DTG-NF18 · NIST CSF in Practice · 4 min

Alert Fatigue Is a Detection Design Problem, Not a Staffing Problem

Alert fatigue is the condition in which the volume of security alerts exceeds the capacity of the security team to investigate them meaningfully, resulting in alerts bein…

DTG-NF14 · NIST CSF in Practice · 4 min

Continuous Monitoring Is a NIST Requirement. It Is Also the Hardest to Operationalize

NIST CSF 2.0 includes continuous monitoring across multiple functions: in Identify, to maintain an accurate picture of the organizational environment and its risks; in De…

DTG-NF10 · NIST CSF in Practice · 4 min

Respond Is the Function That Reveals Whether Govern Was Ever Real

The NIST CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond, Recover. Most governance programs invest sequentially in the first four.

DTG-NF09 · NIST CSF in Practice · 4 min

What a Mature NIST CSF Implementation Looks Like Three Years In

Year one of NIST CSF implementation is about gap assessment and roadmap development. Year two is about control implementation and evidence collection.

DTG-NF07 · NIST CSF in Practice · 4 min

The Supply Chain Risk Category That Gets Ticked and Not Managed

NIST CSF 2.0's GV.SC subcategory — cybersecurity supply chain risk management — is one of the most substantive additions to the framework's governance dimension.

DTG-NF06 · NIST CSF in Practice · 4 min

Recovery Planning That Doesn't Account for Data Integrity Is Not Recovery Planning

Recovery planning in most business continuity programs is architected around availability: restoring systems to operational status within the recovery time objective.

DTG-NF05 · NIST CSF in Practice · 4 min

Detect Is the NIST Function Most Organizations Under-Invest In

If you asked most security practitioners which NIST CSF function receives the least investment relative to its importance, the answer would be Detect.

DTG-NF04 · NIST CSF in Practice · 4 min

The Organization That Mapped to NIST and Still Had the Incident

The NIST CSF mapping was comprehensive. Every subcategory was assessed. Gaps were documented. A roadmap was developed. Progress was reported to the board quarterly.

DTG-171 · NIST CSF in Practice · 8 min

Response Plans Exist. Execution Is Improvised

Incident response plans are one of the most universally documented governance artifacts in enterprise security. They are required by every major framework.

DTG-162 · NIST CSF in Practice · 8 min

Data Protection Controls Exist. They Don't Follow the Data

Data protection controls are implemented at known data locations. Data moves to unknown locations constantly: copied to analytics environments, exported to SaaS tools, ca…

DTG-151 · NIST CSF in Practice · 8 min

NIST CSF 2.0 Defines Governance Clearly. Execution Is Where It Breaks

NIST CSF 2.0 introduced a Govern function that sits above and connects Identify, Protect, Detect, Respond, and Recover. The governance mandate is clear: organizations mus…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center