Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 251 through 275 of 1318 matching records.
Publications SP 800-60 Rev. 2 (Initial Working Draft)

Guide for Mapping Types of Information and Systems to Security Categories

January 31, 2024
https://csrc.nist.gov/pubs/sp/800/60/r2/iwd

Abstract: NIST Special Publication (SP) 800-60 facilities the application of appropriate levels of information security according to a range of levels of impact or consequence that may result from unauthorized disclosure, modification, or use of the information or systems. This publication provides a methodol...

Updates

Addressing Visibility Challenges with TLS 1.3 within the Enterprise: SP 1800-37 2nd Preliminary Draft

January 30, 2024
https://csrc.nist.gov/news/2024/2nd-prelim-draft-of-nist-sp-180037

Volumes A (2nd preliminary draft) and B (initial prelim. draft) of NIST Special Publication 1800-37, Addressing Visibility Challenges with TLS 1.3 within the Enterprise, are available for public comment through April 1, 2024.

Publications SP 1800-37 (2nd Preliminary Draft)

Addressing Visibility Challenges with TLS 1.3 within the Enterprise

January 30, 2024
https://csrc.nist.gov/pubs/sp/1800/37/2prd

Abstract: The Transport Layer Security (TLS) protocol is widely deployed to secure network traffic. The latest version, TLS 1.3, has been strengthened so that even if a TLS-enabled server is compromised, the contents of its previous TLS communications are still protected—better known as forward secrecy. The a...

Events

NIST SSDF for Generative AI and Dual Use Foundation Models

January 17, 2024 - January 17, 2024
https://csrc.nist.gov/events/2024/nist-ssdf-for-generative-ai-dual-use-foundation

We look forward to welcoming you to NIST’s Virtual Workshop on Secure Development Practices for AI Models on January 17. This workshop is being held in support of Executive Order (EO) 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence. EO 14110 tasked NIST with “developing a companion resource to the Secure Software Development Framework (SSDF) to incorporate secure development practices for generative AI and for dual-use foundation models.” What You Will Learn This workshop will bring together industry, academia, and government to discuss secure development...

Updates

Measurement Guide for Information Security: NIST SP 800-55 Draft Volumes 1 and 2 Available for Comment

January 17, 2024
https://csrc.nist.gov/news/2024/nist-sp-800-55-draft-available-for-comment

NIST Special Publication (SP) Draft 800-55, Measurement Guide for Information Security, Volume 1 — Identifying and Selecting Measures, and Volume 2 — Developing an Information Security Measurement Program, are now available for public review and comment through March 18, 2024.

Updates

Pre-Draft Call for Comments | Information Security Handbook: A Guide for Managers

January 9, 2024
https://csrc.nist.gov/news/2024/pre-draft-call-for-comments-sp-800-100

NIST plans to update Special Publication (SP) 800-100, Information Security Handbook: A Guide for Managers, and is issuing a Pre-Draft Call for Comments to solicit feedback from users. Deadline to submit comments is February 23, 2024.

Publications SP 800-100 Rev. 1 (Initial Preliminary Draft)

PRE-DRAFT Call for Comments | Information Security Handbook: A Guide for Managers

January 9, 2024
https://csrc.nist.gov/pubs/sp/800/100/r1/iprd

Abstract: [See the Abstract for SP 800-100]

Updates

Cybersecurity of Genomic Data: NIST IR 8432

December 20, 2023
https://csrc.nist.gov/news/2023/cybersecurity-of-genomic-data-nist-ir-8432

The NIST National Cybersecurity Center of Excellence has released NIST Internal Report (IR) 8432, "Cybersecurity of Genomic Data."

Publications IR 8432 (Final)

Cybersecurity of Genomic Data

December 20, 2023
https://csrc.nist.gov/pubs/ir/8432/final

Abstract: Genomic data has enabled the rapid growth of the U.S. bioeconomy and is valuable to the individual, industry, and government because it has multiple intrinsic properties that in combination make it different from other types of data that possess only a subset of these properties. The characteristics...

Updates

Automation Support for Control Assessments: Project Update and Vision

December 6, 2023
https://csrc.nist.gov/news/2023/nist-has-released-cswp-30

NIST has released Cybersecurity White Paper (CSWP) 30, Automation Support for Control Assessments – Project Update and Vision, which describes planned updates to the NIST Interagency Report (IR) 8011 series.

Publications CSWP 30 (Final)

Automation Support for Control Assessments: Project Update and Vision

December 6, 2023
https://csrc.nist.gov/pubs/cswp/30/automation-support-for-control-assessments-project/final

Abstract: In 2017, the National Institute of Standards and Technology (NIST) published a methodology for supporting the automation of Special Publication (SP) 800-53 control assessments in the form of Interagency Report (IR) 8011. IR 8011 is a multi-volume series that starts with an overview of the methodolog...

Events

Forum Meeting - December 5, 2023

December 5, 2023 - December 5, 2023
https://csrc.nist.gov/events/2023/forum-meeting-december-5-2023

The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of system security and privacy information among federal, state, and local government, and higher education employees. The Forum maintains an extensive e-mail list and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. For more information about the Forum and instructions on how to join, see: https://csrc.nist.gov/Projects/forum....

Project Pages

Learn. What is the CPRT?

https://csrc.nist.gov/projects/cprt/learn

NIST seeks to accelerate the adoption of our cybersecurity and privacy standards, guidelines, and frameworks by making it much easier for users of NIST products to identify, locate, compare, and customize content across NIST’s standards, guidelines, and practices. This will also add value to our existing NIST guidance by delivering human- and machine-consumable information. What is the Cybersecurity and Privacy Reference Tool (CPRT)? The CPRT provides a centralized, standardized, and modernized mechanism for managing reference datasets (and offers a consistent format for accessing reference...

Project Pages

About

https://csrc.nist.gov/projects/cprt/about

Why are we doing this? NIST seeks to : Accelerate the adoption of our cybersecurity and privacy standards, guidelines, and frameworks by making it much easier for users of NIST products to identify, locate, compare, and customize content across NIST’s standards, guidelines, and practices. Add value to our existing reference datasets by delivering human- and machine-consumable reference datasets. The CPRT provides a centralized, standardized, and modernized mechanism for managing reference datasets, eventually creating the opportunity to correlate and establish relationships...

Project Pages

Key NIST Resource List

https://csrc.nist.gov/projects/cprt/resources

CPRT Roadmap Explore the CPRT Project Roadmap, a strategic guide delineating our three crucial phases. Mappings to NIST Documents Explore the process for developing and submitting standardized mappings that involve NIST cybersecurity and privacy publications. Cross-Reference Comparison Report Tool Browse and compare the mappings and crosswalks of industry standards and frameworks to existing NIST Publications. JSON and CSV downloadable content is available for additional customization of the generated reports.

Publications Conference Paper (Final)

The Design and Application of a Unified Ontology for Cyber Security

December 3, 2023
https://csrc.nist.gov/pubs/conference/2023/12/03/the-design-and-application-of-a-unified-ontology-f/final

Conference: 19th International Conference on Information and Systems Security (ICISS 2023) Abstract: Ontology enables semantic interoperability, making it highly valuable for cyber threat hunting. Community-driven frameworks like MITRE ATT&CK, D3FEND, ENGAGE, CWE and CVE have been developed to combat cyber threats. However, manually navigating these independent data sources is time-consuming an...

Updates

The NIST Phish Scale User Guide is Now Available!

November 20, 2023
https://csrc.nist.gov/news/2023/the-nist-phish-scale-user-guide-is-now-available

The National Institute of Standards and Technology Human-Centered Cybersecurity program is pleased to announce the release of the NIST Phish Scale User Guide.

Updates

Just Released! Risk Management in the Enterprise: NIST SP 800-221 & NIST SP 800-221A

November 17, 2023
https://csrc.nist.gov/news/2023/just-released-nist-sp-800-221-nist-sp-800-221a

Today, NIST is issuing best practices on how to better integrate ICT risk programs into an overarching ERM portfolio—given special attention to coordination and communication across risk programs.

Publications SP 800-221 (Final)

Enterprise Impact of Information and Communications Technology Risk: Governing and Managing ICT Risk Programs Within an Enterprise Risk Portfolio

November 17, 2023
https://csrc.nist.gov/pubs/sp/800/221/final

Abstract: All enterprises should ensure that information and communications technology (ICT) risk receives appropriate attention within their enterprise risk management (ERM) programs. This document is intended to help individual organizations within an enterprise improve their ICT risk management (ICTRM). Th...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>