NIST flags human blind spot in its own cyber frameworks
The concept paper concedes existing frameworks treat humans as vulnerabilities, not partners, and asks how to fix that.
TL;DR
NIST published a concept paper seeking stakeholder feedback through September 30 on human-centered cybersecurity guidance. The paper, part of a program launched in 2024, acknowledges that existing frameworks "tend to focus on technical controls and seldom explicitly call out HCC practices," leaving organizations unsure how to take a human-centered approach. NIST asks for input organized under three buckets: scope, ensuring the guidance is actionable, and what evidence should underpin it.
NIST's Human-Centered Cybersecurity program, launched in 2024 under the agency's broader Human-Centered Technologies Group, has produced a concept paper that does something unusual for a standards body: it names a gap in its own approach.
"Beyond mentions of security awareness and training, cybersecurity frameworks and guidelines tend to focus on technical controls and seldom explicitly call out HCC practices," the paper states. "Thus, organizations are unsure how to take a human-centered approach."
For practitioners (the CISOs and security engineers who implement NIST frameworks) this framing matters. The acknowledgment that "human error and risk are often emphasized, skewing the perception of humans as only being vulnerabilities" is a departure from the implicit posture of most NIST guidance, where people are variables to be controlled rather than partners in the security architecture.
The concept paper proposes that humans can be "active partners in cybersecurity via various roles such as cybersecurity and IT professionals, human 'sensors' and reporters of suspicious activity, and security champions." It's a shift from the compliance-checklist model of annual awareness training toward integrating human factors into the design of security programs themselves.
NIST is considering several formats for the eventual guidance: integrating HCC content into existing publications, creating standalone documents with direct mappings to other NIST guidance, publishing shorter standalone pieces on specific topics, and developing case studies. The agency is targeting a broad audience, program creators, technology developers, risk managers, and those who set and influence cybersecurity policy.
Feedback is due September 30. The concept paper's questions are organized into three buckets: scope (what elements are most critical, which existing NIST publications should HCC guidance align with), ensuring value (how to make the guidance actionable for organizations of different sizes and sectors), and related evidence (what kind of research should underpin the guidance).
For the compliance director, the immediate question is whether HCC guidance will become normative, referenced in contracts, incorporated into assessment frameworks, or treated as advisory. NIST hasn't answered that yet, which is presumably part of what the comment period is designed to surface.
Published ·Updated ·Deep Fathom