Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 751 through 775 of 1405 matching records.
Updates

Securing Property Management Systems: Cybersecurity Practice Guide SP 1800-27

March 30, 2021
https://csrc.nist.gov/news/2021/securing-property-management-systems-sp-1800-27

NIST's NCCoE has published Cybersecurity Practice Guide SP 1800-27, "Securing Property Management Systems."

Publications SP 1800-27 (Final)

Securing Property Management Systems

March 30, 2021
https://csrc.nist.gov/pubs/sp/1800/27/final

Abstract: Hotels have become targets for malicious actors wishing to exfiltrate sensitive data, deliver malware, or profit from undetected fraud. Property management systems, which are central to hotel operations, present attractive attack surfaces. This example implementation strives to increase the cybersec...

Updates

Cybersecurity Framework Election Infrastructure Profile: Draft NISTIR 8310 Available for Comment

March 29, 2021
https://csrc.nist.gov/news/2021/draft-nistir-8310-election-infrastructure-profile

A new draft NISTIR 8310, "Cybersecurity Framework Election Infrastructure Profile," is available for public comment through May 14, 2021.

Publications IR 8333 (Final)

Workshop Summary Report for “Cybersecurity Risks in Consumer Home Internet of Things (IoT) Products” Virtual Workshop

March 29, 2021
https://csrc.nist.gov/pubs/ir/8333/final

Abstract: This report provides a summary of the discussion and findings from the NIST Cybersecurity Risks in Consumer Home Internet of Things (IoT) Devices virtual workshop in October 2020. NIST Interagency Report (NISTIR) 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers, and NISTIR 82...

Publications Journal Article (Final)

Cybersecurity Advocates: Discovering the Characteristics and Skills for an Emergent Role

March 22, 2021
https://csrc.nist.gov/pubs/journal/2021/03/cybersecurity-advocates-discovering-the-characteri/final

Journal: Information and Computer Security Abstract: Purpose:Cybersecurity advocates safeguard their organizations by promoting security best practices. However, little is known about what constitutes successful advocacy.Methodology:We conducted 28 in-depth interviews of cybersecurity advocates.Findings:Effective advocates not only possess technical a...

Publications Journal Article (Final)

Cybersecurity Standards and Guidelines to Assist Small and Medium-Sized Manufacturers

March 18, 2021
https://csrc.nist.gov/pubs/journal/2021/03/cybersecurity-stnds-guidelines-assist-small-medium/final

Journal: USNC Current Abstract: For many industrial control systems (ICS), it is unacceptable to degrade performance even for the sake of security. As a result, many organizations such as small and medium-size manufacturers (SMMs) may have difficulty with understanding how to implement cybersecurity standards in ICS environments....

Updates

NICE Framework Competencies: Draft NISTIR 8355 Available for Comment

March 17, 2021
https://csrc.nist.gov/news/2021/nice-framework-competencies-draft-nistir-8355

Draft NISTIR 8355, "NICE Framework Competencies: Assessing Learners for Cybersecurity Work," is available for comment through May 3, 2021.

Updates

Trusted IoT Device Network-Layer Onboarding and Lifecycle Management: Draft Project Description

March 16, 2021
https://csrc.nist.gov/news/2021/draft-trusted-iot-device-onboarding-lcm

The National Cybersecurity Center of Excellence has released a Draft Project Description on Trusted IoT Device Network-Layer Onboarding and Lifecycle Management. The public comment period is open through April 21, 2021.

Publications Journal Article (Final)

Pandemic Parallels: What Can Cybersecurity Learn From COVID-19?

March 15, 2021
https://csrc.nist.gov/pubs/journal/2021/03/pandemic-parallels-what-can-cybersecurity-learn-fr/final

Journal: Computer (IEEE Computer) Abstract: While the threats may appear to be vastly different, further investigation reveals that the cybersecurity community can learn much from the COVID-19 messaging response.

Updates

Addressing Visibility Challenges with TLS 1.3: Draft Project Description Available for Comment

February 26, 2021
https://csrc.nist.gov/news/2021/addressing-visibility-challenges-with-tls-1-3

The NCCoE is requesting comments on a new Draft Project Description, "Addressing Visibility Challenges with TLS 1.3." Public comments may be submitted through March 29, 2021.

Events

Federal Cybersecurity & Privacy Forum - Feb 2021

February 23, 2021 - February 23, 2021
https://csrc.nist.gov/events/2021/fcsm-forum-february-2021

Presentations & Speakers at a Glance: NIST Cyber Risk Scoring Program Overview, Sheldon Pratt, IT Security Assessor, & Santi Kiran, IT Security Assessor, NIST; and Threat-based Risk Profiling Methodology, Zach Baldwin, FedRAMP, Program Manager for Strategy, Innovation, and Technology, GSA, and Tom Volpe, Principal and Subject Matter Expert, VITG NOTE: FORUM MEETINGS ARE OPEN TO ONLY FEDERAL/STATE EMPLOYEES, HIGHER EDUCATION EMPLOYEES, AND THEIR DESIGNATED SUPPORT CONTRACTORS. REGISTRANTS MUST USE A .GOV, .EDU, OR .MIL ADDRESS FOR SIGN-UP. SUPPORT CONTRACTORS MUST INDICATE THE AGENCY...

Project Pages

Security testing

https://csrc.nist.gov/projects/automated-combinatorial-testing-for-software/cybersecurity-testing-1/security-testing

The tools distributed here are used extensively in testing for security vulnerabilities. Survey article: Simos, D. E., Kuhn, R., Voyiatzis, A. G., & Kacker, R. (2016). Combinatorial Methods in Security Testing. IEEE Computer, 49(10), 80-83. Introduces CT-based approaches for security testing and presents our case studies and experiences so far. The success of the presented research program motivates further intensive research on the field of combinatorial security testing. In particular, security testing for the Internet of Things (IoT) is an area where these approaches may prove...

Updates

NIST's Key Practices in Cyber Supply Chain Risk Management: Observations from Industry--NISTIR 8276

February 11, 2021
https://csrc.nist.gov/news/2021/nistir-8276-key-practices-in-c-scrm

NIST announces the publication of NISTIR 8276, Key Practices in Cyber Supply Chain Risk Management: Observations from Industry.

Updates

Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation and Timing Services--NISTIR 8323

February 11, 2021
https://csrc.nist.gov/news/2021/nistir-8323-foundational-pnt-profile

NIST publishes NISTIR 8323, "Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services," in response to Executive Order 13905 of Feb. 12, 2020.

Publications IR 8323 (Final) (Withdrawn)

Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services

February 11, 2021

https://csrc.nist.gov/pubs/ir/8323/final

Abstract: The national and economic security of the United States (US) is dependent upon the reliable functioning of the nation’s critical infrastructure. Positioning, Navigation, and Timing (PNT) services are widely deployed throughout this infrastructure. In a government wide effort to mitigate the potentia...

Publications IR 8276 (Final)

Key Practices in Cyber Supply Chain Risk Management: Observations from Industry

February 11, 2021
https://csrc.nist.gov/pubs/ir/8276/final

Abstract: In today’s highly connected, interdependent world, all organizations rely on others for critical products and services. However, the reality of globalization, while providing many benefits, has resulted in a world where organizations no longer fully control—and often do not have full visibility into...

Updates

5G Cybersecurity: Preliminary Draft of NIST Cybersecurity Practice Guide SP 1800-33A

February 1, 2021
https://csrc.nist.gov/news/2021/preliminary-draft-of-sp-1800-33a-5g-cybersecurity

A preliminary draft of SP 1800-33A, "5G Cybersecurity," is available for comment through March 4, 2021.

Publications SP 800-171 Rev. 2 (Final) (Withdrawn)

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

January 28, 2021

https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final

Abstract: The protection of Controlled Unclassified Information (CUI) resident in nonfederal systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the federal government to successfully conduct its essential missions and functions. This publication pro...

Events

Challenges Digital Proximity Detection Pandemics

January 26, 2021 - January 28, 2021
https://csrc.nist.gov/events/2021/challenges-for-digital-proximity-in-pandemics

The "Challenges for Digital Proximity Detection in Pandemics: Privacy, Accuracy, and Impact" workshop is a forum to discuss successes and challenges associated with implementation of proximity detection technologies and identify areas in which additional effort is required. These areas could be, but are not limited to, privacy and cybersecurity concerns, testbeds, machine learning algorithms, efficacy modelling, new technologies, data and standards, validation and verification, and commercialization. See more details on the workshop webpage:...

Updates

NIST Releases Supplemental Materials for SP 800-53 and SP 800-53B: Control Catalog and Control Baselines in Spreadsheet Format

January 26, 2021
https://csrc.nist.gov/news/2021/control-catalog-and-baselines-as-spreadsheets

New supplemental materials are available for SP 800-53 Rev. 5 and SP 800-53B: spreadsheets for the Control Catalog and Control Baselines.

Events

Workshop on Improving the Security of DevOps

January 21, 2021 - January 21, 2021
https://csrc.nist.gov/events/2021/workshop-on-improving-the-security-of-devops

The purpose of this workshop is to discuss the National Institute of Standards and Technology’s (NIST’s) proposed approach for helping industry and government improve the security of their DevOps practices. During this workshop, NIST will solicit proposed approaches from the participating organizations and hear from the community about DevSecOps-related topics that NIST could tackle. The findings from the workshop will inform NIST in the creation of new applied guidance to fill any gaps, updates to existing guidance, and potential development of a National Cybersecurity Center of Excellence...

Project Pages

FISSEA Cybersecurity Awareness and Training Innovators and former Educator of the Year Recipients.

https://csrc.nist.gov/projects/fissea/contests-and-awards/past-eoty-winners

2019: Shehzad Mirza, Director of Operations – Global Cyber Alliance 2018: Earl “Fred” Bisel Jr, Cybersecurity Education and Certification Readiness Facilities (CERF) Manager Nomination Letter for 2018 EOY Award 2017: Mike Petock, All Native Group (ANG) Nomination Letter for 2017 EOY Award 2016: Sushil Jajodia, George Mason University Nomination Letter for 2016 EOY Award 2015: Gretchen Ann Morris, DB Consulting/NASA John H. Glenn Research Center Nomination Letter for 2015 EOY Award 2014: Shon Harris, Logical Security, presented posthumously Nomination Letters for 2014 EOY Award...

<< first   < previous   19     20     21     22     23     24     25     26     27     28     29     30     31     32     33     34     35     36     37     38     39     40     41     42     43  next >  last >>