Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 126 through 150 of 1324 matching records.
Publications CSWP 34 (Initial Public Draft)

Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration: Healthcare and Public Health Sector Risk Management Approaches

November 6, 2024
https://csrc.nist.gov/pubs/cswp/34/mitigating-cybersecurity-and-privacy-risks-in-tele/ipd

Abstract: In-patient service demands have increased during a time when patients have experienced reduced access to hospital care. Hospital-at-Home (HaH) solutions provide an in-patient care experience for patients, which may result in reduced costs and improved outcomes. While these are desirable benefits, Ha...

Publications CSWP 36C (Initial Public Draft)

Reallocation of Temporary Identities: Applying 5G Cybersecurity and Privacy Capabilities

November 6, 2024
https://csrc.nist.gov/pubs/cswp/36/c/reallocation-of-temporary-identities-applying-5g-c/ipd

Abstract: This white paper is part of a series called Applying 5G Cybersecurity and Privacy Capabilities, which covers 5G cybersecurity- and privacy-supporting capabilities that were implemented as part of the 5G Cybersecurity project at the National Cybersecurity Center of Excellence (NCCoE). This white pape...

Updates

NEW | NIST Releases Errata Update for Cybersecurity Supply Chain Risk Management Guidance

November 1, 2024
https://csrc.nist.gov/news/2024/new-nist-errata-update-c-scrm

NIST has released an errata update to its foundational publication on managing cybersecurity risks in supply chains.

Publications SP 800-161 Rev. 1 (Final)

Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

November 1, 2024
https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final

Abstract: Organizations are concerned about the risks associated with products and services that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the supply chain. These risks are associated with an enterprise’s decr...

Updates

Automation of the NIST Cryptographic Module Validation Program: September 2024 Status Report

October 31, 2024
https://csrc.nist.gov/news/2024/automation-of-the-nist-cmvp-status-report

A draft of NIST Cybersecurity White Paper (CSWP) 37, "Automation of the NIST Cryptographic Module Validation Program: September 2024 Status Report," is now available for public comment through December 4, 2024.

Publications CSWP 37 (Initial Public Draft)

Automation of the NIST Cryptographic Module Validation Program: September 2024 Status Report

October 31, 2024
https://csrc.nist.gov/pubs/cswp/37/automation-of-the-nist-cryptographic-module-valida/ipd

Abstract: The Cryptographic Module Validation Program (CMVP) validates third-party assertions that cryptographic module implementations satisfy the requirements of Federal Information Processing Standards (FIPS) Publication 140-3, Security Requirements for Cryptographic Modules. The NIST National Cybersecurit...

Updates

NIST Releases the C-SCRM Due Diligence Assessment Quick-Start Guide for Public Comment

October 30, 2024
https://csrc.nist.gov/news/2024/nist-releases-sp-1326-for-public-comment

The Initial Public Draft for SP 1326, NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide; is available for public comment. The public comment period is open through December 16, 2024.

Publications SP 1326 (Initial Public Draft)

NIST Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide

October 30, 2024
https://csrc.nist.gov/pubs/sp/1326/ipd

Abstract: Due diligence research is the minimum amount of understanding that an acquirer should have on a supplier and should be done with most of the acquiring organization’s suppliers, regardless of criticality. This Quick-Start Guide provides cybersecurity supply chain risk management (C-SCRM) program capa...

Project Pages

Key Management Guidelines

https://csrc.nist.gov/projects/key-management/key-management-guidelines

The following publications provide general key management guidance: Recommendation for Key Management SP 800-57 Part 1 Revision 5 - General This Recommendation provides cryptographic key-management guidance. It consists of three parts. Part 1 provides general guidance and best practices for the management of cryptographic keying material, including definitions of the security services that may be provided when using cryptography and the algorithms and key types that may be employed, specifications of the protection that each type of key and other cryptographic information requires and...

Publications SP 1305 (Final)

NIST Cybersecurity Framework 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management (C-SCRM)

October 21, 2024
https://csrc.nist.gov/pubs/sp/1305/final

Abstract: Use the CSF to Improve Your C-SCRM Processes. The CSF can help an organization become a smart acquirer and supplier of technology products and services. This guide focuses on two ways the CSF can help you: 1) Use the CSF’s GV.SC Category to establish and operate a C-SCRM capability. 2) Define and co...

Publications SP 1302 (Final)

NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using the CSF Tiers

October 21, 2024
https://csrc.nist.gov/pubs/sp/1302/final

Abstract: This Quick-Start Guide describes how to apply the CSF 2.0 Tiers. CSF Tiers can be applied to CSF Organizational Profiles to characterize the rigor of an organization’s cybersecurity risk governance and management outcomes. This can help provide context on how an organization views cybersecurity risk...

Publications SP 1303 (Final)

NIST Cybersecurity Framework 2.0: Enterprise Risk Management Quick-Start Guide

October 21, 2024
https://csrc.nist.gov/pubs/sp/1303/final

Abstract: This guide provides an introduction to using the NIST Cybersecurity Framework (CSF) 2.0 for planning and integrating an enterprise-wide process for integrating cybersecurity risk management information, as a subset of information and communications technology risk management, into enterprise risk ma...

Updates

NIST Cybersecurity White Paper (CSWP) 36B Using Hardware-Enabled Security to Ensure 5G System Platform Integrity - Applying 5G Cybersecurity and Privacy Capabilities White Paper Series Available for Comment

September 30, 2024
https://csrc.nist.gov/news/2024/cswp-36b-is-available-for-public-comment

NIST Cybersecurity White Paper (CSWP) 36B Using Hardware-Enabled Security to Ensure 5G System Platform Integrity - Applying 5G Cybersecurity and Privacy Capabilities White Paper Series is available for public comment. The deadline to submit comments to this draft document is October 30, 2024.

Publications CSWP 36B (Initial Public Draft)

Using Hardware-Enabled Security to Ensure 5G System Platform Integrity: Applying 5G Cybersecurity and Privacy Capabilities

September 30, 2024
https://csrc.nist.gov/pubs/cswp/36/b/using-hardware-enabled-security-to-ensure-5g-syste/ipd

Abstract: This white paper provides an overview of employing hardware-enabled1 security capabilities to provision, measure, attest to, and enforce the integrity of the compute platform to foster trust in a 5G system’s server infrastructure. This white paper is part of a series called Applying 5G Cybersecurity...

Updates

NIST Releases CSWP 31, Proxy Validation and Verification for Critical AI Systems: A Proxy Design Process

September 26, 2024
https://csrc.nist.gov/news/2024/nist-releases-cswp-31

NIST Cybersecurity White Paper (CSWP) 31, Proxy Validation and Verification for Critical AI Systems: A Proxy Design Process has been published.

Project Pages

RMF Online Introductory Courses

https://csrc.nist.gov/projects/risk-management/rmf-courses

The purpose of these courses is to provide those new to risk management with an introduction to key publications associated with the NIST Risk Management Framework (RMF) methodology for managing cybersecurity and privacy risk. The RMF Online Introductory Courses are developed by NIST and available on-demand, and free of charge. Please refer first to the FAQ below for questions about course logistics, topics and content, initial troubleshooting of issues, and certificate of completion and course credit before reaching out to the team with questions. Select a course below to learn...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>