Jason Edwards

Framework: The NIST Cybersecurity Framework (CSF)

**Framework** is your go-to podcast for mastering the **NIST Cybersecurity Framework (CSF)**—the foundational model for building and improving organizational security programs. This series breaks down every function, category, and subcategory within the CSF, helping professionals, educators, and leaders understand how to apply the framework in real-world environments. Each episode delivers clear, practical explanations that connect framework concepts to daily security operations, governance, and risk management practices. Whether you’re new to cybersecurity or refining an established program,...

Author

Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Oct 14, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

ID.AM-01 - Tracking Organizational Hardware Assets 25.02.2025

ID.AM-01 requires organizations to maintain comprehensive inventories of all hardware assets under their control, including IT, IoT, OT, and mobile devices. This ongoing cataloging ensures visibility into the physical components that support operations, enabling better risk assessment and management. Accurate inventories are foundational to identifying vulnerabilities and protecting critical asset...

GV.SC-10 - Planning for Post-Partnership Security 25.02.2025

GV.SC-10 ensures that supply chain risk management plans address post-relationship activities, such as terminating supplier access or managing data disposal. This involves establishing processes for secure transitions, including end-of-life maintenance and asset recovery, to prevent residual risks. It safeguards the organization after partnerships end. This subcategory mitigates risks like data le...

GV.SC-09 - Monitoring Supply Chain Security Practices 25.02.2025

GV.SC-09 embeds supply chain security practices into cybersecurity and enterprise risk management, ensuring consistent oversight from acquisition to disposal of products and services. This integration includes requiring provenance records and monitoring performance metrics to verify authenticity and security. It aligns supply chain activities with organizational risk strategies. This subcategory s...

GV.SC-08 - Including Suppliers in Incident Response Planning 25.02.2025

GV.SC-08 integrates key suppliers and third parties into the organization’s incident planning, response, and recovery efforts, ensuring coordinated action during cybersecurity events. This includes defining roles, communication protocols, and participation in exercises like simulations to prepare for incidents. Collaboration with suppliers enhances the organization’s ability to manage and recover...

GV.SC-07 - Managing Supplier Risks Throughout Relationships 25.02.2025

GV.SC-07 ensures ongoing understanding and management of risks from suppliers and third parties throughout their relationship with the organization. This involves documenting, prioritizing, and assessing risks—such as product vulnerabilities or service disruptions—and developing tailored responses. Continuous monitoring keeps these risks in check over time. This subcategory promotes a dynamic risk...

GV.SC-06 - Conducting Due Diligence Before Supplier Partnerships 25.02.2025

GV.SC-06 mandates thorough planning and due diligence before engaging suppliers or third parties, assessing their cybersecurity capabilities and risks. This proactive step evaluates factors like technology suitability and risk management practices, ensuring potential partners meet organizational standards. It aims to minimize vulnerabilities introduced through new relationships. By conducting risk...

GV.SC-05 - Setting Cybersecurity Requirements for Suppliers 25.02.2025

GV.SC-05 establishes and prioritizes cybersecurity requirements for suppliers, embedding them into contracts and agreements to enforce consistent security standards. These requirements, tailored to supplier criticality, might include vulnerability disclosures or employee vetting, ensuring third parties align with organizational risk priorities. This contractual approach formalizes expectations and...

GV.SC-04 - Prioritizing Suppliers by Criticality 25.02.2025

GV.SC-04 requires organizations to identify all suppliers and rank them based on their criticality to operations, considering factors like data sensitivity or system access. This prioritization helps focus cybersecurity efforts on the most vital suppliers, whose failure or compromise could significantly impact the organization. Maintaining an up-to-date supplier inventory is key to this process. T...

GV.SC-03 - Integrating Supply Chain Risks into Broader Frameworks 25.02.2025

GV.SC-03 integrates supply chain risk management into the organization’s broader cybersecurity and enterprise risk management (ERM) frameworks, ensuring a unified approach to risk. This alignment allows supply chain risks to be assessed and prioritized alongside other organizational risks, such as operational or financial threats. It fosters consistency in how risks are identified, managed, and es...

GV.SC-02 - Defining Cybersecurity Roles in the Supply Chain 25.02.2025

GV.SC-02 emphasizes defining and sharing cybersecurity roles and responsibilities for all parties in the supply chain—suppliers, customers, and partners—as well as within the organization. This clarity ensures that everyone understands their obligations, from planning to executing risk management activities, fostering accountability and coordination. Communication extends both internally and exter...

GV.SC-01 - Building a Supply Chain Risk Management Program 25.02.2025

GV.SC-01 focuses on creating a structured cybersecurity supply chain risk management program that includes a clear strategy, objectives, policies, and processes, all endorsed by organizational stakeholders. This ensures that risks stemming from suppliers and third-party relationships are systematically addressed, with a defined plan that outlines milestones and responsibilities. Stakeholder agreem...

GV.OV-03 - Evaluating Cybersecurity Performance 25.02.2025

GV.OV-03 emphasizes measuring and reviewing the organization’s cybersecurity risk management performance using indicators like KPIs and KRIs. This evaluation identifies how well policies and procedures meet objectives and highlights risks in terms of likelihood and impact. Regular reviews with leadership ensure insights lead to actionable improvements. This subcategory supports data-driven decisio...

GV.OV-02 - Adjusting Strategies for Comprehensive Risk Coverage 25.02.2025

GV.OV-02 involves periodic reviews of the cybersecurity risk management strategy to confirm it addresses all organizational requirements and emerging risks. This includes analyzing audit findings, incidents, or role performance to identify gaps in coverage or compliance. Adjustments ensure the strategy remains comprehensive and relevant. This subcategory strengthens governance by tying strategy to...

GV.OV-01 - Reviewing Cybersecurity Strategy Outcomes 25.02.2025

GV.OV-01 focuses on evaluating the outcomes of the cybersecurity risk management strategy to refine its direction and effectiveness. This involves measuring how well the strategy supports decision-making and organizational objectives, identifying successes or shortcomings. Adjustments based on these reviews ensure the strategy remains aligned with goals. This subcategory encourages a feedback loop...

GV.PO-02 - Keeping Cybersecurity Policies Current 25.02.2025

GV.PO-02 ensures that the cybersecurity risk management policy remains dynamic, undergoing regular reviews to adapt to evolving threats, technologies, legal requirements, or mission shifts. Updates are communicated to keep stakeholders informed and ensure ongoing relevance, while enforcement maintains compliance. This adaptability keeps the policy effective over time. This subcategory promotes a p...

GV.PO-01 - Establishing a Cybersecurity Risk Management Policy 25.02.2025

GV.PO-01 involves creating a formal cybersecurity risk management policy that reflects the organization’s unique context, strategy, and priorities. This policy outlines management’s intent and expectations, providing a clear framework for security practices that is communicated across all levels. Enforcement ensures that the policy translates into actionable, consistent behavior. This subcategory...

GV.RR-04 - Embedding Cybersecurity in HR Practices 25.02.2025

GV.RR-04 integrates cybersecurity considerations into human resources processes, such as hiring, onboarding, training, and offboarding, to enhance organizational security. This includes screening for cybersecurity knowledge, enforcing policy adherence, and ensuring departing employees’ access is revoked promptly. It embeds security awareness into the employee lifecycle. By prioritizing cybersecuri...

GV.RR-03 - Allocating Resources for Cybersecurity Success 25.02.2025

GV.RR-03 ensures that sufficient resources—people, processes, and technology—are allocated to support the organization’s cybersecurity risk strategy and assigned roles. This involves regular reviews to confirm that resource levels match the risk tolerance and response plans, avoiding gaps in capability. Adequate resourcing enables effective execution of security measures. This subcategory aligns i...

GV.RR-02 - Clarifying Cybersecurity Roles and Responsibilities 25.02.2025

GV.RR-02 focuses on defining and disseminating clear roles, responsibilities, and authorities for cybersecurity risk management across the organization. This clarity ensures that individuals and teams know their specific duties—whether strategic, operational, or auditing—and have the authority to act. Enforcement mechanisms ensure accountability and adherence to these roles. By documenting and com...

GV.RR-01 - Leadership’s Role in Cybersecurity Accountability 25.02.2025

GV.RR-01 assigns responsibility to leadership for overseeing cybersecurity risk, ensuring they are accountable for strategy development and execution. It emphasizes fostering a risk-aware, ethical culture where security is a shared priority, reinforced through visible leadership commitment. This cultural focus drives continuous improvement in cybersecurity practices. Leaders under this subcategory...

GV.RM-07 - Embracing Strategic Opportunities in Risk Management 25.02.2025

GV.RM-07 recognizes that not all risks are negative, encouraging organizations to identify and discuss strategic opportunities, or “positive risks,” alongside threats. These might include adopting new technologies or expanding services, which could enhance capabilities despite introducing risks. Including these in risk discussions ensures a balanced perspective that considers potential benefits. T...

GV.RM-06 - Standardizing Cybersecurity Risk Assessment 25.02.2025

GV.RM-06 establishes a consistent methodology for assessing and prioritizing cybersecurity risks, using tools like risk registers or quantitative formulas. This standardized approach ensures risks are documented, categorized (e.g., by severity or type), and ranked in a way that is clear and repeatable across the organization. Communication of this method ensures all stakeholders can interpret and...

GV.RM-05 - Building Communication Channels for Cybersecurity Risks 25.02.2025

GV.RM-05 emphasizes creating structured communication channels to share cybersecurity risk information across departments and with external parties like suppliers. This ensures that senior executives, operational teams, and third-party partners stay informed about the organization’s cybersecurity posture and emerging risks. Effective communication reduces silos and enhances collective awareness. B...

GV.RM-04 - Crafting Strategic Risk Response Options 25.02.2025

GV.RM-04 focuses on defining and sharing a strategic direction for responding to cybersecurity risks, outlining options like acceptance, mitigation, or transfer (e.g., via insurance). This guidance helps organizations decide how to address risks based on data classification, criticality, or operational needs, ensuring consistency in decision-making. Clear communication ensures all stakeholders und...

GV.RM-03 - Integrating Cybersecurity into Enterprise Risk Management 25.02.2025

GV.RM-03 integrates cybersecurity risk management into the broader enterprise risk management (ERM) framework, ensuring it is considered alongside other risks like financial or operational challenges. This holistic approach allows organizations to aggregate and prioritize cybersecurity risks within the context of overall business objectives. It fosters collaboration between cybersecurity teams and...

Listen to the Framework: The NIST Cybersecurity Framework (CSF) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.