Use this form to search content on CSRC pages.
Protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations is critical to federal agencies. The suite of guidance (NIST Special Publication (SP) 800-171, SP 800-171A, SP 800-172, and SP 800-172A) focuses on protecting the confidentiality of CUI and recommends specific security requirements to achieve that objective. Recent Updates May 13, 2026: NIST issues SP 800-172r3, Enhanced Security Requirements for Protecting Controlled Unclassified Information, and SP 800-172Ar3, Assessing Enhanced Security Requirements for Controlled Unclassified...
Abstract: This guide provides small business owners and operators with a high-level overview of NIST Special Publication (SP) 800-171Ar3 (Revision 3), Assessing Security Requirements for Controlled Unclassified Information.
The concept of Attribute Based Access Control (ABAC) has existed for many years. It represents a point on the spectrum of logical access control from simple access control lists to more capable role-based access, and finally to a highly flexible method for providing access based on the evaluation of attributes. In November 2009, the Federal Chief Information Officers Council (Federal CIO Council) published the Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Plan v1.0, which provided guidance to federal organizations to evolve their logical access control...
*NEW* Short course from the Defense and Aerospace Test and Analysis Workshop 2025 (Dataworks 2025) - complete course presentation here. The goal of this project is to provide practitioners and researchers with a foundational understanding of combinatorial testing techniques and applications to testing AI-enabled software systems (AIES). Resources are being developed in these areas: Combinatorial testing (CT), applying CT to test traditional software systems, including real-world examples and case studies. How Test and Evaluation (T&E) of AIES differ from traditional software systems...
The NIST OSCAL team hosts a series of mini workshops for the OSCAL community to learn, share, and connect. Each session explores topics of interest, highlights real-world OSCAL implementations, and gives community members an opportunity to present their work and exchange ideas. Most of the workshops are designed to be accessible to a broad audience and do not require deep technical knowledge of OSCAL. Discussions are interactive, with plenty of opportunities to ask questions and engage with presenters and the OSCAL team. If you are interested in presenting your OSCAL-related work or proposing...
The Open Security Controls Assessment Language (OSCAL) is a NIST-led initiative created in partnership with industry to improve and automate security and compliance workflows. It introduces open, machine-readable formats in XML, JSON, and YAML that simplify control-based risk assessments and compliance activities. Through automation, OSCAL can reduce audit timelines from months to just minutes, decrease the likelihood of human error, and help organizations adapt more quickly to the changing regulatory requirements. OSCAL also supports hardware security by enabling machine-readable...
People and organizations often fail to adopt and effectively use cybersecurity best practices and technologies for a variety of reasons, including lack of knowledge/skills. Those professionals tasked with educating others may likewise face a number of challenges, including lack of resources, support, and skills needed to be effective security communicators. We conduct research to better understand the approaches and challenges with cybersecurity awareness and role-based training through the eyes of training professionals within the U.S. government. In the recent past, we also explored...
Our team often writes articles or provides presentations that discuss and provide information about human-centered cybersecurity to various audiences, for example, cybersecurity practitioners or fellow researchers. We are co-hosting the Human-Centered Cybersecurity Series for the Redefining Cybersecurity Podcast (see General Human-Centered Cybersecurity -> Podcasts below). Currently, we are conducting a multi-phased research project to understand the interactions between human-centered cybersecurity researchers and practitioners. We hope the results will lead to the creation of mutually...
The National Institute of Standards and Technology (NIST) Human-Centered Cybersecurity program, which is part of the Human-Centered Technologies Group (formerly named Visualization and Usability Group), seeks to "champion the human in cybersecurity" by conducting interdisciplinary research to better understand and improve people’s interactions with cybersecurity systems, products, processes, and services. Be sure to connect with NIST and the Human-Centered Cybersecurity program on social media and subscribe to GovDelivery to stay apprised of our latest research....
Short URL: https://csrc.nist.gov/phishing Phishing continues to be an escalating cyber threat facing organizations of all types and sizes, including industry, academia, and government. Our team performs research to understand phishing within an operational (real-world) context by examining user behaviors during phishing awareness training exercises. Our projects provide insights into users’ rationale and role in early detection, and how these might be scaffolded with technological solutions. Recent efforts have focused on the NIST Phish Scale, a method for rating the human detection...
FY 2026 ISPAB BOARD MEMBERS Steven Lipner, Former Chairperson Executive Director SAFECode Term Expired May 2026 Edna Conway CEO & Founder EMC Advisors Term Expires January 2030 Anne Dames Distinguished Engineer International Business Machines (IBM) Term Expires November 2028 Michael Duffy Associate Director for Capacity Building CISA Cybersecurity Division, Department of Homeland Security Term Expires January 2028 Bill English Chief Information Officer (CIO) / Chief AI Officer (CAIO) General Services Administration, Office of Inspector General Term Expires May 2030 Jessica...
Mappings to NIST Documents The National Online Informative References (OLIR) Program is a NIST effort to facilitate subject matter experts (SMEs) in defining standardized online informative references (OLIRs) between elements of their documents, products, and services and elements of NIST documents like the Cybersecurity Framework Version 1.1, Privacy Framework Version 1.0, NISTIR 8259A, or NIST SP 800-53 Revision 5. The NIST Internal Report (IR) 8278, R1 – National Online Informative References (OLIR) Program: Overview, Benefits, and Use focuses on explaining what OLIRs are, what benefits...
To help strengthen the security and resilience of global supply chains, the NIST National Cybersecurity Center of Excellence (NCCoE) has released the finalized version of NIST Internal Report 8536, Supply Chain Traceability Principles: A Manufacturing Meta-Framework, which provides an interoperable, industry-neutral framework to securely exchange and verify traceability information across supply chains while enabling organizations to continue using existing industry standards.
ABOUT Next Forum | Past Forums Cyber risk has become a topic of core strategic concern for business and government leaders worldwide and is an essential component of an enterprise risk management strategy. The Software and Supply Chain Assurance (SSCA) Forum provides a venue for government, industry, and academic participants from around the world to share their knowledge and expertise regarding software and supply chain risks, effective practices and mitigation strategies, tools and technologies, and any gaps related to the people, processes, or technologies involved. The effort...
C-SCRM News | C-SCRM Resources Cybersecurity Supply Chain Risk Management (C-SCRM) involves identifying, assessing, and mitigating the risks associated with the distributed and interconnected nature of Information Communications Technology and Operational Technology (ICT/OT) product and service supply chains throughout the entire life cycle of a system (including design, development, distribution, deployment, acquisition, maintenance, and destruction). Examples of risks include insertion of counterfeits, unauthorized production, tampering, theft, insertion of malicious software and hardware,...
Type: Presentation
Type: Presentation
Type: Presentation
Type: Presentation
NIST is initiating a revision of Special Publication (SP) 800-213A, Internet of Things (IoT) Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, and has posted a Pre-Draft Call for Comments. This update aims to incorporate lessons learned, align with recent frameworks like CSF 2.0 and SP 800-53 Rev. 5.2.0, and address the evolving IoT threat landscape. This follows the draft update to SP 800-213 Rev. 1.
Abstract: