February 24, 2021
While its guidance is voluntary, businesses would be well advised to follow NIST's lead, as it has become the gold standard for general Privacy and Data Security compliance in the United States.
Whether business leaders want to keep their regulators unconcerned, their clients happy, or their brand strong with regard to Privacy and Data Security, they'll need to know about NIST's new focuses.
NIST's first priority will be enhancing risk management, and there is a reason this is likely first: there is expected to be a lot of action in this space in 2021 based on recent events. NIST calling attention to enhancing risk management follows John Katko's, Ranking Member of the House of Representatives Homeland Security Committee, call to revamp federal procurement and the government's approach to cybersecurity in the wake of the foreign espionage activity that breached government systems via a third party software provider serving as part of the federal government's overall technology supply chain. Another separate but similar breach has also been discoveredthis one likely orchestrated by malicious actors associated with a different foreign government.
Recognizing the political appetite for supply chain risk reforms and the necessity to avoid such cybersecurity breaches in the future, NIST is opening its Cybersecurity Framework for public comment and is proposing revisions to its Supply Chain Risk Management in Federal Information Systems and Organizations publication.
Businesses that participate (or want to participate) in procurement contracts with the United States Government should be proactive in both commenting on the NIST Cybersecurity Framework and begin adjusting and aligning their technology supply chain operations to NIST standards.
NIST will also be redoubling their focus on Privacy. In 2020, NIST published its Privacy Framework to complement and supplement the NIST Cybersecurity Framework. While the Cybersecurity Framework sets standards to prevent unauthorized access to information, the Privacy Framework addresses standards for the appropriate use and processing of that information. NIST recently released a crosswalk between the Privacy Framework and the California Consumer Protection Act.
The NIST Privacy Framework, like the Cybersecurity Framework, provides voluntary, self-regulatory suggestions and guidance regarding Privacy and Data Security. However, notably, the guidance is increasingly being incorporated into corporate contracts and other laws (e.g., the Federal Trade Commission looking favorably on the Cybersecurity Framework when assessing whether an organization had unreasonably weak cybersecurity protections).
NIST plans to further strengthen cryptographic standards and validation, our everyday encryption technology. These standards are incredibly important as they ensure the protection of valuable information and can, in most instances, help avoid triggering the notification requirements under most state data breach statutes.
NIST will also focus on cybersecurity awareness, training, and education. This is crucially important and one of the areas that can lead to significant liability and public relations disasters when not handled correctly. An example is the Equifax hack in 2017 that affected the sensitive personal data of individuals spanning multiple countries. Nearly half of the total US population was affected, and the total cost of the breach was over $1.7 billion. The causeaccording to the (former) CEO of Equifax when testifying before Congressof Equifax's security program failing was an individual employee in the technology department failing to "heed security warnings." This is an extreme example, but it puts a spotlight on the danger of employeeswhether from ignorance or malicenot acting in compliance with the business's Privacy and Data Security Policies.
Following NIST's advancements in cybersecurity awareness, training, education, and workforce development will likely weigh heavily in favor of allowing a business to mitigate and minimize potential legal repercussions while also protecting important business and consumer information.
NIST will be improving the metrics and measurements around cybersecurity and privacy. NIST's efforts in these areas will help cross-disciplinary teams "speak the same language" and create a common dialogue that will improve policy compliance. Unfortunately, the silos of business operations can create scenarios in which professionals use similar words, but apply them with different concepts and meanings (e.g., authorized, incident, breach), resulting in inadvertent noncompliance or triggering of legal requirements. The development of these standards can help a business improve efficiency and effectiveness at the enterprise level.
Identity and Access Management will take additional prominence in NIST's guidance given current threats and recent events. Responding to needs felt during the COVID-19 pandemic, NIST will be providing guidance on identity and access management with an emphasis on remote work.
NIST will be focusing on developing methods for determining trustworthy networks and trustworthy platforms. The introduction of the fifth generation of wireless connectivity (5G) and the ever-present and growing Internet of Things industry has accelerated the need for Privacy and Data Security best practices around ascertaining and evaluating a system or platform's trustworthiness.
NIST will continue to focus on providing guidance around securing emerging technologies. Organizations seeking to be at the forefront of technology and proactive in its approach to Privacy and Data Security should start by reviewing the technological challenges catching NIST's attention.
It is important, however, to note that NIST is not the be-all-and-end-all of Privacy and Data Security. Regulated industries, such as Healthcare, Finance, or Education, may have their own sector-specific requirements. State governments each have their own privacy and data security regulations which are not obligated to give deference to NISTthough it is common for them to do sowhich is why NIST standards are so often utilized by businesses operating in multiple states. Any business with an international footprint is likely subject to international regulatory regimes not accounted for in the NIST standards.
For counsel on any steps recommended by NIST or other Privacy and Data Security compliance needs and best practices, please do not hesitate to reach out to the Privacy and Data Security team here at Ward and Smith.
-- 2021 Ward and Smith, P.A. For further information regarding the issues described above, please contact Peter N. McClelland, CIPP/US.
This article is not intended to give, and should not be relied upon for, legal advice in any particular circumstance or fact situation. No action should be taken in reliance upon the information contained in this article without obtaining the advice of an attorney.
We are your established legal network with offices in Asheville, Greenville, New Bern, Raleigh, and Wilmington, NC.
Read this article:
New Year, New Technology Priorities - Ward and Smith, PA
- Technology | Define Technology at Dictionary.com [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Technology | Definition of Technology by Merriam-Webster [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Technology | Define Technology at Dictionary.com [Last Updated On: March 26th, 2016] [Originally Added On: March 26th, 2016]
- Technology | Definition of Technology by Merriam-Webster [Last Updated On: March 26th, 2016] [Originally Added On: March 26th, 2016]
- Technology Synonyms, Technology Antonyms | Thesaurus.com [Last Updated On: March 27th, 2016] [Originally Added On: March 27th, 2016]
- Technology News | Reuters.com [Last Updated On: March 27th, 2016] [Originally Added On: March 27th, 2016]
- Information technology - Wikipedia, the free encyclopedia [Last Updated On: March 27th, 2016] [Originally Added On: March 27th, 2016]
- Technology - Wikipedia, the free encyclopedia [Last Updated On: June 19th, 2016] [Originally Added On: June 19th, 2016]
- Technology Org - Science and technology news [Last Updated On: July 5th, 2016] [Originally Added On: July 5th, 2016]
- Technology - The Atlantic [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- NOAA Ocean Explorer: Technology [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- History of technology - Wikipedia, the free encyclopedia [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Technology - Blue Sky Innovation - Chicago Tribune [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Technology - Northern Illinois University [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Technology Jobs - Monster.com [Last Updated On: August 27th, 2016] [Originally Added On: August 27th, 2016]
- Urban Dictionary: technology [Last Updated On: January 5th, 2017] [Originally Added On: January 5th, 2017]
- IHS Technology The Source for Critical Information and ... [Last Updated On: January 5th, 2017] [Originally Added On: January 5th, 2017]
- Technology | NFL Football Operations [Last Updated On: January 5th, 2017] [Originally Added On: January 5th, 2017]
- Legaltech News - Law Technology News [Last Updated On: January 5th, 2017] [Originally Added On: January 5th, 2017]
- Reddit: Technology [Last Updated On: January 14th, 2017] [Originally Added On: January 14th, 2017]
- National Education Technology Plan - Office of Educational ... [Last Updated On: January 22nd, 2017] [Originally Added On: January 22nd, 2017]
- Technology: Industries: PwC [Last Updated On: January 22nd, 2017] [Originally Added On: January 22nd, 2017]
- Israeli technology let Super Bowl fans see plays at face mask level - Jerusalem Post Israel News [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Toyota, Suzuki to work together in green, safety technology - The Japan Times [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Aston Martin's architect on how to make technology beautiful - The Verge [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- How the New Fox Show APB Approaches Police Technology - Slate Magazine [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Prosthetic arm technology detects spinal nerve signals - Science Daily [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- In This Year's Super Bowl Of Technology, Intel Led The Way With A Sky Full Of Drones - Forbes [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Learning From Last Year: Technology Funding Outlooks For 2017 - Forbes [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Technology - The New York Times [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Texas transportation leaders scramble to keep up with car technology - Fort Worth Star Telegram [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- What the Tech: Neuro-Bio Monitor Technology - KFDX [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How Powerful AI Technology Can Lead to Unforeseen Disasters - Fortune [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Microsoft's AI group debuts customizable speech-to-text technology, rapidly expanding 'cognitive services' for ... - GeekWire [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How 3-D technology helped surgeons separate conjoined twins - CNN [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- These Four Black Women Inventors Reimagined the Technology of the Home - Smithsonian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Broadcaster dangles new technology for Winter Olympics - Reuters [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- A flare for self-destruction: How technology is the means, not the cause, of our demise - National Post [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How 3D and Self-Design Will Change Technology - Huffington Post [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Republicans Aim to Kill Election Technology Standards Agency - Gizmodo [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Sean Spicer: Coal will be one of the cleanest uses of technology that we have - The Independent [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Is technology getting in the way of togetherness? - Las Vegas Weekly (blog) [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Panera surges to record as Wall Street eyes payoff from technology - Reuters [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Coming technology will likely destroy millions of jobs. Is Trump ready? - Washington Post [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- How Technology Transforms Dreamers Into Economic Powerhouses - Forbes [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Technology Trends That Will Shape 2017 and Boost Your Company's UX - Entrepreneur [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- United Airlines Experiences Another Technology Glitch - Wall Street Journal [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- A growing concern: Technology and transportation - Florida Today [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Aberdeen Oil and Gas Technology centre due to open - BBC News [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Opinion: Ethics should be front and center with technology but isn't always - The Mercury News [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Yes, there's a job creation argument for automation and technology - The Hill (blog) [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Nasdaq plans venture arm to invest in financial technology: sources ... - Reuters [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Volvo melds technology and luxury in the XC90 T8 hybrid - Engadget [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Our seas have become a plastic graveyard - but can technology turn the tide? - Telegraph.co.uk [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Technology identifying fastest checkout lanes comes to metro - KCCI Des Moines [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- This Technology Could Be a Game-Changer for the Marijuana Industry - Fox Business [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Small cell technology is large endeavor for state - Crain's Cleveland Business [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Grapevine: Technology at any age - Jerusalem Post Israel News [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Feeling Tied to Technology? Neuroscientist Offers Tips to Focus and Recharge Your Brain - whotv.com [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- The technology fixing Britain's parking problem - The Independent [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- DHS Developing Technology to Identify Terrorist Travelers - Breitbart News [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- New technology has display designers thinking outside the rectangle - The Japan Times [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Graph Technology A Data Standby By For Every Fortune 500 Company - Computer Business Review [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Tesla obtains patent for charging metal-air battery technology that could enable longer range - Electrek [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Tim Cook: Augmented Reality is as big of a technology as the smartphone - BGR [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Franklin County's 911 centers sharing technology to receive texts - Columbus Dispatch [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- A New Angel Investing Platform Connects Deep Technology And Science Startups With Capital - Forbes [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How technology is encouraging society to be stupid - The Next Web [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Technology puts 'touch' into long-distance relationships - Phys.Org [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- VW plans to use Mobileye sensing and localization technology - Automotive News (subscription) (blog) [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- How dangerous is technology? - OUPblog (blog) [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Valentine's day: what's your secret technology crush? - Naked Security [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Johnston educators among presenters at technology conference - News & Observer [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Is Magic Leap Lying About Its Acid Trip Technology? - Vanity Fair [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- A look at North Korea's missile launches and technology - ABC News [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Parents and technology How much is too much? - WGBA-TV [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Apple's Eddy Cue says technology companies have a responsibility to combat fake news - Recode [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Statistical agencies looking to C-suite, new digital tools to address biggest challenges - FederalNewsRadio.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Even Indian technology entrepreneurs think they are living in a bubble - Quartz [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Is Hyperloop transportation technology coming to India? - YourStory.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]