Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 226 through 250 of 1412 matching records.
Project Pages

Human-Centered Cybersecurity Community of Interest

https://csrc.nist.gov/projects/human-centered-cybersecurity/hcc-coi

Human-centered cybersecurity (HCC) (also known as usable security) involves the social, organizational, and technological influences on people’s understanding of and interactions with cybersecurity. By taking a human-centered cybersecurity approach, we can both improve people's cybersecurity experiences and achieve better cybersecurity outcomes. This Google Group provides a forum for human-centered cybersecurity researchers, cybersecurity and IT practitioners, and human factors experts to share ideas, best practices, and potential engagement opportunities. Read the September 2024 NIST Blog...

Updates

Ransomware Risk Management: CSF 2.0 Community Profile | Draft NIST IR 8374r1 Available for Comment

January 13, 2025
https://csrc.nist.gov/news/2025/draft-ransomware-risk-management-csf-20-profile

The NCCoE has posted an intial public draft of NIST Internal Report 8374r1, "Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile," for comment. The public comment period is open through March 14, 2025.

Publications IR 8374 Rev. 1 (Initial Public Draft)

Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile

January 13, 2025
https://csrc.nist.gov/pubs/ir/8374/r1/ipd

Abstract: Ransomware is a type of malicious attack where attackers encrypt an organization’s data and demand payment to restore access. Attackers may also steal an organization’s information and demand an additional payment in return for not disclosing the information to authorities, competitors, or the publi...

Updates

NIST Publishes NIST IR 8498, Cybersecurity for Smart Inverters: Guidelines for Residential and Light Commercial Solar Energy Systems

December 20, 2024
https://csrc.nist.gov/news/2024/nist-publishes-nist-ir-8498

This report (NIST IR 8498) provides practical cybersecurity guidance for small-scale solar inverter implementations that are typically used in homes and small businesses.

Publications IR 8498 (Final)

Cybersecurity for Smart Inverters: Guidelines for Residential and Light Commercial Solar Energy Systems

December 20, 2024
https://csrc.nist.gov/pubs/ir/8498/final

Abstract: This report provides practical cybersecurity guidance for small-scale solar inverter implementations that are typically used in homes and small businesses. These guidelines are informed by a review of known smart-inverter vulnerabilities documented in the National Vulnerability Database (NVD), a rev...

Topics

Executive Order 14028

https://csrc.nist.gov/topics/laws-and-regulations/executive-documents/executive-order-14028

Improving the Nation's Cybersecurity (May 12, 2021). For more information, see this other NIST site.

Updates

NIST Genomic Data Cybersecurity and Privacy Publications | Comment Period Open

December 17, 2024
https://csrc.nist.gov/news/2024/nccoe-releases-2-draft-documents-for-comments

The second public draft of NIST Internal Report (IR) 8467, "Genomic Data Cybersecurity and Privacy Frameworks Community Profile" and the initial public draft of NIST Cybersecurity White Paper (CSWP) 35, "Cybersecurity Threat Modeling the Genomic Data Sequencing Workflow" are open for public comment through January 30, 2025.

Publications IR 8467 (2nd Public Draft)

Genomic Data Cybersecurity and Privacy Frameworks Community Profile

December 16, 2024
https://csrc.nist.gov/pubs/ir/8467/2pd

Abstract: Advancements in genomic sequencing technologies are accelerating the speed and volume of data collection, sequencing, and analysis. However, this progress also heightens cybersecurity and privacy risks. This Genomic Data Cybersecurity and Privacy Frameworks Community Profile (“Genomic Data Profile”)...

Updates

Requesting Public Comment | NIST Guidance on Implementing a Zero Trust Architecture (ZTA)

December 5, 2024
https://csrc.nist.gov/news/2024/nist-guidance-on-implementing-a-zta

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the draft of the practice guide, Implementing a Zero Trust Architecture (NIST SP 1800-35), for public comment. The public comment period is open through January 31, 2025.

Project Pages

Standards/Guidelines

https://csrc.nist.gov/projects/measurements-for-information-security/standards-guidelines

These are standard publications and guidelines that provide perspectives and frameworks to inform, measure, and manage cybersecurity vulnerabilities and exposures. NIST SP 800-55 Vol. 1 Measurement Guide for Information Security: Volume 1 — Identifying and Selecting Measures Volume 1, Identifying and Selecting Measures, provides a flexible approach to the development, selection, and prioritization of information security measures. This volume explores both quantitative and qualitative assessment and provides basic guidance on data analysis techniques as well as impact and likelihood...

Project Pages

Tools

https://csrc.nist.gov/projects/measurements-for-information-security/tools

These are tools and utilities to assess the level of security risks and provide a mechanism to enhance automation for the cybersecurity information exchange. Baldrige Cybersecurity Excellence Builder (BCEB) A self-assessment tool to help organizations better understand the effectiveness of their cybersecurity risk management efforts and identity improvement opportunities in the context of their overall organizational performance. Common Vulnerability Scoring System (CVSS) An open framework for communicating the characteristics and severity of software vulnerabilities. CVSS is well...

Project Pages

Reference Sources

https://csrc.nist.gov/projects/measurements-for-information-security/reference-sources

These are reference sources for frameworks, algorithms validation, software assurance, testing, and other measurements related to information security. Automated Combinatorial Testing for Software Combinatorial or t-way testing is a proven method for more effective software testing at lower cost. The research toolkit can make sure that there are no simultaneous input combinations that might inadvertently cause a dangerous error. Cryptographic Algorithm Validation Program (CAVP) The NIST Cryptographic Algorithm Validation Program provides validation testing of Approved (i.e.,...

Updates

NIST Report on the 2024 Accordion Cipher Mode Workshop

November 21, 2024
https://csrc.nist.gov/news/2024/report-on-2024-accordion-cipher-mode-workshop

NIST releases NIST IR 8537, NIST Workshop on the Requirements for an Accordion Cipher Mode 2024: Workshop Report.

Publications CSWP 38 (Initial Public Draft)

NIST Privacy Workforce Taxonomy

November 21, 2024
https://csrc.nist.gov/pubs/cswp/38/nist-privacy-workforce-taxonomy/ipd

Abstract: This document provides a taxonomy of Task, Knowledge, and Skill (TKS) Statements aligned with the NIST Privacy Framework, Version 1.0 and the NICE Workforce Framework for Cybersecurity model of TKS Statement building blocks. It contains a mapping of the Taxonomy’s TKS Statements to the NIST Privacy...

Publications IR 8537 (Final)

NIST Workshop on the Requirements for an Accordion Cipher Mode 2024: Workshop Report

November 21, 2024
https://csrc.nist.gov/pubs/ir/8537/final

Abstract: NIST hosted the NIST Workshop on the Requirements for an Accordion Cipher Mode 2024 on June 20--21, 2024, at the National Cybersecurity Center of Excellence in Rockville, Maryland. This report summarizes the participant feedback, key takeaways, and future directions discussed during the event.

Events

Forum Meeting - November 19, 2024

November 19, 2024 - November 19, 2024
https://csrc.nist.gov/events/2024/forum-meeting-november-19-2024

The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of system security and privacy information among federal, state, and local government, and higher education employees. The Forum maintains an extensive e-mail list and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. For more information about the Forum and instructions on how to join, see: https://csrc.nist.gov/Projects/forum....

Updates

Comment Now! NIST Cybersecurity White Paper: Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration

November 7, 2024
https://csrc.nist.gov/news/2024/cswp-34-is-available-for-public-comment

The NCCoE has released for public comment the draft of NIST Cybersecurity White Paper (CSWP) 34, Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration. The comment period for the draft is now open through January 21, 2025.

Updates

NCCoE Released NIST CSWP 36C, Reallocation of Temporary Identities - Applying 5G Cybersecurity and Privacy Capabilities White Paper Series for Public Comment

November 7, 2024
https://csrc.nist.gov/news/2024/cswp-36c-is-available-for-public-comment

Draft CSWP 36C, Reallocation of Temporary Identities - Applying 5G Cybersecurity & Privacy Capabilities White Paper Series for Public Comment. The public comment period is open through December 6, 2024.

Updates

NEW | NIST Releases Errata Update for Cybersecurity Supply Chain Risk Management Guidance

November 1, 2024
https://csrc.nist.gov/news/2024/new-nist-errata-update-c-scrm

NIST has released an errata update to its foundational publication on managing cybersecurity risks in supply chains.

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>