Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 101 through 125 of 1318 matching records.
Updates

Requesting Public Comment | NIST Guidance on Implementing a Zero Trust Architecture (ZTA)

December 5, 2024
https://csrc.nist.gov/news/2024/nist-guidance-on-implementing-a-zta

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the draft of the practice guide, Implementing a Zero Trust Architecture (NIST SP 1800-35), for public comment. The public comment period is open through January 31, 2025.

Project Pages

Standards/Guidelines

https://csrc.nist.gov/projects/measurements-for-information-security/standards-guidelines

These are standard publications and guidelines that provide perspectives and frameworks to inform, measure, and manage cybersecurity vulnerabilities and exposures. NIST SP 800-55 Vol. 1 Measurement Guide for Information Security: Volume 1 — Identifying and Selecting Measures Volume 1, Identifying and Selecting Measures, provides a flexible approach to the development, selection, and prioritization of information security measures. This volume explores both quantitative and qualitative assessment and provides basic guidance on data analysis techniques as well as impact and likelihood...

Project Pages

Tools

https://csrc.nist.gov/projects/measurements-for-information-security/tools

These are tools and utilities to assess the level of security risks and provide a mechanism to enhance automation for the cybersecurity information exchange. Baldrige Cybersecurity Excellence Builder (BCEB) A self-assessment tool to help organizations better understand the effectiveness of their cybersecurity risk management efforts and identity improvement opportunities in the context of their overall organizational performance. Common Vulnerability Scoring System (CVSS) An open framework for communicating the characteristics and severity of software vulnerabilities. CVSS is well...

Project Pages

Reference Sources

https://csrc.nist.gov/projects/measurements-for-information-security/reference-sources

These are reference sources for frameworks, algorithms validation, software assurance, testing, and other measurements related to information security. Automated Combinatorial Testing for Software Combinatorial or t-way testing is a proven method for more effective software testing at lower cost. The research toolkit can make sure that there are no simultaneous input combinations that might inadvertently cause a dangerous error. Cryptographic Algorithm Validation Program (CAVP) The NIST Cryptographic Algorithm Validation Program provides validation testing of Approved (i.e.,...

Publications SP 1800-35 (Initial Public Draft)

Implementing a Zero Trust Architecture

December 4, 2024
https://csrc.nist.gov/pubs/sp/1800/35/ipd

Abstract: A zero trust architecture (ZTA) enables secure authorized access to enterprise resources that are distributed across on-premises and multiple cloud environments, while enabling a hybrid workforce and partners to access resources from anywhere, at any time, from any device in support of the organizat...

Project Pages

External References

https://csrc.nist.gov/projects/cyber-supply-chain-risk-management/references

***Disclaimer: Items in the following lists are provided for research purposes, and do not imply endorsement by NIST.*** U.S. Government Activities / Initiatives Related Standards / Best Practices C-SCRM Research / References Involved Standards Organizations / Associations U.S. Government Activities / Initiatives Committee on National Security Systems Directive (CNSSD) 505 - "...provides the guidance for organizations that own, operate, or maintain [National Security Systems (NSS)] to address supply chain risk and implement and sustain SCRM capabilities". Comprehensive National...

Updates

NIST Report on the 2024 Accordion Cipher Mode Workshop

November 21, 2024
https://csrc.nist.gov/news/2024/report-on-2024-accordion-cipher-mode-workshop

NIST releases NIST IR 8537, NIST Workshop on the Requirements for an Accordion Cipher Mode 2024: Workshop Report.

Publications CSWP 38 (Initial Public Draft)

NIST Privacy Workforce Taxonomy

November 21, 2024
https://csrc.nist.gov/pubs/cswp/38/nist-privacy-workforce-taxonomy/ipd

Abstract: This document provides a taxonomy of Task, Knowledge, and Skill (TKS) Statements aligned with the NIST Privacy Framework, Version 1.0 and the NICE Workforce Framework for Cybersecurity model of TKS Statement building blocks. It contains a mapping of the Taxonomy’s TKS Statements to the NIST Privacy...

Publications IR 8537 (Final)

NIST Workshop on the Requirements for an Accordion Cipher Mode 2024: Workshop Report

November 21, 2024
https://csrc.nist.gov/pubs/ir/8537/final

Abstract: NIST hosted the NIST Workshop on the Requirements for an Accordion Cipher Mode 2024 on June 20--21, 2024, at the National Cybersecurity Center of Excellence in Rockville, Maryland. This report summarizes the participant feedback, key takeaways, and future directions discussed during the event.

Events

Forum Meeting - November 19, 2024

November 19, 2024 - November 19, 2024
https://csrc.nist.gov/events/2024/forum-meeting-november-19-2024

The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of system security and privacy information among federal, state, and local government, and higher education employees. The Forum maintains an extensive e-mail list and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. For more information about the Forum and instructions on how to join, see: https://csrc.nist.gov/Projects/forum....

Updates

Comment Now! NIST Cybersecurity White Paper: Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration

November 7, 2024
https://csrc.nist.gov/news/2024/cswp-34-is-available-for-public-comment

The NCCoE has released for public comment the draft of NIST Cybersecurity White Paper (CSWP) 34, Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration. The comment period for the draft is now open through January 21, 2025.

Updates

NCCoE Released NIST CSWP 36C, Reallocation of Temporary Identities - Applying 5G Cybersecurity and Privacy Capabilities White Paper Series for Public Comment

November 7, 2024
https://csrc.nist.gov/news/2024/cswp-36c-is-available-for-public-comment

Draft CSWP 36C, Reallocation of Temporary Identities - Applying 5G Cybersecurity & Privacy Capabilities White Paper Series for Public Comment. The public comment period is open through December 6, 2024.

Publications CSWP 34 (Initial Public Draft)

Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration: Healthcare and Public Health Sector Risk Management Approaches

November 6, 2024
https://csrc.nist.gov/pubs/cswp/34/mitigating-cybersecurity-and-privacy-risks-in-tele/ipd

Abstract: In-patient service demands have increased during a time when patients have experienced reduced access to hospital care. Hospital-at-Home (HaH) solutions provide an in-patient care experience for patients, which may result in reduced costs and improved outcomes. While these are desirable benefits, Ha...

Publications CSWP 36C (Initial Public Draft)

Reallocation of Temporary Identities: Applying 5G Cybersecurity and Privacy Capabilities

November 6, 2024
https://csrc.nist.gov/pubs/cswp/36/c/reallocation-of-temporary-identities-applying-5g-c/ipd

Abstract: This white paper is part of a series called Applying 5G Cybersecurity and Privacy Capabilities, which covers 5G cybersecurity- and privacy-supporting capabilities that were implemented as part of the 5G Cybersecurity project at the National Cybersecurity Center of Excellence (NCCoE). This white pape...

Updates

NEW | NIST Releases Errata Update for Cybersecurity Supply Chain Risk Management Guidance

November 1, 2024
https://csrc.nist.gov/news/2024/new-nist-errata-update-c-scrm

NIST has released an errata update to its foundational publication on managing cybersecurity risks in supply chains.

Publications SP 800-161 Rev. 1 (Final)

Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

November 1, 2024
https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final

Abstract: Organizations are concerned about the risks associated with products and services that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the supply chain. These risks are associated with an enterprise’s decr...

Updates

Automation of the NIST Cryptographic Module Validation Program: September 2024 Status Report

October 31, 2024
https://csrc.nist.gov/news/2024/automation-of-the-nist-cmvp-status-report

A draft of NIST Cybersecurity White Paper (CSWP) 37, "Automation of the NIST Cryptographic Module Validation Program: September 2024 Status Report," is now available for public comment through December 4, 2024.

Publications CSWP 37 (Initial Public Draft)

Automation of the NIST Cryptographic Module Validation Program: September 2024 Status Report

October 31, 2024
https://csrc.nist.gov/pubs/cswp/37/automation-of-the-nist-cryptographic-module-valida/ipd

Abstract: The Cryptographic Module Validation Program (CMVP) validates third-party assertions that cryptographic module implementations satisfy the requirements of Federal Information Processing Standards (FIPS) Publication 140-3, Security Requirements for Cryptographic Modules. The NIST National Cybersecurit...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>