Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 676 through 700 of 1417 matching records.
Updates

NICE Framework Competencies: 2nd Draft NISTIR 8355 Available for Comment

December 15, 2021
https://csrc.nist.gov/news/2021/nice-framework-competencies-2nd-draft-nistir-8355

The National Initiative for Cybersecurity Education (NICE) has released a second draft of NISTIR 8355, NICE Framework Competencies: Assessing Learners for Cybersecurity Work.

Project Pages

Related References

https://csrc.nist.gov/projects/mcspwg/nccp

Title / Topic Description Executive Order (EO) 14028 On Improving The Nation's Cybersecurity Executive Order 14028, “Improving the Nation’s Cybersecurity” marks a renewed commitment and prioritization of federal cybersecurity modernization and strategy. To keep pace with modern technological advancements and evolving threats, the Federal Government continues to migrate to the cloud. In support of these efforts, the Secretary of Homeland Security acting through the Director of the Cybersecurity and Infrastructure Security Agency...

Updates

NCCoE Releases Draft Project Description for IPv6 Transition

December 9, 2021
https://csrc.nist.gov/news/2021/nccoe-draft-project-description-ipv6-transition

The National Cybersecurity Center of Excellence (NCCoE) has released a new draft project description, Secure IPv6-Only Implementation in the Enterprise.

Publications Project Description (Initial Public Draft)

Secure IPv6-Only Implementation in the Enterprise

December 9, 2021
https://csrc.nist.gov/pubs/pd/2021/12/09/secure-ipv6only-implementation-in-the-enterprise/ipd

Abstract: The NCCoE is planning a project to provide guidance and a reference architecture that address operational, security, and privacy issues associated with the evolution to IPv6-only network infrastructures. The project will demonstrate tools and methods for securely implementing IPv6, whether as a “gre...

Updates

Combination Frequency Differencing: Draft NIST Cybersecurity White Paper

December 6, 2021
https://csrc.nist.gov/news/2021/combination-frequency-differencing-draft

A draft NIST Cybersecurity White Paper, Combination Frequency Differencing, is now available for public comment.

Events

Federal Cybersecurity & Privacy Professionals Forum - December 02, 2021

December 2, 2021 - December 2, 2021
https://csrc.nist.gov/events/2021/federal-cybersecurity-privacy-professionals-fo-1

Presentations & Speakers at a Glance: Update from the Office of the Federal Chief Information Officer, Maria Roat (OMB) Update from GAO on the Cybersecurity & Information Security Audit Manual, Jennifer R. Franks (GAO) OMB Circular A-130 Implementation and Updates to SP 800-53 and FedRAMP, Carol Bales (OMB), Brian Conrad (GSA), and Vicky Pillitteri (NIST) Federal Zero Trust Strategy, Eric Mill (OMB) NOTE: FORUM MEETINGS ARE OPEN TO ONLY FEDERAL/STATE EMPLOYEES, HIGHER EDUCATION EMPLOYEES, AND THEIR DESIGNATED SUPPORT CONTRACTORS. REGISTRANTS MUST USE A .GOV, .EDU, OR .MIL...

Events

2nd Public Draft SP 800-161 Revision 1 Workshop

December 1, 2021 - December 1, 2021
https://csrc.nist.gov/events/2021/2nd-public-draft-sp-800-161-revision-1-workshop

Click on the image to access the 2nd public draft of Special Publication (SP) 800-161, Revision 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (released October 28, 2021). PRESENTATION for WORKSHOP (.PDF) Event Description: The NIST Cybersecurity Supply Chain Risk Management Team is hosting a webinar to provide an overview of the changes made in its 2nd public draft of Special Publication 800 – 161, Revision 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. NIST seeks to engage stakeholders to provide clarity,...

Updates

NIST Updates IoT Cybersecurity Guidance and Accompanying Catalog

November 29, 2021
https://csrc.nist.gov/news/2021/updates-to-iot-cybersecurity-guidance-and-catalog

NIST has released final IoT-specific guidance (NIST Special Publications 800-213 and 800-213A) to federal organizations to support extending their risk management process to the inclusion of IoT devices in federal systems.

Publications SP 800-213 (Final)

IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements

November 29, 2021
https://csrc.nist.gov/pubs/sp/800/213/final

Abstract: Organizations will increasingly use Internet of Things (IoT) devices for the mission benefits they can offer, but care must be taken in the acquisition and implementation of IoT devices. This publication contains background and recommendations to help organizations consider how an IoT device they pl...

Publications SP 800-213A (Final)

IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog

November 29, 2021
https://csrc.nist.gov/pubs/sp/800/213/a/final

Abstract: This publication provides a catalog of internet of things (IoT) device cybersecurity capabilities (i.e., features and functions needed from a device to support security controls) and non-technical supporting capabilities (i.e., actions and support needed from device manufacturers and other supportin...

Updates

Enterprise Patch Management: Draft Publications Available for Comment

November 17, 2021
https://csrc.nist.gov/news/2021/two-draft-publications-enterprise-patch-management

Two draft publications on enterprise patch management are available for public comment through January 10, 2022: Draft SP 800-40 Rev. 4 and Draft SP 1800-31.

Updates

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management: NISTIR 8286A

November 12, 2021
https://csrc.nist.gov/news/2021/identifying-and-estimating-cybersecurity-risk

NISTIR 8286A, Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management, provides an in-depth discussion of the concepts introduced in NISTIR 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM).

Publications IR 8286A (Final) (Withdrawn)

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

November 12, 2021

https://csrc.nist.gov/pubs/ir/8286/a/final

Abstract: This document supplements NIST Interagency or Internal Report 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM), by providing additional detail regarding risk guidance, identification, and analysis. This report offers examples and information to illustrate risk tolerance, risk app...

Projects

National Initiative for Improving Cybersecurity in Supply Chains

https://csrc.nist.gov/projects/niics

[Redirect to: https://www.nist.gov/cybersecurity/improving-cybersecurity-supply-chains-nists-public-private-partnership] In 2021, NIST announced a new effort to work with the private sector and others in government to improve cybersecurity supply chains. This initiative, NIICS, will help organizations to build, evaluate, and assess the cybersecurity of products and services in their supply chains, an area of increasing concern. It will emphasize tools, technologies, and guidance focused on the developers and providers of technology.

Publications Other (Final)

Privacy-enhancing cryptography tools to complement differential privacy techniques

November 3, 2021
https://csrc.nist.gov/pubs/other/2021/11/03/privacyenhancing-cryptography-tools/final

Abstract: In this post, we illustrate how various techniques from privacy-enhancing cryptography, coupled with differential privacy protection, can be used to protect data privacy while enabling data utility. Of notable interest is the setting where there are multiple sources of relevant data, each having pri...

Updates

Cybersecurity Supply Chain Risk Management Practices: Second Draft SP 800-161 Rev. 1 Available for Comment

October 28, 2021
https://csrc.nist.gov/news/2021/2nd-draft-sp-800-161-rev-1-cscrm-practices

A second public draft of Special Publication (SP) 800-161 Revision 1, "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations," is open for comment through December 10, 2021.

Updates

Hardware-Enabled Security and Trusted Cloud: Draft Reports Available for Comment

October 27, 2021
https://csrc.nist.gov/news/2021/hardware-enabled-security-and-trusted-cloud-draft

The National Cybersecurity Center of Excellence (NCCoE) has released three new draft reports on hardware-enabled security and trusted cloud for public comment.

Publications IR 8397 (Final)

Guidelines on Minimum Standards for Developer Verification of Software

October 6, 2021
https://csrc.nist.gov/pubs/ir/8397/final

Abstract: Executive Order (EO) 14028, Improving the Nation’s Cybersecurity, 12 May 2021, directs the National Institute of Standards and Technology (NIST) to recommend minimum standards for software testing within 60 days. This document describes eleven recommendations for software verification techniques as...

Updates

Secure Software Development Framework (SSDF) Draft Update Available for Comment

September 30, 2021
https://csrc.nist.gov/news/2021/ssdf-draft-sp-800-218-available-for-comment

Draft NIST Special Publication (SP) 800-218, "Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities," is open for comment through Nov. 5, 2021.

Updates

NIST Publishes 2020 Cybersecurity and Privacy Program Annual Report

September 30, 2021
https://csrc.nist.gov/news/2021/nist-publishes-2020-cybersecurity-and-privacy-prog

NIST just released Special Publication (SP) 800-214, 2020 Cybersecurity and Privacy Program Annual Report.

Updates

New NIST White Paper | Benefits of an Updated Mapping between the NIST CSF and the NERC Critical Infrastructure Protection Standards

September 29, 2021
https://csrc.nist.gov/news/2021/updated-mapping-btwn-nist-csf-and-nerc-cip-stnds

This white paper highlights a recent mapping effort between the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) standards and the NIST Cybersecurity Framework.

<< first   < previous   16     17     18     19     20     21     22     23     24     25     26     27     28     29     30     31     32     33     34     35     36     37     38     39     40  next >  last >>