Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 101 through 125 of 1413 matching records.
Publications SP 1800-43 (Initial Public Draft)

Genomic Data Threat Modeling

August 5, 2025
https://csrc.nist.gov/pubs/sp/1800/43/ipd

Abstract: This paper provides an example of how to conduct genomic data threat modeling for privacy on a data processing environment, including documenting the architecture, identifying threats, applying sample interventions, and iterating the process as needed. The paper complements the earlier NIST CSWP 35,...

Updates

Development of an Internal-Use NCCoE Chatbot | Comment on Draft NIST IR 8579

July 31, 2025
https://csrc.nist.gov/news/2025/draft-nist-ir-8579-nccoe-chatbot

The National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of Internal Report (IR) 8579. The comment period for this NIST IR closes on September 11, 2025.

Updates

Second Public Draft | Supply Chain Traceability: Manufacturing Meta-Framework

July 31, 2025
https://csrc.nist.gov/news/2025/nist-ir-8536-second-public-draft

NIST's NCCoE has posted the second public draft of NIST IR 8536, "Supply Chain Traceability: Manufacturing Meta-Framework," for public comment. The comment period is open through October 3, 2025.

Publications IR 8579 (Initial Public Draft)

Developing the NCCoE Chatbot: Technical and Security Learnings from the Initial Implementation

July 31, 2025
https://csrc.nist.gov/pubs/ir/8579/ipd

Abstract: Chatbots are emerging as alternative interfaces for structured information retrieval and internal knowledge access. Chatbots can utilize the capabilities of large language models (LLMs) to help interpret user-provided input and provide responses to a variety of requests. This paper describes the dev...

Publications SP 800-63-4 (Final)

Digital Identity Guidelines

July 31, 2025
https://csrc.nist.gov/pubs/sp/800/63/4/final

Abstract: These guidelines cover the identity proofing, authentication, and federation of users (e.g., employees, contractors, or private individuals) who interact with government information systems over networks. They define technical requirements in each of the areas of identity proofing, enrollment, authe...

Publications IR 8536 (2nd Public Draft)

Supply Chain Traceability: Manufacturing Meta-Framework

July 31, 2025
https://csrc.nist.gov/pubs/ir/8536/2pd

Abstract: Manufacturing and critical infrastructure supply chains are vital to the security, resilience, and economic strength of the United States. However, increasing global complexity makes tracing product origins more difficult, exposing vulnerabilities to logistical disruptions, fraud, sabotage, and coun...

Updates

Secure Software Development, Security, and Operations (DevSecOps) Practices | Draft SP 1800-44A

July 30, 2025
https://csrc.nist.gov/news/2025/draft-sp-1800-44a-available-for-comment

Volume A of NIST Special Publication 1800-44, "Secure Software Development, Security, and Operations (DevSecOps) Practices," is available for comment through September 14, 2025.

Publications SP 1800-44 (Initial Public Draft)

Secure Software Development, Security, and Operations (DevSecOps) Practices

July 30, 2025
https://csrc.nist.gov/pubs/sp/1800/44/ipd

Abstract: Development Operations (DevOps) bring together software development and operations to shorten development cycles, allow organizations to be agile and maintain the pace of innovation while taking advantage of cloud-native technology and practices and the increasing industry use of rapidly evolving ar...

Updates

Draft SP 800-53 Controls on Secure and Reliable Patches Available for Comment

July 22, 2025
https://csrc.nist.gov/news/2025/sp-800-53-draft-controls-available-for-comment

NIST's draft updates to SP 800-53 providing additional guidance on how to securely and reliably deploy patches and updates in response to Executive Order 14306

Topics

Executive Order 14306

https://csrc.nist.gov/topics/laws-and-regulations/executive-documents/executive-order-14306

Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144 (June 6, 2025)

Updates

Considerations for Achieving Crypto Agility | Second Public Draft Available for Comment

July 18, 2025
https://csrc.nist.gov/news/2025/considerations-for-achieving-crypto-agility-2nd-dr

The second public draft of NIST Cybersecurity White Paper (CSWP) 39, Considerations for Achieving Crypto Agility: Strategies and Practices is available for comment. The public comment period for this second draft is open through August 15, 2025.

Updates

Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments | Comment on NIST SP 1334

July 15, 2025
https://csrc.nist.gov/news/2025/cyber-risks-of-portable-storage-media-in-ot-enviro

The NCCoE seeks public comments on the initial public draft of SP 1334, "Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments." Comments are due August 14, 2025.

Projects

Combinatorial Testing for AI-Enabled Systems

https://csrc.nist.gov/projects/combinatorial-testing-for-ai-enabled-systems

*NEW* Short course from the Defense and Aerospace Test and Analysis Workshop 2025 (Dataworks 2025) - complete course presentation here. The goal of this project is to provide practitioners and researchers with a foundational understanding of combinatorial testing techniques and applications to testing AI-enabled software systems (AIES). Resources are being developed in these areas: Combinatorial testing (CT), applying CT to test traditional software systems, including real-world examples and case studies. How Test and Evaluation (T&E) of AIES differ from traditional software systems...

Topics

smart grid

https://csrc.nist.gov/topics/applications/smart-grid

NIST's cybersecurity resources have supported NIST's smart grid development efforts, which resulted from the Energy Independence and Security Act of 2007 (EISA). RT=EISA

Updates

Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46

June 30, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-46

This document, Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46; has been approved as final.

Updates

Network Security Design Principles | Applying 5G Cybersecurity and Privacy Capabilities

June 17, 2025
https://csrc.nist.gov/news/2025/5g-network-security-design-principles-cswp-36e

NCCoE released the sixth white paper in the series, 5G Network Security Design Principles, which provides the network infrastructure security design principles that commercial and private 5G network operators are encouraged to use.

Updates

End-of-Life Announcement: NIST SCAP Validation Program

June 17, 2025
https://csrc.nist.gov/news/2025/end-of-life-announcement-nist-scapval

The National Institute of Standards and Technology (NIST) announces the phased conclusion of the Security Content Automation Protocol (SCAP) Validation Program.

Publications CSWP 36E (Initial Public Draft)

5G Network Security Design Principles: Applying 5G Cybersecurity and Privacy Capabilities

June 17, 2025
https://csrc.nist.gov/pubs/cswp/36/e/5g-network-security-design-principles/ipd

Abstract: This white paper describes the network infrastructure design principles that commercial and private 5G network operators are encouraged to use to improve cybersecurity and privacy. Such a network infrastructure isolates types of 5G network traffic from each other: data plane, signaling, and operatio...

Updates

Implementing a Zero Trust Architecture: NIST Publishes SP 1800-35

June 10, 2025
https://csrc.nist.gov/news/2025/implementing-a-zero-trust-architecture-sp-1800-35

NIST Special Publication 1800-35, "Implementing a Zero Trust Architecture," provides results and best practices from NCCoE's work with 24 vendors to demonstrate end-to-end zero trust architecture.

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>