Expel unveils updated NIST CSF 2.0 Getting Started Toolkit

Popular guide and self-scoring spreadsheet aid organisations in charting a course for continuous cybersecurity program improvement.

  • Thursday, 14th March 2024 Posted 1 month ago in by Phil Alsop

Expel has unveiled the updated version of its National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) Getting Started toolkit. The kit, which includes a “getting started” guide and a self-scoring spreadsheet, helps security leaders and operators assess their cybersecurity postures, aligned with the recently released version 2.0 of the NIST CSF.

“Over the last decade, the NIST CSF has been a critical tool for companies in determining their cybersecurity readiness and assessing where they can improve—and version 2.0 expands on that foundation,” said Greg Notch, Chief Information Security Officer, Expel. “Even the strongest security programs have room for improvement. Our NIST CSF kit makes it easy for security teams to understand the latest updates to the framework, and provides up-to-date resources to better understand how their programs and controls rate across critical security functions.”

A recent research study conducted by the SANS Institute (sponsored by Expel) found that almost three-quarters (74%) of companies that use a framework use the NIST CSF. Version 2.0 of the frameworks expands on the previous iteration, introducing a new “Govern” function that offers a better understanding of how to prioritise investments to improve risk posture across the CSF’s other function areas—Identify, Protect, Detect, Response, and Recover. The latest update also adds Framework Tiers, which characterise the typical rigour of cybersecurity risk governance and management practices throughout an organisation.

Expel’s NIST CSF guide helps security leaders and operators understand how to approach the framework and make sense of its functions, categories, subcategories, and tiers. The self-scoring spreadsheet allows users to evaluate their current, future, and goal states for each outcome in the CSF, while also offering clear charts for resource allocation guidance.

Notch continues: “The recommendations in the NIST CSF are designed to be easy to understand and implement, but can seem intimidating to those folks who are assessing their orgs with it for the first time. This kit makes it simple for teams to complete their initial assessments using the new framework in just a couple of hours. More importantly, it sets up teams to conduct future assessments at regular intervals so they can focus on continuous improvement.”

Symatrix continues impressive growth trajectory

Posted 2 days ago by Phil Alsop
Record growth follows 42% increase in revenues in FY23 as Oracle partner bolsters expansion in UK and India.

Crowdstrike expands partnerships and alliances

Posted 2 days ago by Phil Alsop
Service partners and alliances including Deloitte, EY, HCLTech, TCS and more to power the AI-native SOC with CrowdStrike Falcon Next-Gen SIEM,...
The value of the graphic processor unit (GPU) sales in 2023 more than doubled the previous year’s figure according to refurbished technology...

CITIC Telecom CPC reaches VMware Pinnacle

Posted 2 days ago by Phil Alsop
CITIC Telecom CPC has become a VMware Cloud Service Provider (VCSP) Pinnacle tier partner in the Broadcom Advantage Partner Program globally.
New generative AI capabilities in Now Assist supercharge productivity, accelerate cost savings, and empower customers and employees to innovate at...

Utimaco launches u.nity Partner Program

Posted 3 days ago by Phil Alsop
New comprehensive program accelerates revenue by providing customers with Utimaco’s leading data protection solutions and services.

HP prepares partners for the era of AI

Posted 3 days ago by Phil Alsop
Announces go-live of industry's first role-based AI training and certification programme and new partner growth opportunities.
With Cubbit DS3, French-based MSP CloudReso can offer unprecedented data sovereignty, geographical resilience, and ransomware protection.