Appendix A: Helpful Advice for Small Organizations Seeking to Implement Some of the Book’s Recommendations
Many, if not most, of the principles and practices of sound cybersecurity presented throughout this book are admittedly complex. They are also far easier to grasp and implement for large organizations, which typically have bigger budgets and multiple personnel to devote to IT, technology, security tasks, and training.
Numerous resources offer guidance to small and medium-sized businesses when implementing the NIST Cybersecurity Framework and adopting critical practices to protecting systems and information. Three in particular that are worth reviewing and keeping on hand are:
- 1. NISTIR 7621, Revision 1 – Small Business Information Security: The Fundamentals, November 2016 at https://nvlpubs.nist.gov/nistpubs/ir/2016/NIST.IR.7621r1.pdf.
- 2. NIST Small Business Cybersecurity Corner at https://www.nist.gov/itl/smallbusinesscyber.
- 3. Cybersecurity Risk Management and Best Practices (CSRIC IV WG4 Final Report), Section 9.9 Small and Medium Business (370–397) at https://transition.fcc.gov/pshs/advisory/csric4/CSRIC_IV_WG4_Final_Report_031815.pdf.
However, even these guides detail, albeit more simply, the same basic cybersecurity steps that are highlighted in this book – developing risk assessments, mapping out and planning infrastructure protections, implementing intrusion detection systems, and so forth.
What this means, in short, is that there is no easy way to ensure systems ...