Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 51 through 75 of 1414 matching records.
Projects

Federal Cybersecurity and Privacy Professionals Forum

https://csrc.nist.gov/projects/forum

The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of cybersecurity and privacy knowledge, best practices, and resources among U.S. federal, state, and local government, and higher education organizations. The Federal Cybersecurity and Privacy Professionals Forum ("the Forum") maintains an extensive email list, and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. There is no cost...

Projects

Security Research Review Seminar

https://csrc.nist.gov/projects/srr-seminar

Security Research Review Seminar is a biweekly talk arranged by the Computer Security Division (773) of the Information Technology Laboratory (ITL) at NIST. Researchers, academics, and practitioners for within and outside NIST are invited to discuss their work in the areas of hardware, software, AI, and system level security. Interesting topics related to verification, validation, assurance, and standardizations are also discussed. Upcoming Talks The following schedule is tentative: Date Speaker Title Dec/Jan Hamid...

Updates

Secure Onboarding of IoT Devices to Networks: NIST Publishes CSWP 42, IR 8350, and SP 1800-36

November 25, 2025
https://csrc.nist.gov/news/2025/secure-onboarding-of-iot-devices-to-networks

The NCCoE is releasing three publications to help secure IoT devices and their networks: Cybersecurity White Paper 42, Internal Report 8350, and Special Publication 1800-36.

Publications SP 1800-36 (Final)

Trusted Internet of Things (IoT) Device Network-Layer Onboarding and Lifecycle Management: Enhancing Internet Protocol-Based IoT Device and Network Security

November 25, 2025
https://csrc.nist.gov/pubs/sp/1800/36/final

Abstract: Establishing trust between a network and an Internet of Things (IoT) device (as defined in NIST Internal Report 8425) prior to providing the device with the credentials it needs to join the network is crucial for mitigating the risk of potential attacks. There are two possibilities for attack. One h...

Updates

Second Public Draft of CSF 2.0 Quick-Start Guide for Cybersecurity, ERM, and Workforce Management

November 24, 2025
https://csrc.nist.gov/news/2025/nist-sp-1308-second-public-draft-qsg

A second public draft of NIST SP 1308, NIST CSF 2.0: Cybersecurity, Enterprise Risk Management, and Workforce Management Quick-Start Guide, is available for public comment through January 7, 2026.

Publications SP 1308 (2nd Public Draft)

NIST Cybersecurity Framework 2.0: Cybersecurity, Enterprise Risk Management, and Workforce Management Quick-Start Guide

November 24, 2025
https://csrc.nist.gov/pubs/sp/1308/2pd

Abstract: This Quick Start Guide (QSG) shows how the NICE Workforce Framework for Cybersecurity and the Cybersecurity Framework (CSF) can be used together to facilitate communication across business units and improve organizational processes where cybersecurity, enterprise risk management (ERM), and workforce...

Projects

Log Management

https://csrc.nist.gov/projects/log-management

NIST is in the process of addressing public comments on Draft Special Publication (SP) 800-92 Revision 1, Cybersecurity Log Management Planning Guide. The purpose of this document is to help all organizations improve their log management so they have the log data they need. The document's scope is cybersecurity log management planning, and all other aspects of logging and log management, including implementing log management technology and making use of log data, are out of scope. This document replaces the original SP 800-92, Guide to Computer Security Log Management. That material was...

Projects

Incident Response

https://csrc.nist.gov/projects/incident-response

In April 2025, NIST finalized Special Publication (SP) 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. NIST SP 800-61 Revision 3 seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities as described by the NIST Cybersecurity Framework (CSF) 2.0. Doing so can help organizations prepare for incident responses, reduce the number and impact of incidents that occur, and improve the efficiency...

Project Pages

Workshops and Timeline

https://csrc.nist.gov/projects/post-quantum-cryptography/workshops-and-timeline

Workshops Date September 24-26, 2025 Sixth PQC Standardization Conference (In-Person / Virtual) Venue: NIST Gaithersburg, Maryland, USA Call for Papers April 10-12, 2024 Fifth PQC Standardization Conference (In-Person) Hilton Washington DC/Rockville Hotel Rockville, MD Call for Papers November 29- December 1, 2022 Fourth PQC Standardization Conference Virtual Call for Papers June 7-9, 2021 Third...

Updates

Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments | NIST SP 1334

September 30, 2025
https://csrc.nist.gov/news/2025/cyber-risks-of-portable-storage-media-in-ot

The NCCoE has released Special Publication 1334, "Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments."

Updates

Foundational Cybersecurity Activities for IoT Product Manufacturers | IR 8259r1 2pd

September 30, 2025
https://csrc.nist.gov/news/2025/nist-ir-8259r1-second-public-draft

The second public draft of IR 8259r1, "Foundational Cybersecurity Activities for IoT Product Manufacturers," is available for comment through December 10, 2025.

Publications SP 1334 (Final)

Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments

September 30, 2025
https://csrc.nist.gov/pubs/sp/1334/final

Abstract: Portable storage media continue to be useful tools for transferring data physically to and from Operational Technology (OT) environments. Universal Serial Bus (USB) flash drives are commonly used, in addition to external hard drives, CD or DVD drives, and other removable media.Though portable storag...

Publications IR 8259 Rev. 1 (2nd Public Draft)

Foundational Cybersecurity Activities for IoT Product Manufacturers

September 30, 2025
https://csrc.nist.gov/pubs/ir/8259/r1/2pd

Abstract: Internet of Things (IoT) products often lack product cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving the securability of their IoT products by providing necess...

Project Pages

External References

https://csrc.nist.gov/projects/cyber-supply-chain-risk-management/references

***Disclaimer: Items in the following lists are provided for research purposes, and do not imply endorsement by NIST.*** U.S. Government Activities / Initiatives Related Standards / Best Practices C-SCRM Research / References Involved Standards Organizations / Associations U.S. Government Activities / Initiatives Committee on National Security Systems Directive (CNSSD) 505 - "...provides the guidance for organizations that own, operate, or maintain [National Security Systems (NSS)] to address supply chain risk and implement and sustain SCRM capabilities". Comprehensive National...

Updates

Cybersecurity Framework 2.0 Manufacturing Profile: NIST IR 8183r2 Initial Public Draft

September 29, 2025
https://csrc.nist.gov/news/2025/csf-2-0-manufacturing-profile-initial-draft

The initial public draft of NIST IR 8183r2 (Revision 2), "Cybersecurity Framework 2.0 Manufacturing Profile," is available for public comment through November 17, 2025.

Publications IR 8183 Rev. 2 (Initial Public Draft)

Cybersecurity Framework 2.0 Manufacturing Profile

September 29, 2025
https://csrc.nist.gov/pubs/ir/8183/r2/ipd

Abstract: This document provides the Cybersecurity Framework (CSF) Version 2.0 Community Profile developed for supporting manufacturing environments. This “Manufacturing Profile” is aligned with manufacturing sector goals and industry best practices and can be used as a roadmap for reducing cybers...

Updates

Guidelines for Media Sanitization: NIST Publishes SP 800-88r2

September 26, 2025
https://csrc.nist.gov/news/2025/guidelines-for-media-sanitization-rev-2

NIST has released Special Publication (SP) 800-88r2 (Revision 2), Guidelines for Media Sanitization.

Updates

Now Available for Comment: White Paper on Migration to Post-Quantum Cryptography (PQC)

September 18, 2025
https://csrc.nist.gov/news/2025/pqc-migration-mappings-to-risk-framework-documents

The NIST National Cybersecurity Center of Excellence (NCCoE) has published an initial public draft of NIST Cybersecurity White Paper (CSWP) 48, "Mappings of Migration to PQC Project Capabilities to Risk Framework Documents." Comments are due October 20, 2025.

Publications CSWP 48 (Initial Public Draft)

Mappings of Migration to PQC Project Capabilities to NIST Cybersecurity Framework 2.0 and to Security and Privacy Controls for Information Systems and Organizations

September 18, 2025
https://csrc.nist.gov/pubs/cswp/48/mapping-migration-to-pqc-project-capabilities-to-r/ipd

Abstract: The capabilities demonstrated by the NCCoE Migration to Post-Quantum Cryptography project support several security objectives and controls identified by the NIST Cybersecurity Framework 2.0 (CSWP 29) and Security and Privacy Controls for Information Systems and Organizations (SP 800-53), respectivel...

Updates

Addressing Visibility Challenges with TLS 1.3 within the Enterprise: NIST Publishes SP 1800-37

September 17, 2025
https://csrc.nist.gov/news/2025/addressing-visibility-challenges-tls-1-3

The final release of Special Publication 1800-37, Addressing Visibility Challenges with TLS 1.3 within the Enterprise, is now available.

Publications SP 1800-37 (Final)

Addressing Visibility Challenges with TLS 1.3 within the Enterprise: High-Level Document

September 17, 2025
https://csrc.nist.gov/pubs/sp/1800/37/final

Abstract: The Transport Layer Security (TLS) protocol is widely deployed to secure network traffic. TLS 1.3 protects the contents of its previous TLS communications even if a TLS-enabled server is compromised. This is known as forward secrecy. The approach used to achieve forward secrecy in TLS 1.3 may...

Events

FORUM Meeting - September 16, 2025

September 16, 2025 - September 16, 2025
https://csrc.nist.gov/events/2025/forum-meeting-september-16-2025

The Federal Cybersecurity & Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of system security and privacy information among federal, state, and local government, and higher education employees. The Forum maintains an extensive Email list and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. For more information about the Forum and instructions on how to join, see: https://csrc.nist.gov/Projects/forum. A...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>