Transformative Asset Management Strategies: Insights from NIST CSF
摘要
This report provides an in-depth examination of asset management strategies carried out in accordance with the NIST Cybersecurity Framework (CSF). The aim is to demonstrate the effectiveness of implementing industry-standard tools to manage and secure organizational assets, including data, hardware, software, systems, facilities, services, and people. Through strict adherence to the NIST CSF guidelines, each sub-category of the Asset Management function was addressed via specific tasks and tools. The methodology entailed creating and regularly updating comprehensive inventories of hardware and software assets, mapping internal and external data flows, managing services supplied by vendors, prioritizing assets based on their criticality, and ensuring thorough lifecycle management of all assets. Tools such as Lansweeper, Spiceworks, Microsoft SCCM, PDQ Inventory, Wireshark, Microsoft Visio, Cloud-Health, Qualys, Bulk Extractor and Exiftool were utilized to carry out these tasks. The key findings emphasize the efficiency and reliability of these tools in maintaining up-to-date asset inventories, mapping network data flows, and managing the lifecycle of assets. The implementation of these tools resulted in a more structured and secure asset management process, aligned with organizational objectives and risk strategies. By providing detailed insights and best practices derived from our practical assessment, this paper aims to guide organizations in optimizing their asset management processes through the effective adoption of NIST CSF principles.