NIST Publishes Updated Draft To Cybersecurity Framework

WASHINGTON—The National Institute of Standards and Technology (NIST) has published an updated draft of its cybersecurity framework.

The draft places more emphasis on using external data sources to inform risk management, reported NAFCU, which supports the move.
 
Comments on the draft are due to NIST by Jan. 19.
 
This draft also gives a better description of supply chain risk management and modifies a section – "Methodology to Protect Privacy and Civil Liberties" – which warns of risks associated with over collection of user data, NAFCU explained.
 
NIST released its cybersecurity framework in 2014, which NAFCU has urged the agency to keep voluntary.

“NAFCU-supported updates were made to the framework in April. Many credit unions have benefited from NIST's framework as it has aided in the development of the Federal Financial Institutions Examination Council's cybersecurity assessment tool. The NCUA's future cybersecurity examination procedures may also mirror the cybersecurity assessment tool's structure,” NAFCU said.
 
NAFCU said that it continues to urge NIST to work with other regulators and industry stakeholders to clarify how the framework should be used or adopted, and emphasize that there is no one-size-fits-all approach to cybersecurity. The association also asks NIST to use its expertise to educate lawmakers and regulators about emerging cybersecurity threats and the need for multi-sector collaboration to prevent consumer data breaches.

Section: Standard
Word Count: 266
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/Fresh-Today/NIST-Publishes-Updated-Draft-To-Cybersecurity-Framework