Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-70 Rev. 4

National Checklist Program for IT Products: Guidelines for Checklist Users and Developers

Date Published: February 2018

Supersedes: SP 800-70 Rev. 3 (12/08/2016)


Stephen Quinn (NIST), Murugiah Souppaya (NIST), Melanie Cook (NIST), Karen Scarfone (Scarfone Cybersecurity)



change detection; checklist; information security; National Checklist Program (NCP); security configuration checklist; Security Content Automation Protocol (SCAP); software configuration; vulnerability
Control Families

Audit and Accountability; Configuration Management; System and Communications Protection