You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to https://csrc.nist.gov.
An official website of the United States government
Here’s how you know
Official websites use .gov A
.gov website belongs to an official government
organization in the United States.
Secure .gov websites use HTTPS A
lock (
) or https:// means you’ve safely connected to
the .gov website. Share sensitive information only on official,
secure websites.
C-SCRM News | C-SCRM Resources Cybersecurity Supply Chain Risk Management (C-SCRM) involves identifying, assessing, and mitigating the risks associated with the distributed and interconnected nature of Information Communications Technology and Operational Technology (ICT/OT) product and service supply chains throughout the entire life cycle of a system (including design, development, distribution, deployment, acquisition, maintenance, and destruction). Examples of risks include insertion of...
NIST has traditionally published secure configuration guides for Apple operating systems, e.g., NIST SP 800-179. The macOS Security Compliance Project (mSCP) seeks to simplify the macOS security development cycle by reducing the amount of effort required to implement security baselines. This collaboration between federal organizations minimizes the duplicate effort that would be required to administer individual security baselines. Additionally, the secure baseline content provided is easily...
The Open Security Controls Assessment Language (OSCAL) is a NIST-led initiative created in partnership with industry to improve and automate security and compliance workflows. It introduces open, machine-readable formats in XML, JSON, and YAML that simplify control-based risk assessments and compliance activities. Through automation, OSCAL can reduce audit timelines from months to just minutes, decrease the likelihood of human error, and help organizations adapt more quickly to the changing...
Recent Updates January 8, 2026: To facilitate discussion at the Cyber AI Profile Workshop #2 on January 14, 2026, an annotated outline (discussion draft) of Control Overlays for Securing AI Systems: Using and Fine-Tuning Predictive AI is available for review. Feedback is welcomed at the workshop, through ongoing engagement in the COSAiS Slack Channel, and by email to [email protected]. Initial feedback on this annotated outline should be submitted by February 13, 2026 to...