NIST Regulatory Requirements in Ensuring National Cybersecurity
Elshad Neymatov · International journal of latest research in engineering and technology. · 2025
The study focuses on conducting an analysis of the regulatory mandates of the National Institute of Standards and Technology of the United States (NIST) as an element in constructing a comprehensive national cybersecurity system.The objective of the article is to systematize and evaluate the effectiveness of implementing the NIST Cybersecurity Framework (CSF) for the protection of strategically significant sectors: healthcare, energy, and transport complex.The methodological basis consisted of a retrospective system-synthetic analysis of current scientific publications for 2021-2025, relevant regulatory acts, and statistical reports reflecting practices of NIST standards implementation.As a result of the study, the main advantages and bottlenecks in adapting NIST CSF in various sectors were identified, and recommendations for further improvement of the framework model were formulated.In particular, with regard to the protection of electronic medical records (EHR), it is proposed to implement a multi-level approach combining AES-256 encryption, role-based access control (RBAC), and continuous monitoring for strict compliance with HIPAA requirements.The scientific novelty lies in reconceiving NIST CSF not as a static set of prescriptions, but as a dynamic, adaptive system capable of integrating sectoral specificity and timely responding to new technological challenges.The practical significance of the obtained conclusions is determined by their value for cybersecurity specialists, representatives of regulatory authorities, and leaders of critical infrastructure organizations responsible for developing strategic measures for the protection of information assets.