Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 7621 Rev. 1

Small Business Information Security: The Fundamentals

Date Published: November 2016

Supersedes: IR 7621 (10/01/2009)


Celia Paulsen (NIST), Patricia Toth (NIST)



cybersecurity; fundamentals  ; ; information security; small business
Control Families

Access Control; Awareness and Training; Configuration Management; Contingency Planning; Identification and Authentication; Media Protection; Physical and Environmental Protection; Planning; Personnel Security; System and Services Acquisition; System and Communications Protection; System and Information Integrity


Download URL

Supplemental Material:
Press Release
"Ignoring Cybersecurity is Risky Business" (blog post)

Related NIST Publications:
ITL Bulletin

Document History:
11/03/16: IR 7621 Rev. 1 (Final)


Security and Privacy

awareness training & education, planning


small & medium business