Cybersecurity, Privacy, & AI

Trending Now
Doxim Data Breach Settlement Underscores Third-Party Data Security Risk • SASC Proposes Reorganization of Pentagon’s IT, Cyber Leadership • Anthropic Suspends Top AI Models After U.S. Export Control Order • Senate Bill Seeks to Restore Funding for Cyber Information-Sharing Program • CISA Directive Orders Agencies to Prioritize Vulnerability Patching in a New Way

NIST Pushes on Next Version of “Risk Management Framework”

The National Institute of Standards and Technology looks to release the final version of its Risk Management Framework 2.0 early next year, and is working to get critical privacy controls worked into it, according to NIST Fellow Ron Ross, one of the initiative’s primary managers.

The work to get the RMF completed includes discussions with the White House’s Office of Information and Regulatory Affairs on the privacy additions. Ross says that those discussions are important because the latest version of the RMF will cover a number of critical areas, including supply chain and systems engineering, but also privacy.

RMF 2.0’s new privacy provisions address how organizations can assess and manage risks to data and systems by focusing on protecting individuals’ personally identifiable information.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.