NSA Top 10 (v2018)
Overview of NSA Top 10 (2018)
The NSA Top 10 Cybersecurity Mitigation Strategies (2018) outlines updated cybersecurity mitigation strategies that address emerging threats and risks in the digital landscape. Published in 2018, this version updated the foundational strategies from the 2016 version to address evolving threats, new attack techniques, and emerging technologies that have changed the cybersecurity landscape. The 2018 version maintains the focus on practical, actionable measures while incorporating lessons learned from recent cyber incidents and addressing new attack vectors.
The 2018 version emerged in response to evolving threat landscape, including increased ransomware attacks, supply chain compromises, cloud security concerns, and sophisticated phishing campaigns. The updated strategies reflect the NSA's analysis of actual cyber intrusions and attack patterns observed between 2016 and 2018, identifying defensive measures that remain effective against evolving threats. The strategies continue to focus on foundational cybersecurity practices that deliver maximum defensive value, while incorporating updates that address emerging threats and technologies.
While the 2018 version has been superseded by later versions, understanding the 2018 version remains important for organizations working with systems deployed during this period, historical security assessments, and understanding how cybersecurity best practices evolved. The 2018 version established important updates to foundational principles, including enhanced focus on cloud security, supply chain risks, and advanced threat detection. Organizations should consider migrating to newer versions for current best practices, though the 2018 strategies remain valuable cybersecurity guidance.
Framework Applicability and Adoption
The NSA Top 10 (2018) applies to organizations of all sizes and sectors seeking to implement foundational cybersecurity practices that defend against common and emerging cyber threats. The strategies are particularly relevant for organizations establishing cybersecurity programs, as they provide clear guidance on essential defensive measures. The framework is widely applicable across industries, providing practical guidance that organizations can implement regardless of their size or sector.
Adoption of the NSA Top 10 (2018) has been driven by its practical, actionable nature and focus on foundational cybersecurity practices that address both traditional and emerging threats. Organizations seeking to establish or enhance cybersecurity programs often reference the NSA Top 10 strategies, as they provide clear guidance on essential defensive measures. The strategies complement other cybersecurity frameworks, enabling organizations to implement foundational practices while working toward comprehensive framework compliance.
The 10 Cybersecurity Mitigation Strategies
The NSA Top 10 (2018) organizes cybersecurity mitigation strategies into 10 key areas that address common and emerging attack vectors. Each strategy provides specific guidance on defensive measures that prevent or mitigate attack techniques.
1. Application Whitelisting
Application whitelisting prevents unauthorized software from executing on systems, blocking malware and other malicious code even when other security controls fail. The 2018 version emphasizes cloud application whitelisting and container security, addressing emerging technologies and deployment models. Organizations must maintain approved application lists, configure systems to allow only approved applications to execute, and implement processes for managing application approvals in cloud and containerized environments.
Implementation requires organizations to identify approved applications, configure systems to enforce whitelisting policies, and establish processes for approving new applications. Organizations should implement whitelisting on critical systems first, then expand coverage progressively to cloud and containerized environments. Application whitelisting must be balanced with operational requirements, ensuring that legitimate business applications can execute while preventing unauthorized software. Regular review and updates of whitelists ensure that approved applications remain current and that unauthorized software is prevented from executing.
2. Patch Applications and Operating Systems
Timely patching of applications and operating systems addresses known vulnerabilities that adversaries exploit to compromise systems. The 2018 version emphasizes cloud patching, container image updates, and automated patch deployment that address modern deployment models. Organizations must establish patch management processes that identify vulnerabilities, test patches, and deploy patches promptly across on-premises, cloud, and hybrid environments.
Organizations should implement automated patch management where possible, conduct regular vulnerability assessments, and maintain patch deployment schedules that balance security needs with operational stability. Patch testing processes ensure that patches don't introduce operational issues, while rapid deployment processes ensure that critical vulnerabilities are addressed promptly. Patch management programs must address operating system patches, application patches, cloud service updates, and container image updates, ensuring comprehensive vulnerability coverage.
3. Minimize Administrative Privileges
Minimizing administrative privileges reduces the risk of privilege escalation attacks and limits the damage that can occur when accounts are compromised. The 2018 version emphasizes cloud identity management, just-in-time access, and privileged access management that address modern access control requirements. Organizations must implement least privilege principles, granting users only the minimum privileges necessary to perform their job functions across on-premises and cloud environments.
Organizations should implement role-based access controls, separate administrative accounts from standard user accounts, and implement processes for requesting and approving elevated privileges. Administrative account usage should be monitored and logged, enabling detection of unauthorized administrative activities. Privilege minimization requires coordination between IT, security, and business units to ensure that users receive appropriate access while maintaining security. Cloud identity management and privileged access management tools enable organizations to implement least privilege effectively in modern environments.
4. Secure Configurations
Secure configurations ensure that systems are configured according to security best practices, reducing attack surface and preventing common misconfigurations that adversaries exploit. The 2018 version emphasizes cloud security configurations, container security settings, and infrastructure as code security that address modern deployment models. Organizations must establish secure configuration baselines, implement configuration management processes, and monitor systems for configuration drift across on-premises, cloud, and hybrid environments.
Organizations should use security configuration guides, implement configuration management tools, and conduct regular configuration audits that verify systems remain configured securely. Secure configuration baselines should be maintained and updated as threats evolve, ensuring that configurations address current security concerns. Configuration management processes should prevent unauthorized changes, detect configuration drift, and enable rapid recovery from configuration errors. Infrastructure as code enables organizations to manage configurations programmatically, ensuring consistent secure configurations.
5. Network Segmentation
Network segmentation isolates systems and limits lateral movement by adversaries who gain initial access. The 2018 version emphasizes cloud network segmentation, micro-segmentation, and zero trust networking that address modern network architectures. Organizations must implement network segmentation that separates systems based on security requirements, isolates critical systems, and prevents unauthorized network access across on-premises, cloud, and hybrid environments.
Organizations should implement firewalls, network access controls, and network monitoring that enforce segmentation policies and detect unauthorized network access. Segmentation should isolate critical systems, separate user networks from administrative networks, and prevent lateral movement between network segments. Cloud network segmentation and micro-segmentation enable organizations to implement granular network controls that limit lateral movement effectively. Network segmentation requires careful planning and design, with security considerations integrated throughout network architecture.
6. Continuous Monitoring
Continuous monitoring enables organizations to detect security events, identify anomalies, and respond to threats promptly. The 2018 version emphasizes cloud security monitoring, container monitoring, and security analytics that address modern deployment models. Organizations must implement security monitoring capabilities that collect security events, analyze events for threats, and alert security personnel to potential security incidents across on-premises, cloud, and hybrid environments.
Organizations should implement security information and event management (SIEM) systems, intrusion detection systems, and log management capabilities that support continuous monitoring. Monitoring capabilities should detect common attack patterns, identify anomalies, and provide alerts that enable rapid response. Cloud security monitoring and container monitoring enable organizations to maintain visibility into modern deployment models. Continuous monitoring requires ongoing attention and resources, with monitoring capabilities that evolve as threats change.
7. Incident Response Planning
Incident response planning enables organizations to respond effectively to security incidents, minimizing damage and supporting rapid recovery. The 2018 version emphasizes cloud incident response, container incident handling, and automated response capabilities that address modern environments. Organizations must develop incident response plans that define procedures for detecting, containing, eradicating, and recovering from security incidents across on-premises, cloud, and hybrid environments.
Organizations should conduct regular incident response exercises that test procedures, identify gaps, and improve response capabilities. Incident response teams should be established, trained, and equipped to respond to security incidents effectively. Cloud incident response and container incident handling require specialized procedures that address cloud and container-specific attack scenarios. Incident response planning requires coordination across organizational functions, with clear procedures that enable rapid response when incidents occur.
8. Data Protection
Data protection ensures that sensitive information remains confidential and available, protecting data from unauthorized access, disclosure, and loss. The 2018 version emphasizes cloud data protection, container data security, and data loss prevention that address modern data storage and processing models. Organizations must implement data protection controls including encryption, access controls, and backup capabilities that protect sensitive information across on-premises, cloud, and hybrid environments.
Organizations should classify data based on sensitivity, implement encryption for sensitive data, and establish backup and recovery procedures that ensure data availability. Data protection controls should prevent unauthorized access, detect data breaches, and enable rapid recovery from data loss. Cloud data protection and container data security require specialized controls that address cloud and container-specific data protection requirements. Data protection requires coordination between IT, security, and business units to ensure that sensitive information receives appropriate protection.
9. Access Controls
Access controls ensure that only authorized users can access systems and data, preventing unauthorized access and protecting sensitive information. The 2018 version emphasizes cloud identity management, multi-factor authentication, and zero trust access controls that address modern access requirements. Organizations must implement strong authentication mechanisms, enforce access policies, and monitor access activities across on-premises, cloud, and hybrid environments.
Organizations should implement multi-factor authentication for high-risk access, conduct regular access reviews, and enforce access policies consistently. Access control implementations should prevent unauthorized access, detect access anomalies, and enable rapid access revocation when necessary. Cloud identity management and zero trust access controls enable organizations to implement strong access controls effectively in modern environments. Access controls require ongoing management, with processes for provisioning, reviewing, and revoking access as organizational needs change.
10. Security Awareness and Training
Security awareness and training ensure that personnel understand security risks and their responsibilities for protecting organizational assets. The 2018 version emphasizes cloud security awareness, social engineering awareness, and security culture that address modern threat landscape. Organizations must provide security awareness training that addresses common threats, security policies, and security responsibilities, with particular emphasis on cloud security and social engineering.
Organizations should conduct regular security awareness training, assess training effectiveness, and provide ongoing security education that keeps personnel informed about evolving threats. Security awareness programs should address phishing, social engineering, cloud security risks, and other common attack techniques that target personnel. Training effectiveness should be measured and improved, ensuring that personnel understand security risks and their role in protecting organizational assets. Security culture development enables organizations to embed security awareness into organizational culture.
Implementation Strategies and Best Practices
Successfully implementing the NSA Top 10 (2018) strategies requires organizations to prioritize strategies based on risk, implement strategies progressively, and integrate strategies into existing security programs. Organizations should begin with gap assessments that evaluate current security practices against the 10 strategies, identifying implementation priorities and developing roadmaps that address high-risk areas first.
Prioritize High-Impact Strategies: Organizations should prioritize strategies that provide the greatest risk reduction, focusing on application whitelisting, patch management, and privilege minimization that address the most common attack vectors. High-impact strategies should be implemented first, providing immediate defensive value while building toward comprehensive coverage. Prioritization enables organizations to achieve meaningful security improvements quickly, demonstrating value and building momentum for additional implementations.
Address Cloud and Modern Technologies: The 2018 version emphasizes cloud security, container security, and modern deployment models that require specialized implementation approaches. Organizations should implement strategies that address cloud environments, containerized applications, and hybrid deployments. Cloud security requires specialized controls and processes that differ from traditional on-premises security. Organizations should adapt strategies to address cloud-specific requirements while maintaining foundational security principles.
Implement Application Whitelisting: Application whitelisting provides strong protection against malware and unauthorized software, making it a high-priority strategy for implementation. Organizations should implement whitelisting on critical systems first, establish processes for managing application approvals, and expand coverage progressively to cloud and containerized environments. Whitelisting implementation requires careful planning to ensure that legitimate business applications can execute while preventing unauthorized software.
Establish Comprehensive Patch Management: Timely patching addresses known vulnerabilities that adversaries exploit, making patch management essential for cybersecurity. Organizations should implement automated patch management where possible, establish patch testing processes, and deploy patches promptly across on-premises, cloud, and hybrid environments. Patch management programs should address operating system patches, application patches, cloud service updates, and container image updates.
Minimize Administrative Privileges: Privilege minimization reduces attack surface and limits damage when accounts are compromised, making it essential for cybersecurity. Organizations should implement least privilege principles, separate administrative accounts from standard accounts, and conduct regular access reviews. Cloud identity management and privileged access management tools enable organizations to implement least privilege effectively in modern environments.
Implement Secure Configurations: Secure configurations reduce attack surface and prevent common misconfigurations that adversaries exploit. Organizations should establish secure configuration baselines, implement configuration management processes, and conduct regular configuration audits. Infrastructure as code enables organizations to manage configurations programmatically, ensuring consistent secure configurations across environments.
Establish Network Segmentation: Network segmentation limits lateral movement and isolates critical systems, providing important defensive capabilities. Organizations should implement network segmentation that separates systems based on security requirements, isolates critical systems, and prevents unauthorized network access. Cloud network segmentation and micro-segmentation enable organizations to implement granular network controls.
Implement Continuous Monitoring: Continuous monitoring enables threat detection and rapid response, making it essential for effective cybersecurity. Organizations should implement security monitoring capabilities including SIEM systems, intrusion detection, and log management that provide visibility into security activities. Cloud security monitoring and container monitoring enable organizations to maintain visibility into modern deployment models.
Relationship to Other Frameworks and Standards
The NSA Top 10 (2018) strategies complement and align with other cybersecurity frameworks and standards, providing foundational practices that support comprehensive cybersecurity programs.
CIS Controls: The NSA Top 10 (2018) strategies align closely with CIS Controls, particularly the foundational controls that address basic cyber hygiene. Many strategies map directly to CIS Controls, enabling organizations to implement foundational practices that support CIS Controls implementation. Organizations implementing CIS Controls can leverage NSA Top 10 strategies as foundational practices, building comprehensive cybersecurity programs that address both foundational and advanced requirements.
NIST Cybersecurity Framework: The NSA Top 10 (2018) strategies support NIST Cybersecurity Framework functions including Identify, Protect, Detect, and Respond, providing practical guidance for implementing framework practices. Organizations implementing the Cybersecurity Framework can use NSA Top 10 strategies to implement foundational practices that support framework objectives. The strategies complement the framework's strategic guidance with practical, actionable measures that organizations can implement immediately.
NIST SP 800-53: Many NSA Top 10 (2018) strategies align with NIST SP 800-53 controls, providing practical guidance for implementing specific controls. Organizations implementing SP 800-53 can leverage NSA Top 10 strategies to implement foundational controls that address common attack vectors. The strategies provide practical implementation guidance that complements SP 800-53's comprehensive control catalog.
Cloud Security Frameworks: The 2018 version's emphasis on cloud security aligns with cloud security frameworks including Cloud Security Alliance (CSA) guidance and cloud-specific security standards. Organizations implementing cloud security frameworks can leverage NSA Top 10 strategies to implement foundational cloud security practices. The strategies provide practical guidance for implementing cloud security controls that address common cloud security concerns.
Common Challenges and Solutions
Organizations implementing the NSA Top 10 (2018) strategies frequently encounter similar challenges related to resource constraints, cloud security, operational impact, and organizational change. Understanding these common challenges helps organizations plan proactively and implement strategies effectively.
Resource Constraints: Implementing all 10 strategies requires resources including tools, expertise, and time that may be limited, particularly for smaller organizations. Organizations may struggle to allocate resources for strategy implementation, particularly when resources are already committed to other priorities. Resource constraints may force organizations to prioritize some strategies over others, potentially leaving gaps in cybersecurity coverage.
Solutions include prioritizing strategies based on risk, focusing resources on high-impact strategies first, and leveraging automation and tools to improve efficiency. Organizations should implement strategies progressively, achieving incremental progress while building capabilities over time. Risk-based prioritization enables organizations to allocate limited resources effectively, addressing the most significant risks first. Organizations should also leverage managed services and external expertise that provide capabilities without requiring internal resource development.
Cloud Security Complexity: The 2018 version's emphasis on cloud security requires organizations to address cloud-specific security concerns that may differ from traditional on-premises security. Organizations may lack cloud security expertise, struggle to implement cloud security controls, or face challenges integrating cloud security with existing security programs. Cloud security requires specialized knowledge and tools that many organizations lack.
Solutions include engaging cloud security experts, implementing cloud security tools and services, and adapting strategies to address cloud-specific requirements. Organizations should leverage cloud provider security capabilities, implement cloud security monitoring, and establish cloud security processes that address cloud-specific concerns. Cloud security training and awareness enable organizations to build internal cloud security capabilities.
Operational Impact: Some strategies may impact operational efficiency or user convenience, creating resistance from users and business units. Application whitelisting may prevent legitimate software from executing, privilege minimization may require additional approval processes, and secure configurations may limit functionality. Organizations may face pressure to relax security controls to improve operational efficiency.
Solutions include involving stakeholders in strategy design, communicating the security value of strategies, and balancing security with operational requirements. Organizations should implement strategies in ways that minimize operational disruption, provide user training and support, and demonstrate how strategies protect organizational assets. Effective communication helps stakeholders understand why strategies are necessary and how they protect against threats.
Organizational Change: Implementing strategies requires organizational change including new processes, technologies, and behaviors that may face resistance. Organizations may struggle to change established practices, adopt new technologies, or modify user behaviors. Change resistance may undermine strategy effectiveness, preventing organizations from achieving security objectives.
Solutions include establishing change management processes, providing training and support, and demonstrating the value of strategies. Organizations should involve stakeholders in strategy design, communicate strategy benefits, and provide resources that support strategy adoption. Change management processes should address resistance, provide support, and ensure that strategies are adopted effectively.
Maintaining Strategy Effectiveness: Maintaining strategy effectiveness requires ongoing attention, resources, and updates as threats evolve. Organizations may struggle to maintain strategies over time, particularly when facing resource constraints or competing priorities. Strategies may become less effective as threats evolve, requiring updates and improvements.
Solutions include establishing processes for maintaining strategies, conducting regular assessments that evaluate strategy effectiveness, and updating strategies as threats evolve. Organizations should allocate resources for strategy maintenance, conduct regular reviews, and update strategies based on threat intelligence and lessons learned. Continuous improvement processes ensure that strategies remain effective as threats evolve.
Audit and Compliance Validation
Organizations implementing the NSA Top 10 (2018) strategies may be subject to assessments that verify strategy implementation and effectiveness. While the strategies are not mandatory compliance requirements, organizations may need to demonstrate implementation for customer requirements, security assessments, or framework compliance. Organizations should maintain evidence of strategy implementation, document processes and procedures, and demonstrate that strategies are effective.
Internal assessments provide opportunities for organizations to evaluate strategy implementation, identify gaps, and improve security practices proactively. Organizations should conduct regular internal assessments that evaluate each strategy, identify implementation gaps, and prioritize improvements. Internal assessments should verify that strategies are implemented effectively and that they provide expected defensive value.
Frequently Asked Questions
What are the key updates in the NSA Top 10 (2018) compared to the 2016 version?
The 2018 version updated strategies to address evolving threats and technologies, including enhanced focus on cloud security, container security, and modern deployment models. The strategies incorporate lessons learned from recent cyber incidents and address new attack vectors including ransomware, supply chain compromises, and sophisticated phishing campaigns. While maintaining foundational principles from the 2016 version, the 2018 version provides updated guidance that addresses emerging threats and technologies.
How do the NSA Top 10 (2018) strategies address cloud security?
The 2018 version emphasizes cloud security throughout the strategies, including cloud application whitelisting, cloud patch management, cloud identity management, cloud network segmentation, and cloud security monitoring. The strategies provide guidance on implementing foundational cybersecurity practices in cloud environments, addressing cloud-specific security concerns while maintaining foundational security principles. Organizations implementing cloud deployments should adapt strategies to address cloud-specific requirements.
Who should implement the NSA Top 10 (2018) strategies?
The NSA Top 10 (2018) strategies are applicable to organizations of all sizes and sectors seeking to implement foundational cybersecurity practices. The strategies are particularly relevant for organizations establishing cybersecurity programs or migrating to cloud environments, as they provide clear guidance on essential defensive measures. Organizations with cloud deployments should pay particular attention to cloud security aspects of the strategies.
How do the NSA Top 10 (2018) strategies relate to other cybersecurity frameworks?
The NSA Top 10 (2018) strategies complement and align with other cybersecurity frameworks including CIS Controls, NIST Cybersecurity Framework, and NIST SP 800-53. Many strategies map directly to controls in these frameworks, enabling organizations to implement foundational practices that support comprehensive framework compliance. Organizations can use the NSA Top 10 strategies as foundational practices while working toward comprehensive framework compliance.
What is the difference between NSA Top 10 (2018) and later versions?
Later versions of the NSA Top 10 updated strategies further to address evolving threats and technologies, providing current best practices for cybersecurity. While the 2018 version established important updates to foundational principles, newer versions address additional emerging threats and provide updated guidance. Organizations should consider migrating to newer versions for current best practices, though the 2018 strategies remain valuable cybersecurity guidance.
How long does it take to implement the NSA Top 10 (2018) strategies?
Implementation timelines vary based on organizational size, current security maturity, cloud adoption, and resource availability. Small organizations with limited systems may implement basic strategies in 3-6 months, while larger organizations with extensive cloud deployments may require 12-24 months for comprehensive implementation. Organizations should prioritize high-impact strategies first, implementing progressively and building capabilities over time.
Are the NSA Top 10 (2018) strategies mandatory?
The NSA Top 10 (2018) strategies are not mandatory compliance requirements, but they provide valuable foundational cybersecurity practices that organizations should consider implementing. Some organizations may be required to implement strategies based on customer requirements, contractual obligations, or security assessments. Organizations should evaluate their risk exposure and implement strategies that address their specific security needs.
Conclusion
The NSA Top 10 Cybersecurity Mitigation Strategies (2018) provides essential foundational cybersecurity guidance for organizations seeking to establish or enhance cybersecurity programs, with particular emphasis on cloud security and modern deployment models. These 10 strategies address common and emerging attack vectors, providing practical, actionable measures that organizations can implement to significantly reduce cybersecurity risk exposure. While the 2018 version has been superseded by later versions, the foundational principles and cloud security focus remain valuable for organizations establishing cybersecurity programs or migrating to cloud environments.
Successful implementation requires executive support, adequate resources, qualified personnel, and sustained commitment to maintaining strategy effectiveness. Organizations should prioritize high-impact strategies first, implement strategies progressively, and integrate strategies into existing security programs. The strategies complement other cybersecurity frameworks, enabling organizations to implement foundational practices while working toward comprehensive framework compliance.
By following structured implementation approaches, prioritizing strategies based on risk, addressing cloud security requirements, and maintaining strategy effectiveness over time, organizations can achieve meaningful cybersecurity improvements that protect critical assets and reduce risk exposure. The investment in foundational cybersecurity practices pays dividends through reduced attack likelihood, improved security posture, and enhanced ability to protect organizational assets from common and emerging cyber threats.