Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 226 through 250 of 1442 matching records.
Publications IR 8562 (Final)

Summary Report for “Workshop on Updating Manufacturer Guidance for Securable Connected Product Development”

April 16, 2025
https://csrc.nist.gov/pubs/ir/8562/final

Abstract: This report summarizes the feedback received by the NIST Cybersecurity for the Internet of Things (IoT) program at the in-person and hybrid workshop on "Updating Manufacturer Guidance for Securable Connected Product Development" held in December 2024. The purpose of this workshop was to consider how...

Events

Trusted Semiconductor Supply Chain Workshop

April 15, 2025 - April 15, 2025
https://csrc.nist.gov/events/2025/trusted-semiconductor-supply-chain-workshop

Code of Conduct for NIST Conferences Final Agenda with Links to Presentations The NIST Trust and Provenance in the Semiconductor Supply Chain Workshop will be held as an in-person on Tuesday, April 15, 2025 at the NIST National Cybersecurity Center of Excellence (NCCoE) conference facility, in Rockville, MD. This one-day event aims to bring together technical experts from industry, academia, and the government to discuss drivers, need, methods and process to establish trust and provenance across the semiconductor supply chain. The workshop will solicit and obtain valuable feedback from the...

Updates

NIST Publishes Initial Public Draft (IPD) CSWP 42, Towards Automating IoT Security: Implementing Trusted Network -Layer Onboarding

April 14, 2025
https://csrc.nist.gov/news/2025/nist-publishes-draft-cswp-42-for-public-comment

NIST CSWP 42, Towards Automating IoT Security: Implementing Trusted Network -Layer Onboarding, is available for public comment. The comment period is open through May 29, 2025.

Updates

NIST Privacy Framework 1.1 initial public draft is available for comment

April 14, 2025
https://csrc.nist.gov/news/2025/comment-on-the-nist-privacy-framework-11

The initial public draft of the NIST Privacy Framework 1.1 is available for public comment through June 13, 2025.

Publications CSWP 40 (Initial Public Draft)

NIST Privacy Framework 1.1

April 14, 2025
https://csrc.nist.gov/pubs/cswp/40/nist-privacy-framework-11/ipd

Abstract: The NIST Privacy Framework 1.1 is a voluntary tool developed in collaboration with stakeholders intended to help organizations identify and manage privacy risk to build innovative products and services while protecting individuals’ privacy. It provides high-level privacy risk management outcomes tha...

Publications SP 1332 (Final)

Workshop Summary Report for ConnectCon 2024: “Minding the Gaps in Human-Centered Cybersecurity

April 7, 2025
https://csrc.nist.gov/pubs/sp/1332/final

Abstract: In August 2024, the National Institute of Standards and Technology (NIST) co-sponsored ConnectCon, an interactive workshop that facilitated meaningful conversations and connections between researchers and practitioners on the topic of human-centered cybersecurity. During the work...

Project Pages

Preparation Resources

https://csrc.nist.gov/projects/incident-response/preparation-resources

The following are selected examples of additional resources supporting incident response preparation. General Incident Response Programs, Policies, and Plans Carnegie Mellon University, Incident Management (includes plan, policy, and reporting templates, and incident declaration criteria) Computer Crime & Intellectual Property Section (CCIPS), U.S. Department of Justice, Best Practices for Victim Response and Reporting of Cyber Incidents Cybersecurity & Infrastructure Security Agency (CISA), Incident Response Plan (IRP) Basics NIST, Guide for Cybersecurity Event Recovery (SP...

Project Pages

Life Cycle Resources

https://csrc.nist.gov/projects/incident-response/life-cycle-resources

The following are selected examples of additional resources supporting the incident response life cycle. Vulnerability and Threat Information CISA, Automated Indicator Sharing (AIS) CISA, CISA Cyber Threat Indicator and Defensive Measure Submission System CISA, Cybersecurity Alerts & Advisories CISA, Cybersecurity Directives CISA, Ransomware Vulnerability Warning Pilot (RVWP) The MITRE Corporation, MITRE ATT&CK National Council of ISACs (NCI) NIST, Guide to Cyber Threat Information Sharing (SP 800-150) NIST, National Vulnerability Database (NVD) NIST, Recommendations for...

Updates

NIST Revises SP 800-61: Incident Response Recommendations and Considerations for Cybersecurity Risk Management

April 3, 2025
https://csrc.nist.gov/news/2025/nist-revises-sp-800-61

NIST has finalized Special Publication (SP) 800-61r3 (Revision 3), Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile.

Publications SP 800-61 Rev. 3 (Final)

Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile

April 3, 2025
https://csrc.nist.gov/pubs/sp/800/61/r3/final

Abstract: This publication seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities as described by the NIST Cybersecurity Framework (CSF) 2.0. Doing so can help organizations prepare for incid...

Publications SP 1800-33 (Initial Public Draft)

5G Cybersecurity

March 18, 2025
https://csrc.nist.gov/pubs/sp/1800/33/ipd

Abstract: The National Cybersecurity Center of Excellence (NCCoE) is collaborating with technology providers and other companies on a project to develop example solution approaches for safeguarding 5G networks. These solutions use combinations of cybersecurity and privacy measures drawn from 5G capabilities a...

Project Pages

Industrial Case Studies - Combinatorial and Pairwise Testing

https://csrc.nist.gov/projects/automated-combinatorial-testing-for-software/combinatorial-methods-in-testing/case-studies-and-examples

Combinatorial testing is being applied successfully in nearly every industry, and is especially valuable for assurance of high-risk software with safety or security concerns. Combinatorial testing is referred to as effectively exhaustive, or pseudo-exhaustive, because it can be as effective as fully exhaustive testing, while reducing test set size by 20X to more than 100X. Case studies below are from many types of applications, including aerospace, automotive, autonomous systems, cybersecurity, financial systems, video games, industrial controls, telecommunications, web applications, and...

Updates

Draft CSF 2.0 Quick Start Guide: Cybersecurity, Enterprise Risk Management, and Workforce Management

March 12, 2025
https://csrc.nist.gov/news/2025/csf-20-cyber-erm-and-workforce-managment-qsg

The latest Quick Start Guide for the NIST Cybersecurity Framework 2.0 is available for public comment through April 25, 2025.

Updates

Considerations for Achieving Crypto Agility: NIST Releases CSWP 39 for Public Comment

March 5, 2025
https://csrc.nist.gov/news/2025/nist-releases-cswp-39-for-public-comment

NIST Cybersecurity White Paper (CSWP), Considerations for Achieving Crypto Agility, provides an in-depth survey of current approaches and considerations to achieving crypto agility.

Updates

Now Open for Public Comment | NIST Cybersecurity Framework 2.0 Profile for Semiconductor Manufacturing

February 27, 2025
https://csrc.nist.gov/news/2025/draft-csf-profile-for-semiconductor-manufacturing

The NIST National Cybersecurity Center of Excellence (NCCoE) along with the SEMI Semiconductor Manufacturing Cybersecurity Consortium has released Draft NIST Internal Report (IR) 8546, Cybersecurity Framework (CSF) 2.0 Semiconductor Manufacturing Community Profile for public comment until 11:59 PM ET on July 30, 2025.

Publications IR 8546 (Initial Public Draft)

Cybersecurity Framework Version 2.0 Semiconductor Manufacturing Profile

February 27, 2025
https://csrc.nist.gov/pubs/ir/8546/ipd

Abstract: This document defines a Cybersecurity Framework (CSF) 2.0 Community Profile with a voluntary, risk-based approach to managing cybersecurity activities and reducing cyber risks for semiconductor development and manufacturing. Collaboratively developed in support of the National Cybersecurity Implemen...

Updates

Integrating Cybersecurity and Enterprise Risk Management | NIST IR 8286 Series Revisions and Updates

February 26, 2025
https://csrc.nist.gov/news/2025/cybersecurity-and-erm-nist-ir-8286-series-revision

NIST has released revisions or updates to all five publications in its Interagency Report (IR) 8286 series. The public comment period is open through April 14, 2025, for the initial public drafts of IR 8286r1, IR 8286Ar1, and IR 8286Cr1.

Project Pages

About the Forum

https://csrc.nist.gov/projects/forum/about-the-forum

The NIST Cybersecurity & Privacy Professionals Forum is co-chaired by representatives of NIST's Information Technology Laboratory, Computer Security Division (CSD) and Applied Cybersecurity Division (ACD). The Forum Secretariat provides the necessary administrative and logistical support for operations. The Forum serves as an important mechanism for NIST to: exchange information directly with cybersecurity and privacy professionals in U.S. federal, state, and local government, and higher education organizations in fulfillment of its leadership mandate under the Federal Information...

Publications IR 8286B (Final)

Prioritizing Cybersecurity Risk for Enterprise Risk Management

February 26, 2025
https://csrc.nist.gov/pubs/ir/8286/b/upd1/final

Abstract: This document is the second in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional detail regarding the enterprise application of cybersecurity risk information; the previous document, NIST IR 82...

Publications IR 8286D (Final)

Using Business Impact Analysis to Inform Risk Prioritization and Response

February 26, 2025
https://csrc.nist.gov/pubs/ir/8286/d/upd1/final

Abstract: While business impact analysis (BIA) has historically been used to determine availability requirements for business continuity, the process can be extended to provide a broad understanding of the potential impacts of any type of loss on the enterprise mission. The management of enterprise risk requi...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>