Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 76 through 100 of 1339 matching records.
Project Pages

Industrial Case Studies - Combinatorial and Pairwise Testing

https://csrc.nist.gov/projects/automated-combinatorial-testing-for-software/combinatorial-methods-in-testing/case-studies-and-examples

Combinatorial testing is being applied successfully in nearly every industry, and is especially valuable for assurance of high-risk software with safety or security concerns. Combinatorial testing is referred to as effectively exhaustive, or pseudo-exhaustive, because it can be as effective as fully exhaustive testing, while reducing test set size by 20X to more than 100X. Case studies below are from many types of applications, including aerospace, automotive, autonomous systems, cybersecurity, financial systems, video games, industrial controls, telecommunications, web applications, and...

Publications IR 8523 (Initial Public Draft)

Multi-Factor Authentication for Criminal Justice Information Systems: Implementation Considerations for Protecting Criminal Justice Information

March 13, 2025
https://csrc.nist.gov/pubs/ir/8523/ipd

Abstract: Most recent cybersecurity breaches have involved compromised credentials. Migrating from single-factor to multi-factor authentication (MFA) reduces the risk of compromised credentials and unauthorized access. Both criminal and noncriminal justice agencies need to access criminal justice information...

Updates

Draft CSF 2.0 Quick Start Guide: Cybersecurity, Enterprise Risk Management, and Workforce Management

March 12, 2025
https://csrc.nist.gov/news/2025/csf-20-cyber-erm-and-workforce-managment-qsg

The latest Quick Start Guide for the NIST Cybersecurity Framework 2.0 is available for public comment through April 25, 2025.

Publications SP 1308 (Initial Public Draft)

NIST Cybersecurity Framework 2.0: Cybersecurity, Enterprise Risk Management, and Workforce Management Quick Start Guide

March 12, 2025
https://csrc.nist.gov/pubs/sp/1308/ipd

Abstract: This Quick Start Guide (QSG) shows how the NICE Workforce Framework for Cybersecurity and the Cybersecurity Framework (CSF) can be used together to facilitate communication across business units and improve organizational processes where cybersecurity, enterprise risk management (ERM), and workforce...

Projects

Hardware Security

https://csrc.nist.gov/projects/hardware-security

Proposed Activities | Previous and Current Activities | Contact Us Semiconductor-based hardware is the foundation of modern-day electronics. Electronics are ubiquitous in our daily lives: from smartphones, computers, and telecommunication to transportation and critical infrastructure like power grids and waterways. The semiconductor hardware supply chain is a complex network consisting of many companies that collectively provide intellectual property, create designs, provide raw materials, and manufacture, test, package, and distribute products. Coordination among these companies is...

Project Pages

About

https://csrc.nist.gov/projects/human-centered-cybersecurity/about

Our Goal The Human-Centered Cybersecurity program within the NIST Visualization and Usability Group provides research evidence and guidance to policymakers, system engineers, organizational decision makers, and cybersecurity professionals so that they can make better decisions that consider the human element, thereby advancing cybersecurity adoption and empowering people to be active, informed partners in cybersecurity. Ideally, this guidance should: Have a basis in real empirical data Create solutions that are secure in practice, not just in theory Take stakeholders' needs and behaviors...

Updates

Considerations for Achieving Crypto Agility: NIST Releases CSWP 39 for Public Comment

March 5, 2025
https://csrc.nist.gov/news/2025/nist-releases-cswp-39-for-public-comment

NIST Cybersecurity White Paper (CSWP), Considerations for Achieving Crypto Agility, provides an in-depth survey of current approaches and considerations to achieving crypto agility.

Publications CSWP 39 (Initial Public Draft)

Considerations for Achieving Cryptographic Agility: Strategies and Practices

March 5, 2025
https://csrc.nist.gov/pubs/cswp/39/considerations-for-achieving-cryptographic-agility/ipd

Abstract: Crypto agility refers to the capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, and infrastructures. This white paper provides an in-depth survey of current approaches to achieving crypto agility. It discusses challenges and tradeoffs an...

Projects

Secure Software Development Framework

https://csrc.nist.gov/projects/ssdf

NIST has finalized SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile. This publication augments SP 800-218 by adding practices, tasks, recommendations, considerations, notes, and informative references that are specific to AI model development throughout the software development life cycle. NIST has recently added a Community Profiles section to this page. It will contain links to SSDF Community Profiles developed by NIST and by third parties. Contact us at [email protected] if you have a published SSDF Community...

Updates

Now Open for Public Comment | NIST Cybersecurity Framework 2.0 Profile for Semiconductor Manufacturing

February 27, 2025
https://csrc.nist.gov/news/2025/draft-csf-profile-for-semiconductor-manufacturing

The NIST National Cybersecurity Center of Excellence (NCCoE) along with the SEMI Semiconductor Manufacturing Cybersecurity Consortium has released Draft NIST Internal Report (IR) 8546, Cybersecurity Framework (CSF) 2.0 Semiconductor Manufacturing Community Profile for public comment until 11:59 PM ET on July 30, 2025.

Publications IR 8546 (Initial Public Draft)

Cybersecurity Framework Version 2.0 Semiconductor Manufacturing Profile

February 27, 2025
https://csrc.nist.gov/pubs/ir/8546/ipd

Abstract: This document defines a Cybersecurity Framework (CSF) 2.0 Community Profile with a voluntary, risk-based approach to managing cybersecurity activities and reducing cyber risks for semiconductor development and manufacturing. Collaboratively developed in support of the National Cybersecurity Implemen...

Updates

Integrating Cybersecurity and Enterprise Risk Management | NIST IR 8286 Series Revisions and Updates

February 26, 2025
https://csrc.nist.gov/news/2025/cybersecurity-and-erm-nist-ir-8286-series-revision

NIST has released revisions or updates to all five publications in its Interagency Report (IR) 8286 series. The public comment period is open through April 14, 2025, for the initial public drafts of IR 8286r1, IR 8286Ar1, and IR 8286Cr1.

Project Pages

About the Forum

https://csrc.nist.gov/projects/forum/about-the-forum

The NIST Cybersecurity & Privacy Professionals Forum is co-chaired by representatives of NIST's Information Technology Laboratory, Computer Security Division (CSD) and Applied Cybersecurity Division (ACD). The Forum Secretariat provides the necessary administrative and logistical support for operations. The Forum serves as an important mechanism for NIST to: exchange information directly with cybersecurity and privacy professionals in U.S. federal, state, and local government, and higher education organizations in fulfillment of its leadership mandate under the Federal Information...

Projects

Federal Cybersecurity and Privacy Professionals Forum

https://csrc.nist.gov/projects/forum

The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of cybersecurity and privacy knowledge, best practices, and resources among U.S. federal, state, and local government, and higher education organizations. The Federal Cybersecurity and Privacy Professionals Forum ("the Forum") maintains an extensive email list, and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. There is no cost...

Publications IR 8286 Rev. 1 (Initial Public Draft)

Integrating Cybersecurity and Enterprise Risk Management (ERM)

February 26, 2025
https://csrc.nist.gov/pubs/ir/8286/r1/ipd

Abstract: The increasing frequency, creativity, and severity of cybersecurity attacks means that all enterprises should ensure that cybersecurity risk is receiving appropriate attention within their enterprise risk management (ERM) programs. This document is intended to help individual organizations within an...

Publications IR 8286A Rev. 1 (Initial Public Draft)

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

February 26, 2025
https://csrc.nist.gov/pubs/ir/8286/a/r1/ipd

Abstract: This document supplements NIST Interagency Report 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM), by providing additional detail regarding risk guidance, identification, and analysis. This report offers examples and information to illustrate risk tolerance, risk appetite, and m...

Publications IR 8286B (Final)

Prioritizing Cybersecurity Risk for Enterprise Risk Management

February 26, 2025
https://csrc.nist.gov/pubs/ir/8286/b/upd1/final

Abstract: This document is the second in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional detail regarding the enterprise application of cybersecurity risk information; the previous document, NIST IR 82...

Publications IR 8286C Rev. 1 (Initial Public Draft)

Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight

February 26, 2025
https://csrc.nist.gov/pubs/ir/8286/c/r1/ipd

Abstract: This document is the third in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional details regarding enterprise application of cybersecurity risk information; the previous documents, IRs 8286A and...

Publications IR 8286D (Final)

Using Business Impact Analysis to Inform Risk Prioritization and Response

February 26, 2025
https://csrc.nist.gov/pubs/ir/8286/d/upd1/final

Abstract: While business impact analysis (BIA) has historically been used to determine availability requirements for business continuity, the process can be extended to provide a broad understanding of the potential impacts of any type of loss on the enterprise mission. The management of enterprise risk requi...

Project Pages

PIV Announcements

https://csrc.nist.gov/projects/piv/announcements

Posted July 15, 2024 NIST Releases SP 800-73-5 and SP 800-78-5 including comment dispositions for SP 800-73-5 and SP 800-78-5. Posted September 27, 2023 Personal Identity Verification (PIV) Interfaces, Cryptographic Algorithms, and Key Sizes: Drafts of SP 800-73-5 and SP 800-78-5 Available for Public Comment In January 2022, NIST revised Federal Information Processing Standard (FIPS) 201, which establishes standards for the use of Personal Identity Verification (PIV) Credentials – including the credentials on PIV Cards. NIST Special Publication (SP) 800-73-5: Parts 1–3 and SP 800-78-5...

Events

FORUM Meeting - February 25, 2025

February 25, 2025 - February 25, 2025
https://csrc.nist.gov/events/2025/forum-meeting-february-25-2025

The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of system security and privacy information among federal, state, and local government, and higher education employees. The Forum maintains an extensive e-mail list and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. For more information about the Forum and instructions on how to join, see: https://csrc.nist.gov/Projects/forum....

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>