- Can
my organization participate now?
- I
would like to participate eventually, what should I do now?
- What
are the ABCs of checklist development and participation?
- How
do I submit my existing checklist(s)?
- How
do I create a checklist description for the checklist repository?
- What
are the requirements for using the checklist program logo?
1.
Can my organization participate now?
Yes.
You may begin participating by working with NIST on developing checklists
for submission to the repository.
2.
I would like to participate, what should I do now?
If
you are interested in participating, please contact NIST; you can
be placed on a mailing list for announcements and NIST can answer
any questions you have and provide assistance as necessary. Please
see the Contact page for further information
on contacting NIST or download the participation
materials.
3.
What are the ABCs of checklist development and participation?
NIST
Special Publication 800-70: Security Configuration Checklists for
IT Products Program contains details and instructions for new
checklist development. The basic steps for checklist development
are as follows:
- Download
and read checklist development information (contained in NIST
Special Publication 800-70: Security Configuration Checklists
for IT Products Program) and checklist program participation
information (found on the Participation
Materials page).
- Select
an operational environment (Standalone or SOHO, Managed or Enterprise,
Customs such as Specialized Security-Limited Functionality or
Legacy).
- Develop
a checklist (targeted towards the selected operational environment
from step two) and checklist documentation according to the recommendations
and requirements of the program.
- Test
the checklist and complete
a checklist description form.
- Submit
the checklist, the checklist description, and a participation
agreement to NIST for review.
- Answer
questions as a result of the public review and resolve remaining
issues with checklist format or content.
-
Maintain the checklist as changes to the IT product occur.
The
checklist documentation should contain the following:
- A
statement of the checklist's security objectives, including the
targeted operational environment and expected behavior of the
product after applying the checklist.
-
The target audience (e.g., end-user, system administrator) and
the level of technical skill required to install the checklist.
-
An explanation of the checklist settings, including each setting’s
effect on the operation of the product and any functionality the
settings enable or disable.
-
Backup procedures or any other initial steps required before applying
the checklist.
-
As appropriate, step-by-step instructions for applying the checklist
(e.g., screen shots, illustrated procedures) and verifying that
the installation is successful.
-
Procedures for uninstalling the checklist (if applicable).
-
Troubleshooting instructions or other information and references.
For
more specific details and procedures, download and read NIST
Special Publication 800-70: Security Configuration Checklists for
IT Products Program or contact NIST.
4.
How do I submit my existing checklist(s)?
Existing
checklists should be submitted to NIST along with a completed checklist
description form (a blank version is available from this site;
see the next question). Existing checklists that are created and
supported by IT product vendors do not necessarily require a public
review, however this will be determined on a case-by-case basis.
5.
How do I create a checklist description for the checklist repository?
The checklist description describes various aspects of a checklist;
the descriptions fields are accessible via the checklist
repository so that users can browse and select checklists. You
can download a blank checklist
description form, complete its fields, and then return it along
with the checklist and other related material to NIST. Refer to
the participation materials.
6.
What are the requirements for using the checklist program logo?

Checklist
producers, e.g., vendors, will be able to use the checklist program
logo on product literature or websites to show participation in
the NIST program and ownership of a checklist on the repository.
To use the logo, the producer must provide assistance or support
to its product users (as per its customary support agreements) who
use the checklist; i.e., use of the checklist cannot void product
warranties or support agreements. The logo does not convey NIST
endorsement or support of the checklist or IT product. See the participation
and logo usage agreement for more details.
Please
send comments if your questions
were not answered here.
Top
of Page |