defend against third party risks

A new Web-based tool to assist companies in using a new cyber-security framework released by the National Institute of Standards and Technology (NIST) has just been announced by the Promontory Financial Group.

The company, headquartered in the USA capital, Washington, D.C., claims to be the world’s foremost expert in financial risk, regulation, and compliance. It helps companies and governments around the world manage complex risk and meet their regulatory challenges.

“Regulators have recently noted the potential for third-party vendors to represent a weak link in an institution’s overall information-security system”

The `Framework for Improving Critical Infrastructure Cyber-security’ was developed by NIST as directed in a February 2013 executive order in the USA that called for a voluntary, risk-based framework incorporating industry-leading practices and standards. Supervisors are likely to draw upon the framework when conducting examinations and updating their examination procedures.

It is widely expected to become a critical component of any rigorous cybersecurity program in both financial and nonfinancial institutions.

"Many firms with high-performing cyber-risk management functions are already using elements of the framework internally,” said Earl Crane, a senior principal at Promontory. “However, they are now starting to use the framework to communicate their requirements and hold accountable their vendors, third-party service providers, and outsourced operations.”

The flexible, Web-based Cyber-risk Assessment Tool allows financial institutions to identify, manage, and report on cyber-security risk, consistent with existing regulatory frameworks. The software, designed by industry experts and former compliance examiners, can be used to guide a company as it uses the NIST framework to improve its cyber-risk management programs and assess the cyber-security of third parties.

“Regulators have recently noted the potential for third-party vendors to represent a weak link in an institution’s overall information-security system,” Crane said. “We believe this is the first tool to use the framework to manage vendor cyber-risk and reduce third-party risk exposure.”

Though the NIST cyber-security framework is voluntary, it is already seen as emerging as one of the most important blueprints for cyber-risk management in regulated and non-regulated companies. Its existence helps companies use the framework in a robust, well-documented, and user-friendly way.

Formula 1 embraces Lenovo cooling technology to boost sustainability and performance in broadcast...
VOSS expands enterprise collaboration capabilities with AI, security, and monitoring tools.
Frore Systems highlights the AirJet Mini G2 as a solid-state cooling solution aimed at managing...
Infosys teams up with AWS to enhance enterprise capabilities using generative AI, with a focus on...
Siemens and NVIDIA are bringing AI into industrial processes, from design and engineering through...
CIMPOR, in collaboration with Vodafone Portugal and Ericsson, has completed a deployment of private...
Cognizant is set to acquire 3Cloud, enhancing its Azure and AI capabilities for enterprise AI...
Calitii, under Synechron, becomes a ServiceNow Elite Partner, reflecting its prowess in AI-driven...