Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 776 through 800 of 1324 matching records.
Publications SP 1800-16 (Final)

Securing Web Transactions: TLS Server Certificate Management

June 16, 2020
https://csrc.nist.gov/pubs/sp/1800/16/final

Abstract: This NIST Cybersecurity Practice Guide shows large and medium enterprises how to employ a formal TLS certificate management program to address certificate-based risks and challenges. It describes the TLS certificate management challenges faced by organizations; provides recommended best practices fo...

Events

FISSEA Summer Series

June 1, 2020 - August 1, 2020
https://csrc.nist.gov/events/2020/fissea-summer-series

→ June 22, 2020 Meeting the Need: Training that Rocks The world is changing before our eyes – no doubt about it. If we, as learning and development leaders, are to keep up with the required changes, trends, and learner needs, we’ve also got to make some big changes. We’ve invited four incredibly high-impact learning and development leaders to talk with us about how we can take our training development and delivery to the next level. In this session, experts from both cybersecurity and training development are going to discuss how you can change your cybersecurity awareness program to be...

Updates

Security for IoT Device Manufacturers: NIST Publishes NISTIRs 8259 and 8259A

June 1, 2020
https://csrc.nist.gov/news/2020/security-iot-device-manufacturers-8259-and-8259a

Two publications, NISTIRs 8259 and 8259A, are now available to provide cybersecurity best practices and guidance for IoT device manufacturers.

Publications IR 8259A (Final)

IoT Device Cybersecurity Capability Core Baseline

May 29, 2020
https://csrc.nist.gov/pubs/ir/8259/a/final

Abstract: Device cybersecurity capabilities are cybersecurity features or functions that computing devices provide through their own technical means (i.e., device hardware and software). This publication defines an Internet of Things (IoT) device cybersecurity capability core baseline, which is a set of devic...

Publications IR 8259 (Final)

Foundational Cybersecurity Activities for IoT Device Manufacturers

May 29, 2020
https://csrc.nist.gov/pubs/ir/8259/final

Abstract: Internet of Things (IoT) devices often lack device cybersecurity capabilities their customers—organizations and individuals—can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving how securable the IoT devices they make are by providing necessary cyber...

Events

Advancing Cybersecurity Risk Management Conference

May 27, 2020 - May 28, 2020
https://csrc.nist.gov/events/2020/advancing-cybersecurity-risk-management-conference

NIST is closely monitoring guidance from Federal, State, and local health authorities on the outbreak of COVID-19. To protect the health and safety of NIST employees and the American public they continue to serve, NIST has decided to cancel the May 2020 Advancing Cybersecurity Risk Management conference. For more information on COVID-19, please visit: cdc.gov/covid19. For questions regarding your registration, please contact pauline.truong@nist.gov. We hope you are able to participate in future in-person and virtual NIST cybersecurity risk management events. Building on the 2018 NIST...

Updates

Draft White Paper on "Getting Ready for Post-Quantum Cryptography" is Available for Comment

May 26, 2020
https://csrc.nist.gov/news/2020/draft-nist-cswp-on-getting-ready-for-pqc

NIST has posted a draft Cybersecurity White Paper, "Getting Ready for Post-Quantum Cryptography: Explore Challenges Associated with Adoption and Use of Post-Quantum Cryptographic Algorithms." The public comment period ends June 30, 2020.

Publications SP 1800-23 (Final)

Energy Sector Asset Management: For Electric Utilities, Oil & Gas Industry

May 20, 2020
https://csrc.nist.gov/pubs/sp/1800/23/final

Abstract: Industrial control systems (ICS) compose a core part of our nation’s critical infrastructure. Energy sector companies rely on ICS to generate, transmit, and distribute power and to drill, produce, refine, and transport oil and natural gas. Given the wide variety of ICS assets, such as programmable l...

Publications IR 8196 (Final)

Security Analysis of First Responder Mobile and Wearable Devices

May 11, 2020
https://csrc.nist.gov/pubs/ir/8196/final

Abstract: Public safety practitioners utilizing the forthcoming Nationwide Public Safety Broadband Network (NPSBN) will have smartphones, tablets, and wearables at their disposal. Although these devices should enable first responders to complete their missions, any influx of new technologies will introduce ne...

Updates

Symposium on Federally Funded Research on Cybersecurity of Electric Vehicle Supply Equipment (EVSE): NISTIR 8294

April 29, 2020
https://csrc.nist.gov/news/2020/nistir-8294-symposium-on-cybersecurity-of-evse

NISTIR 8294, "Symposium on Federally Funded Research on Cybersecurity of Electric Vehicle Supply Equipment (EVSE)," has been published, describing a NIST-hosted event from September 12, 2019. It also includes the meeting agenda and seven presentations.

Publications IR 8294 (Final)

Symposium on Federally Funded Research on Cybersecurity of Electric Vehicle Supply Equipment (EVSE)

April 29, 2020
https://csrc.nist.gov/pubs/ir/8294/final

Abstract: Electric vehicles are becoming common on the Nation’s roads, and the electric vehicle supply equipment infrastructure (EVSE) is being created to support that growth. The NIST Information Technology Lab (ITL) hosted a one-day symposium to showcase federally funded research into the potential cybersec...

Updates

Hardware-Enabled Security for Server Platforms: Draft White Paper Available for Comment

April 28, 2020
https://csrc.nist.gov/news/2020/draft-wp-on-hardware-enabled-security-for-servers

A draft NIST Cybersecurity White Paper is available for comment: "Hardware-Enabled Security for Server Platforms." The public comment period is open through June 2, 2020.

Publications Other (Final)

Protecting Data from Ransomware and Other Data Loss Events: A Guide for Managed Service Providers to Conduct, Maintain, and Test Backup Files

April 24, 2020
https://csrc.nist.gov/pubs/other/2020/04/24/protecting-data-from-ransomware-and-other-data-los/final

Abstract: The National Cybersecurity Center of Excellence (NCCoE) at the National Institute of Standards and Technology (NIST) developed this publication to help managed service providers (MSPs) improve their cybersecurity and the cybersecurity of their customers. MSPs have become an attractive target for cyb...

Updates

Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF)

April 23, 2020
https://csrc.nist.gov/news/2020/mitigating-risk-of-software-vulns-ssdf

NIST has published "Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF)," a new NIST Cybersecurity White Paper.

Publications CSWP 13 (Final) (Withdrawn)

Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF)

April 23, 2020

https://csrc.nist.gov/pubs/cswp/13/mitigating-risk-of-software-vulnerabilities-ssdf/final

Abstract: Few software development life cycle (SDLC) models explicitly address software security in detail, so secure software development practices usually need to be added to each SDLC model to ensure the software being developed is well secured. This white paper recommends a core set of high-level secure s...

Publications Project Description (Final)

5G Cybersecurity: Preparing a Secure Evolution to 5G

April 13, 2020
https://csrc.nist.gov/pubs/pd/2020/04/13/5g-cybersecurity-preparing-a-secure-evolution-to-5/final

Abstract: Cellular networks will be transitioning from 4G to 5G, and 5G networks will provide increased cybersecurity protections. This project will identify several 5G use case scenarios and demonstrate for each one how to strengthen the 5G architecture components to mitigate identified risks and meet indust...

Updates

IoT Device Characterization: Draft NIST White Paper on "Methodology for Characterizing Network Behavior of Internet of Things Devices"

April 1, 2020
https://csrc.nist.gov/news/2020/draft-white-paper-on-iot-device-characterization

NIST has released a Draft NIST Cybersecurity White Paper on "Methodology for Characterizing Network Behavior of Internet of Things Devices." The public comment period ends May 1, 2020.

Publications Project Description (Final)

Critical Cybersecurity Hygiene: Patching the Enterprise

March 30, 2020
https://csrc.nist.gov/pubs/pd/2020/03/30/critical-cybersecurity-hygiene-patching-the-enterp/final

Abstract: Cyber hygiene describes recommended mitigations for the small number of root causes responsible for many cybersecurity incidents. Implementing a few simple practices can address these common root causes. Patching is a particularly important component of cyber hygiene, but existing tools and processe...

Publications Project Description (Final)

Validating the Integrity of Computing Devices: Supply Chain Assurance

March 26, 2020
https://csrc.nist.gov/pubs/pd/2020/03/26/validating-the-integrity-of-servers-and-client-dev/final

Abstract: Product integrity and the ability to distinguish trustworthy products is a critical foundation of cyber supply chain risk management (C-SCRM). Authoritative information regarding the provenance and integrity of the components provides a strong basis for trust in a computing device, whether it is a c...

Updates

Integrating Cybersecurity and Enterprise Risk Management (ERM): Draft NISTIR 8286 Available for Comment

March 19, 2020
https://csrc.nist.gov/news/2020/nist-releases-draft-nistir-8286-for-comment

NIST is requesting comments on Draft NISTIR 8286, "Integrating Cybersecurity and Enterprise Risk Management (ERM)." The public comment period closes April 20, 2020.

Updates

Telework Cybersecurity Resources: New ITL Bulletin and Blog Posts

March 19, 2020
https://csrc.nist.gov/news/2020/telework-cybersecurity-itl-bulletin-blog-posts

NIST has published a new ITL Bulletin (March 2020) that addresses enterprise security solutions for telework, remote access, and BYOD. Also, a new Telework Cybersecurity summary is available on the CSRC homepage and will be updated as new resources are added for organizations and teleworkers.

Updates

Approaches for Federal Agencies to Use the Cybersecurity Framework: NIST Publishes NISTIR 8170

March 19, 2020
https://csrc.nist.gov/news/2020/approach-federal-agencies-to-use-cyberframework

NISTIR 8170, "Approaches for Federal Agencies to Use the Cybersecurity Framework," provides guidance on how to use the NIST Cybersecurity Framework in federal agencies, in conjunction with the current and planned suite of NIST security and privacy risk management publications.

Publications IR 8170 (Final) (Withdrawn)

Approaches for Federal Agencies to Use the Cybersecurity Framework

March 19, 2020

https://csrc.nist.gov/pubs/ir/8170/final

Abstract: The document highlights examples for implementing the Framework for Improving Critical Infrastructure Cybersecurity (known as the Cybersecurity Framework) in a manner that complements the use of other NIST security and privacy risk management standards, guidelines, and practices. These examples incl...

Publications ITL Bulletin (Final)

Security for Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Solutions

March 18, 2020
https://csrc.nist.gov/pubs/itlb/2020/03/security-for-enterprise-telework-remote-access-and/final

Abstract: Today, many people are teleworking (also known as telecommuting), which is the ability of an organization's employees, contractors, business partners, vendors, and other users to perform work from locations other than the organization's facilities. Teleworkers use various client devices, such as des...

<< first   < previous   20     21     22     23     24     25     26     27     28     29     30     31     32     33     34     35     36     37     38     39     40     41     42     43     44  next >  last >>