Date Published: June 15, 2023
Comments Due: July 17, 2023 (public comment period is CLOSED)
Email Questions to:
[email protected]
Planning Note (02/26/2024):
This report references the NIST Cybersecurity Framework v1.1.
The Cybersecurity Framework (CSF) Profile for Genomic Data provides voluntary guidance to help organizations manage, reduce, and communicate cybersecurity and privacy risks for systems, networks, and assets that process genomic data. This publication is a follow-on effort to NIST Internal Report (IR) 8432, The Cybersecurity of Genomic Data, and was developed in collaboration with stakeholders across industry, academia, and government. This effort is informed by direction from Congress, the White House, and NIST’s existing expertise in genomics as well as cybersecurity.
The Profile identifies 12 genomic-related Mission Objectives and prioritizes relevant CSF Subcategories to help organizations protect genomic data throughout the data lifecycle.
Organizations processing genomic data can use this guidance to:
The CSF Profile for Genomic Data is intended to supplement, not replace, current cybersecurity standards, regulations, and industry guidelines. Organizations should consider their unique obligations, operating environment, and Mission Objectives when prioritizing and implementing cybersecurity capabilities and controls. While the focus of this CSF Profile is cybersecurity, whenever human genomic data is processed, privacy risk management considerations must also be addressed. As a result, privacy is referenced in multiple places throughout the CSF Profile where cybersecurity and privacy risks overlap. NIST plans to address the broader privacy landscape for genomic data by creating a Profile using the NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management (“Privacy Framework”). Once created, the Privacy Framework Profile for Genomic Data should be used as a complementary tool to this CSF Profile.
Submit Comments
The public comment period closes at 11:59 PM ET on July 17, 2023. Please email all draft comments to [email protected]. We encourage you to submit all feedback using the comment template found on our project page.
Join the Community of Interest
If you have expertise in genomic data and/or cybersecurity, consider joining the NCCoE Genomics Cybersecurity Community of Interest (COI) to receive the latest project news and announcements. Email the team at [email protected] declaring your interest, or complete the sign-up form on our project page.
NOTE: A call for patent claims is included on page ii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy – Inclusion of Patents in ITL Publications.
None selected
Publication:
https://doi.org/10.6028/NIST.IR.8467.ipd
Download URL
Supplemental Material:
Comment template
Project homepage
Related NIST Publications:
Document History:
06/15/23: IR 8467 (Draft)
06/15/23: IR 8467 (Draft)
personally identifiable information, risk management, security programs & operations
Applications Sectors