Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 1 through 25 of 1468 matching records.
Project Pages

Cybersecurity Adoption, Awareness, & Training

https://csrc.nist.gov/projects/human-centered-cybersecurity/research-areas/cybersecurity-adoption

People and organizations often fail to adopt and effectively use cybersecurity best practices and technologies for a variety of reasons, including lack of knowledge/skills. Those professionals tasked with educating others may likewise face a number of challenges, including lack of resources, support, and skills needed to be effective security communicators. We conduct research to better understand the approaches and challenges with cybersecurity awareness and role-based training through the eyes of training professionals within the U.S. government. In the recent past, we also explored...

Project Pages

Human-Centered Cybersecurity (General)

https://csrc.nist.gov/projects/human-centered-cybersecurity/research-areas/human-centered-cybersecurity-general

Our team often writes articles or provides presentations that discuss and provide information about human-centered cybersecurity to various audiences, for example, cybersecurity practitioners or fellow researchers. We are co-hosting the Human-Centered Cybersecurity Series for the Redefining Cybersecurity Podcast (see General Human-Centered Cybersecurity -> Podcasts below). Currently, we are conducting a multi-phased research project to understand the interactions between human-centered cybersecurity researchers and practitioners. We hope the results will lead to the creation of mutually...

Projects

Human-Centered Cybersecurity

https://csrc.nist.gov/projects/human-centered-cybersecurity

The National Institute of Standards and Technology (NIST) Human-Centered Cybersecurity program, which is part of the Human-Centered Technologies Group (formerly named Visualization and Usability Group), seeks to "champion the human in cybersecurity" by conducting interdisciplinary research to better understand and improve people’s interactions with cybersecurity systems, products, processes, and services. Be sure to connect with NIST and the Human-Centered Cybersecurity program on social media and subscribe to GovDelivery to stay apprised of our latest research....

Project Pages

Phishing

https://csrc.nist.gov/projects/human-centered-cybersecurity/research-areas/phishing

Short URL: https://csrc.nist.gov/phishing Phishing continues to be an escalating cyber threat facing organizations of all types and sizes, including industry, academia, and government. Our team performs research to understand phishing within an operational (real-world) context by examining user behaviors during phishing awareness training exercises. Our projects provide insights into users’ rationale and role in early detection, and how these might be scaffolded with technological solutions. Recent efforts have focused on the NIST Phish Scale, a method for rating the human detection...

Projects

Open Security Controls Assessment Language

https://csrc.nist.gov/projects/open-security-controls-assessment-language

The Open Security Controls Assessment Language (OSCAL) is a NIST-led initiative created in partnership with industry to improve and automate security and compliance workflows. It introduces open, machine-readable formats in XML, JSON, and YAML that simplify control-based risk assessments and compliance activities. Through automation, OSCAL can reduce audit timelines from months to just minutes, decrease the likelihood of human error, and help organizations adapt more quickly to the changing regulatory requirements. OSCAL also supports hardware security by enabling machine-readable descriptions...

Project Pages

Membership

https://csrc.nist.gov/projects/ispab/members

FY 2026 ISPAB BOARD MEMBERS Steven Lipner, Former Chairperson Executive Director SAFECode Term Expired May 2026 Edna Conway CEO & Founder EMC Advisors Term Expires January 2030 Anne Dames Distinguished Engineer International Business Machines (IBM) Term Expires November 2028 Michael Duffy Associate Director for Capacity Building CISA Cybersecurity Division, Department of Homeland Security Term Expires January 2028 Bill English Chief Information Officer (CIO) / Chief AI Officer (CAIO) General Services Administration, Office of Inspector General Term Expires May 2030 Jessica...

Projects

National Online Informative References Program

https://csrc.nist.gov/projects/olir

Mappings to NIST Documents The National Online Informative References (OLIR) Program is a NIST effort to facilitate subject matter experts (SMEs) in defining standardized online informative references (OLIRs) between elements of their documents, products, and services and elements of NIST documents like the Cybersecurity Framework Version 1.1, Privacy Framework Version 1.0, NISTIR 8259A, or NIST SP 800-53 Revision 5. The NIST Internal Report (IR) 8278, R1 – National Online Informative References (OLIR) Program: Overview, Benefits, and Use focuses on explaining what OLIRs are, what benefits...

Updates

NIST's NCCoE Releases Final Version of Internal Report (IR) 8536: Supply Chain Traceability Principles: A Manufacturing Meta-Framework

September 9, 2026
https://csrc.nist.gov/news/2026/nccoe-releases-nist-ir-8536

To help strengthen the security and resilience of global supply chains, the NIST National Cybersecurity Center of Excellence (NCCoE) has released the finalized version of NIST Internal Report 8536, Supply Chain Traceability Principles: A Manufacturing Meta-Framework, which provides an interoperable, industry-neutral framework to securely exchange and verify traceability information across supply chains while enabling organizations to continue using existing industry standards.

Project Pages

OSCAL Adopters' Monthly Workshops Series

https://csrc.nist.gov/projects/open-security-controls-assessment-language/oscal-adopters-workshops

The NIST OSCAL team is hosting a series of monthly mini workshops that aims to address topics of interest for our community and to open this forum for its members to present their OSCAL-related work. Unless specifically stated, the workshops will not require a deep, technical understanding of OSCAL, and the dialog is informal, allowing the community to interact with the presenters and with the OSCAL team members. Call for Proposals The NIST OSCAL Mini Workshop program committee is seeking timely, topical, and thought-provoking technical presentations or demonstrations highlighting OSCAL...

Project Pages

Software and Supply Chain Assurance Forum

https://csrc.nist.gov/projects/cyber-supply-chain-risk-management/ssca

ABOUT Next Forum | Past Forums Cyber risk has become a topic of core strategic concern for business and government leaders worldwide and is an essential component of an enterprise risk management strategy. The Software and Supply Chain Assurance (SSCA) Forum provides a venue for government, industry, and academic participants from around the world to share their knowledge and expertise regarding software and supply chain risks, effective practices and mitigation strategies, tools and technologies, and any gaps related to the people, processes, or technologies involved. The effort...

Projects

Cybersecurity Supply Chain Risk Management

https://csrc.nist.gov/projects/cyber-supply-chain-risk-management

C-SCRM News | C-SCRM Resources Cybersecurity Supply Chain Risk Management (C-SCRM) involves identifying, assessing, and mitigating the risks associated with the distributed and interconnected nature of Information Communications Technology and Operational Technology (ICT/OT) product and service supply chains throughout the entire life cycle of a system (including design, development, distribution, deployment, acquisition, maintenance, and destruction). Examples of risks include insertion of counterfeits, unauthorized production, tampering, theft, insertion of malicious software and hardware,...

Updates

Call for Comments on NIST’s IoT Device Cybersecurity Requirement Catalog | SP 800-213A

August 31, 2026
https://csrc.nist.gov/news/2026/nist-s-sp-800-213a-released-for-comments

NIST is initiating a revision of Special Publication (SP) 800-213A, Internet of Things (IoT) Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, and has posted a Pre-Draft Call for Comments. This update aims to incorporate lessons learned, align with recent frameworks like CSF 2.0 and SP 800-53 Rev. 5.2.0, and address the evolving IoT threat landscape. This follows the draft update to SP 800-213 Rev. 1.

Project Pages

Human-Centered Cybersecurity Concept Paper

https://csrc.nist.gov/projects/human-centered-cybersecurity/human-centered-cybersecurity-concept-paper

Cybersecurity works best when it works with people, not against them — and that's exactly what human-centered cybersecurity (HCC) is all about. The Human-Centered Technologies team at NIST is releasing a concept paper on HCC, and we want your input. Our goal is to build a shared understanding of what HCC really means, then chart a path toward practical guidelines and resources that organizations can actually use to make meaningful change by: Clarifying whether HCC is primarily an approach—measured by indicators of adoption and maturity—or an outcome—requiring other measures of success such...

1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>