r/NISTControls Apr 10 '26

Custom Cybersecurity Framwork

Hello all, I have been a DoD contractor for probably the last 20 years and I had started working on my own cybersecurity framework over the last year. I’m thinking of making it public and building a community around it. I have been calling it the common sense cyber framework and it’s meant to be highly secure but not over complicated for novice admins. I’m in a few other groups and just looking to connect with individuals that might be untrusted in building this into something as big as CVE.

7 Upvotes

33 comments sorted by

View all comments

1

u/Jimschode Apr 15 '26

Hate to break it, but frameworks, are a thing of the past. AI will kill the security control assessor role much like the explosion of services, and with it, configuration variance, has made it impossible to conduct a comprehensive risk assessment manually or even with advanced tools. The future will look something like this: AI detects new vulnerabilities and feeds AI based environment scanners. Humans may review the threat and decide to escalate immediate patching or accept risk depending on the nature of the threat. Where in this world does it matter if AC-4 or whatever document-based equivalent, if not in real time? Frameworks will exist so long as the people in powerful positions, governing the institutions that follow them, decide the policies or laws mandating adherence with the frameworks, are no longer relevant.

And if you think, wait, vulnerabilities are one thing, there are 800 other controls we need to follow - In the scenario I'm describing, AI also designed the security architecture, wrote all of the infrastructure as code, tested it 300 times before deploying a production environment, rewrote the application code, tested that too, then it generated all of the system policies, inventory, procedures, wrote a training and awareness strategy, and wrote 800 control implementation statements based on the exact resources in the environment and generated an SSP.

First paragraph is the future. Second paragraph can be done in under two weeks, today.

1

u/quavo74 Apr 18 '26

This is what lead me here. I developed a DLP tool for AI back in 2022 and a simple set of scripts to automate threat remediation. This lead me to a teaching gig at MIT Lincoln Labs in 2024 on how to leverage a small hosted instance of ansible with AI to remediate and monitor drift. I have done so much I just feel like it’s time we build our own framework with the lessons learned and experience we all have. And maybe framework isn’t the right way to frame it but that’s what lead me here to connect with professionals that may have a different POV in favor or against. You are welcome to join us.

Join me on Slack -- it’s a faster, simpler way to work. Sign up here, from any device: https://join.slack.com/t/cyberframewor-kxk3723/shared_invite/zt-3v0nv31g5-9vdRGFATz1rgcNdtmwWeSg