Computer Security Resource Center

Computer Security Resource Center

Computer Security
Resource Center

White Paper (DRAFT)

[Project Description] Data Confidentiality: Detect, Respond to, and Recover from Data Breaches

Date Published: June 2019
Comments Due: July 29, 2019 (public comment period is CLOSED)
Email Questions to: ds-nccoe@nist.gov

Planning Note (6/24/2019): See the related Draft Project Description, Data Confidentiality: Identifying and Protecting Assets and Data Against Data Breaches, which is also open for comment through July 29, 2019.

Author(s)

Jennifer Cawthra (NIST), Michael Ekstrom (MITRE), Lauren Lusty (MITRE), Julian Sexton (MITRE), John Sweetnam (MITRE), Anne Townsend (MITRE)

Announcement

The National Cybersecurity Center of Excellence (NCCoE) announces the release of the second of two new Data Confidentiality (DC) draft project descriptions. 
 
This component of the DC suite of publications is entitled Detect, Respond to, and Recover from Data Breaches and seeks to provide the technical capabilities needed by an organization to maintain full awareness of its data as well as mitigate the effects of a data breach. The implementation will include data and network monitoring, event detection, and other potential technologies. The solution will use security controls that adhere to the NIST Cybersecurity Framework and industry standards and best practices. 
 
This project will result in a freely available NIST Cybersecurity Practice Guide in the Special Publication 1800 series. To that end, we are requesting your feedback to help refine the challenge and scope of the project. 

Abstract

Keywords

data breach; data confidentiality; data loss; data protection; malware; ransomware; spear phishing
Control Families

None selected