April 16, 2018
3.4
Cybersecurity Framework
Version 1.1
Buying Decisions
Since a Framework Target Profile is a prioritized list of organizational cybersecurity
requirements, Target Profiles can be used to inform decisions about buying products and
services. This transaction varies from Communicating Cybersecurity Requirements with
Stakeholders (addressed in Section 3.3) in that it may not be possible to impose a set of
cybersecurity requirements on the supplier. The objective should be to make the best buying
decision among multiple suppliers, given a carefully determined list of cybersecurity
requirements. Often, this means some degree of trade-off, comparing multiple products or
services with known gaps to the Target Profile.
Once a product or service is purchased, the Profile also can be used to track and address residual
cybersecurity risk. For example, if the service or product purchased did not meet all the
objectives described in the Target Profile, the organization can address the residual risk through
other management actions. The Profile also provides the organization a method for assessing if
the product meets cybersecurity outcomes through periodic review and testing mechanisms.
3.5
Identifying Opportunities for New or Revised Informative
References
The Framework can be used to identify opportunities for new or revised standards, guidelines, or
practices where additional Informative References would help organizations address emerging
needs. An organization implementing a given Subcategory, or developing a new Subcategory,
might discover that there are few Informative References, if any, for a related activity. To
address that need, the organization might collaborate with technology leaders and/or standards
bodies to draft, develop, and coordinate standards, guidelines, or practices.
3.6
Methodology to Protect Privacy and Civil Libert ies
This section describes a methodology to address individual privacy and civil liberties
implications that may result from cybersecurity. This methodology is intended to be a general set
of considerations and processes since privacy and civil liberties implications may differ by sector
or over time and organizations may address these considerations and processes with a range of
technical implementations. Nonetheless, not all activities in a cybersecurity program engender
privacy and civil liberties considerations. Technical privacy standards, guidelines, and additional
best practices may need to be developed to support improved technical implementations.
Privacy and cybersecurity have a strong connection. An organization’s cybersecurity activities
also can create risks to privacy and civil liberties when personal information is used, collected,
processed, maintained, or disclosed. Some examples include: cybersecurity activities that result
in the over-collection or over-retention of personal information; disclosure or use of personal
information unrelated to cybersecurity activities; and cybersecurity mitigation activities that
result in denial of service or other similar potentially adverse impacts, including some types of
incident detection or monitoring that may inhibit freedom of expression or association.
The government and its agents have a responsibility to protect civil liberties arising from
cybersecurity activities. As referenced in the methodology below, government or its agents that
own or operate critical infrastructure should have a process in place to support compliance of
cybersecurity activities with applicable privacy laws, regulations, and Constitutional
requirements.
This publication is available free of charge from: https://doi.org/10.6028/NIST.CSWP.04162018
18