Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 901 through 925 of 1324 matching records.
Updates

Privileged Account Management for the Financial Services Sector: Draft SP 1800-18 Now Available for Comment

September 28, 2018
https://csrc.nist.gov/news/2018/nccoe-releases-draft-sp-1800-18-for-comment

NIST is seeking comments on Draft SP 1800-18, a practice guide demonstrating Privileged Account Management (PAM) solutions that use commercially available products to appropriately secure and enforce organizational policies. Public comments are due by November 30, 2018.

Updates

Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks: Draft NIST Internal Report 8228

September 24, 2018
https://csrc.nist.gov/news/2018/nist-releases-draft-nistir-8228-for-comment

NIST seeks public comments on Draft NISTIR 8228, which is intended to help federal agencies and other organizations better understand and manage the cybersecurity and privacy risks associated with their IoT devices. Public comments are due October 24, 2018.

Updates

IT Asset Management: NIST Publishes Cybersecurity Practice Guide, Special Publication 1800-5

September 7, 2018
https://csrc.nist.gov/news/2018/nist-releases-special-publication-1800-5

SP 1800-5 provides an example IT asset management solution for financial services institutions, so they can securely track, manage, and report on information assets throughout their entire life cycle.

Updates

Draft Cybersecurity Practice Guide: Protecting the Integrity of Internet Routing

September 4, 2018
https://csrc.nist.gov/news/2018/nist-requests-comments-on-draft-sp-1800-14

NIST's National Cybersecurity Center of Excellence (NCCoE) is requesting comments on Draft Special Publication 1800-14, Protecting the Integrity of Internet Routing: Border Gateway Protocol (BGP) Route Origin Validation. Comments are due October 15, 2018.

Updates

NCCoE Releases Preliminary Draft of Trusted Cloud Security Practice Guide (Executive Summary)

August 24, 2018
https://csrc.nist.gov/news/2018/nccoe-prelim-draft-trusted-cloud-security-exec-sum

NIST has released a preliminary draft of NIST Special Publication 1800-19A, Trusted Cloud: Security Practice Guide for VMWare Hybrid Cloud Infrastructure as a Service (IaaS) Environments (Executive Summary).

Updates

Comments Requested - Draft of NIST SP1800-17, Multifactor Authentication for E-Commerce

August 23, 2018
https://csrc.nist.gov/news/2018/comments-requested-draft-of-nist-sp1800-17

According to a recent independent analysis, e-commerce fraud increased by 30 percent in 2017, compared to.....

Updates

Securing Wireless Infusion Pumps in Healthcare Delivery Organizations: NIST Releases Special Publication 1800-8

August 20, 2018
https://csrc.nist.gov/news/2018/nist-releases-special-publication-1800-8

Special Publication (SP) 1800-8 informs healthcare organizations on risks associated with deploying and operating wireless infusion pumps, and how to improve their cybersecurity. They are among the most network-connected medical devices.

Publications SP 1800-8 (Final)

Securing Wireless Infusion Pumps in Healthcare Delivery Organizations

August 17, 2018
https://csrc.nist.gov/pubs/sp/1800/8/final

Abstract: Medical devices, such as infusion pumps, were once standalone instruments that interacted only with the patient or medical provider. However, today’s medical devices connect to a variety of healthcare systems, networks, and other tools within a healthcare delivery organization (HDO). Connecting devi...

Publications SP 1800-1 (Final)

Securing Electronic Health Records on Mobile Devices

July 27, 2018
https://csrc.nist.gov/pubs/sp/1800/1/final

Abstract: Healthcare providers increasingly use mobile devices to receive, store, process, and transmit patient clinical information. According to our own risk analysis, discussed here, and in the experience of many healthcare providers, mobile devices can introduce vulnerabilities in a healthcare organizatio...

Updates

NIST to Withdraw Eleven Outdated SP 800 Publications

July 17, 2018
https://csrc.nist.gov/news/2018/nist-to-withdraw-eleven-outdated-sp-800-pubs

NIST’s Computer Security Division intends to withdraw eleven (11) SP 800 publications on August 1, 2018. They are out of date and will not be revised or superseded.

Updates

Identity and Access Management for Electric Utilities: NIST Releases Special Publication 1800-2

July 16, 2018
https://csrc.nist.gov/news/2018/nist-releases-special-publication-1800-2

The National Cybersecurity Center of Excellence (NCCoE) has released the final NIST Cybersecurity Practice Guide 1800-2, Identity and Access Management for Electric Utilities, and invites you to download the guide.

Publications SP 1800-2 (Final)

Identity and Access Management for Electric Utilities

July 13, 2018
https://csrc.nist.gov/pubs/sp/1800/2/final

Abstract: To protect power generation, transmission, and distribution, energy companies need to control physical and logical access to their resources, including buildings, equipment, information technology (IT), and operational technology (OT). They must authenticate authorized individuals to the devices and...

Publications SP 800-203 (Final)

2017 NIST/ITL Cybersecurity Program Annual Report

July 2, 2018
https://csrc.nist.gov/pubs/sp/800/203/final

Abstract: Title III of the E-Government Act of 2002, entitled the Federal Information Security Management Act (FISMA) of 2002, requires NIST to prepare an annual public report on activities undertaken in the previous year, and planned for the coming year, to carry out responsibilities under this law. The prim...

Events

SSAS Workshop

June 27, 2018 - June 28, 2018
https://csrc.nist.gov/events/2018/sound-static-analysis-for-security-(ssas)-workshop

This two-day workshop focuses on decreasing software security vulnerabilities by orders of magnitude, using the strong guarantees that only sound static analysis can provide. The workshop is aimed at developers, managers and evaluators of security-critical projects, as well as researchers in cybersecurity. The program features experts on sound static analysis applied to security, around three theme topics: Analysis of legacy code, Use in new development, and Accountable software quality. Each topic will be introduced by a renowned international expert: David A. Wheeler from the...

Publications SP 1500-4 Rev. 1 (Final) (Withdrawn)

NIST Big Data Interoperability Framework: Volume 4, Security and Privacy Version 2

June 26, 2018

https://csrc.nist.gov/pubs/sp/1500/4/r1/final

Abstract: Big Data is a term used to describe the large amount of data in the networked, digitized, sensor-laden, information-driven world. While opportunities exist with Big Data, the data can overwhelm traditional technical approaches and the growth of data is outpacing scientific and technological advances...

Publications Journal Article (Final)

Baseline Tailor

June 26, 2018
https://csrc.nist.gov/pubs/journal/2018/06/baseline-tailor/final

Journal: Journal of the National Institute of Standards and Technology Abstract: Baseline Tailor is an innovative web application for users of the National Institute of Standards and Technology (NIST) Cybersecurity Framework and Special Publication (SP) 800-53. Baseline Tailor makes the information in these widely referenced publications easily accessible to both security profes...

Publications SP 800-171 Rev. 1 (Final) (Withdrawn)

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

June 7, 2018

https://csrc.nist.gov/pubs/sp/800/171/r1/upd3/final

Abstract: [The errata update includes minor editorial changes to selected CUI security requirements, some additional references and definitions, and a new appendix that contains an expanded discussion about each CUI requirement.] The protection of Controlled Unclassified Information (CUI) resident in nonfede...

Publications Other (Final)

A Report to the President on Supporting the Growth and Sustainment of the Nation's Cybersecurity Workforce: Building the Foundation for a More Secure American Future

May 30, 2018
https://csrc.nist.gov/pubs/other/2018/05/30/supporting-growth-and-sustainment-of-the-cybersecu/final

Abstract: This report responds to the May 11, 2017, Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure. That order directs the Secretary of Commerce and the Secretary of Homeland Security to: 1) Assess the scope and sufficiency of efforts to educate and train th...

Publications Other (Final)

A Report to the President on Enhancing the Resilience of the Internet and Communications Ecosystem Against Botnets and Other Automated, Distributed Threats

May 30, 2018
https://csrc.nist.gov/pubs/other/2018/05/30/enhancing-resilience-against-botnets-report-to-the/final

Abstract: This report outlines a guide to government and private sector actions that would reduce the threat of botnets and similar cyberattacks. It responds to the May 11, 2017, Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure. That order directed the Secreta...

Updates

Draft Specification for Submitting Cybersecurity Framework Online Informative Reference Templates: Draft NISTIR 8204

May 17, 2018
https://csrc.nist.gov/news/2018/nist-releases-draft-nistir-8204

NIST is seeking public comments on Draft NISTIR 8204, Cybersecurity Framework Online Informative References (OLIR) Submissions: Specification for Completing the OLIR Template. The public comment period is open until July 16, 2018.

Updates

NIST Releases Draft Update of the Risk Management Framework, Special Publication 800-37 Revision 2

May 9, 2018
https://csrc.nist.gov/news/2018/nist-releases-draft-sp-800-37-rev-2

The initial public draft of SP 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations, is available for public comment until June 22, 2018.

<< first   < previous   25     26     27     28     29     30     31     32     33     34     35     36     37     38     39     40     41     42     43     44     45     46     47     48     49  next >  last >>