National Institute of Standards & Technology User Guide



Module Highlights

This section highlights some key reporting capabilities contained within the NIST Compliance Automation Suite. LogRhythm has adopted the Consolidated Compliance Framework (CCF) approach to find common control approaches across various frameworks. This approach has been applied to the NIST Compliance Automation Suite to help organizations streamline compliance objectives. Collectively many considered NIST an influencer of compliance frameworks and is a core to LogRhythm’s compliance approaches within CCF. All objects associated with this module follow the ‘CCF: XXX’ naming convention and utilize a restricted view to only allow those appropriate individuals to see NIST specific content.

New profiles can be created for the Global Administrator, Global Analyst, Restricted Administrator, Restricted Analyst, and Web Service Administrator security roles. The security roles enable the administrator to assign access to specific objects within the Entity to individual users. For example, many Restricted Analysts can be given access to Entity A, but not access to the same Log Sources within Entity A. Restricted Analyst 1 can have access to Log Sources 1, 2, and 3 on Entity A, while Restricted Analyst 2 has access to Log Sources 4, 5, and 6 on Entity A. This allows the organization to limit access to data and compliance content according to compliance needs.

As the organization identifies the need for a compliance module, in this instance NIST, it is important to consider where the organization is along the Compliance Maturity Module. How mature the organization is will determine what key resources are available to better align the NIST Compliance Automation Suite deployment with your compliance program. As the organization matures and key internal resources are established, the organization can easily pivot from a strong compliance base to establish strong security practices. To start, assess your organization’s maturity level in each category in the tables below.

LogRhythm Control Family Augment Ability

NIST 800-53 Control Family

LR Augment Ability

Access Control (AC)

image2018-11-30_16-13-42.png

Awareness and Training (AT)

image2018-11-30_16-16-48.png

Audit and Accountability (AU)

image2018-11-30_16-13-45.png

Security Assessment and Authorization (CA)

image2018-11-30_16-14-51.png

Configuration Management (CM)

image2018-11-30_16-13-49.png

Contingency Planning (CP)

image2018-11-30_16-14-54.png

Identification and Authentication (IA)

image2018-11-30_16-15-2.png

Individual Participation (IP)

image2018-11-30_16-13-51.png

Incident Response (IR)

image2018-11-30_16-14-57.png

Maintenance (MA)

image2018-11-30_16-13-54.png

Media Protection (MP)

image2018-11-30_16-14-59.png

Privacy Authorization (PA)

image2018-11-30_16-13-57.png

Physical and Environmental Protection (PE)

image2018-11-30_16-13-59.png

Planning (PL)

image2018-11-30_16-14-1.png

Program Management (PM)

image2018-11-30_16-14-4.png

Personnel Security (PS)

image2018-11-30_16-15-6.png

Risk Assessment (RA)

image2018-11-30_16-15-13.png

System and Services Acquisition (SA)

image2018-11-30_16-15-10.png

System and Communications Protection (SC)

image2018-11-30_16-15-17.png

System and Information Integrity (SI)

image2018-11-30_16-15-8.png


NIST 800-171 Control Family

LR Augment Ability

Access Control (3.1)

image2018-11-30_16-15-20.png

Awareness and Training (3.2)

image2018-11-30_16-16-43.png

Audit and Accountability (3.3)

image2018-11-30_16-15-38.png

Configuration Management (3.4)

image2018-11-30_16-15-23.png

Identification and Authentication (3.5)

image2018-11-30_16-15-36.png

Incident Response (3.6)

image2018-11-30_16-15-42.png

Maintenance (3.7)

image2018-11-30_16-15-25.png

Media Protection (3.8)

image2018-11-30_16-15-40.png

Personnel Security (3.9)

image2018-11-30_16-15-28.png

Physical Protection (3.10)

image2018-11-30_16-15-52.png

Risk Assessment (3.11)

image2018-11-30_16-15-30.png  

Security Assessment (3.12)

image2018-11-30_16-15-46.png

System and Communications Protection (3.13)

image2018-11-30_16-15-33.png  

System and Information Integrity (3.14)

image2018-11-30_16-15-49.png


NIST CSF Control Family

LR Augment Ability

Identify (ID)

image2018-11-30_16-13-1.png

Protect (PR)

image2018-11-30_16-13-12.png  

Detect (DE)

image2018-11-30_16-13-10.png  

Respond (RS)

image2018-11-30_16-13-7.png  

Recover (RC)

image2018-11-30_16-13-5.png  

The guide is divided into the following sections: