Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 126 through 150 of 1450 matching records.
Project Pages

PIV Standards and Supporting Documentation

https://csrc.nist.gov/projects/piv/piv-standards-and-supporting-documentation

Each title heading is clickable - clicking each title will expand/collapse the list of standards & supporting documents. PIV Standards: FIPS 201-3 - Personal Identity Verification (PIV) of Federal Employees and Contractors (January 2022) Federal Register Notice 2020 Draft comments and dispositions FIPS 201-2 has been withdrawn and is superseded by FIPS 201-3 PIV Card Specifications: SP 800-78-5 - Cryptographic Algorithms and Key Sizes for Personal Identity Verification (July 2024) SP 800-76-2 - Biometric Data Specification for Personal Identity...

Project Pages

2010-2019 PIV News Archives

https://csrc.nist.gov/projects/piv/announcements/piv-news-archives

2019-2018 PIV News Archive March 21, 2019: Presentations of the FIPS 201-3 Business Requirements Meeting are available here. February 8, 2019: Safe the date for the Federal Business Requirements Meeting for FIPS 201 Revision 3 on 3/19/19. FIPS 201, Personal Identity Verification (PIV) for Federal Employees and Contractors, will be going through a third revision soon. In preparation for the revision, NIST invites federal departments and agencies’ representatives to participate in this government-only meeting to discuss the change requests accumulated over the past five years....

Updates

Protecting Tokens and Assertions from Forgery, Theft, and Misuse | NIST IR 8587 is available for public comment

December 22, 2025
https://csrc.nist.gov/news/2025/comment-on-nist-ir-8587-initial-public-draft

The initial public draft of NIST IR 8587, "Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers," is now available for public comment through January 30, 2026.

Publications IR 8587 (Initial Public Draft)

Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

December 22, 2025
https://csrc.nist.gov/pubs/ir/8587/ipd

Abstract: This report provides implementation guidance to help federal agencies and cloud service providers (CSPs) protect identity tokens and assertions from forgery, theft, and misuse. Building on updates to NIST SP 800-53 (Release 5.1.1), it outlines principles for CSPs and consuming agencies, details arch...

Updates

NIST Publishes CSWP 39: Considerations for Achieving Crypto Agility

December 19, 2025
https://csrc.nist.gov/news/2025/considerations-for-achieving-crypto-agility

The final version of Cybersecurity White Paper (CSWP) 39, Considerations for Achieving Crypto Agility: Strategies and Practices, has been published on December 19, 2025.

Updates

NIST Revises Publications on Integrating Cybersecurity and Enterprise Risk Management

December 18, 2025
https://csrc.nist.gov/news/2025/nist-revises-ir-8286-suite-of-reports

NIST revises three publications on Integrating Cybersecurity and Enterprise Risk Management: NIST IR 8286r1, 8286Ar1, and 8286Cr1.

Publications IR 8286C Rev. 1 (Final)

Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight

December 18, 2025
https://csrc.nist.gov/pubs/ir/8286/c/r1/final

Abstract: This document is the third in a series that supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM). This series provides additional details regarding enterprise application of cybersecurity risk information; the previous documents, IRs 8286A and...

Publications IR 8286 Rev. 1 (Final)

Integrating Cybersecurity and Enterprise Risk Management (ERM)

December 18, 2025
https://csrc.nist.gov/pubs/ir/8286/r1/final

Abstract: The increasing frequency, creativity, and severity of cybersecurity attacks means that all enterprises should ensure that cybersecurity risk is receiving appropriate attention within their enterprise risk management (ERM) programs. This document is intended to help individual organizations within an...

Publications IR 8286A Rev. 1 (Final)

Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

December 18, 2025
https://csrc.nist.gov/pubs/ir/8286/a/r1/final

Abstract: This document supplements NIST Interagency Report (IR) 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM), by providing additional detail regarding risk guidance, identification, and analysis. This report offers examples and information to illustrate risk tolerance, risk appetite,...

Updates

Now Available! NIST Cybersecurity White Paper: Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration

December 17, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-cswp-34

The National Cybersecurity Center of Excellence (NCCoE) has published the final version of NIST Cybersecurity White Paper (CSWP) 34, Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration.

Publications CSWP 34 (Final)

Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration

December 17, 2025
https://csrc.nist.gov/pubs/cswp/34/mitigating-cybersecurity-and-privacy-risks-in-tele/final

Abstract: In-patient service demands have increased during a time when patients have experienced reduced access to hospital care. Hospital-at-Home (HaH) solutions are a form of telehealth that provide an in-patient care experience in patients’ homes, offering the potential for improved outcomes. While t...

Updates

Check out NIST’s Cyber AI Profile Preliminary Draft and Save the Date for our Cyber AI Workshop #2 in January

December 16, 2025
https://csrc.nist.gov/news/2025/nist-releases-prelim-draft-cyber-ai-profile

The Cyber AI Profile (NIST Community Profile) is available for comment through January 30th. Also, save the date for NCCoE's hybrid workshop on January 14, 2026 to discuss NIST IR 8596 iprd and updates on SP 800-53 COSAiS.

Publications IR 8596 (Initial Preliminary Draft)

Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile): NIST Community Profile

December 16, 2025
https://csrc.nist.gov/pubs/ir/8596/iprd

Abstract: The Cybersecurity Framework Profile for Artificial Intelligence (AI) Profile (“Cyber AI Profile” or “The Profile”) will provide guidelines for managing cybersecurity risk related to AI systems as well as identifying opportunities for using AI to enhance cybersecurity capabili...

Updates

Updated Draft Guidelines for National Checklist Program for IT Products

December 9, 2025
https://csrc.nist.gov/news/2025/draft-sp-800-70-rev-5-is-available-for-comment

NIST Special Publication (SP) 800-70r5 ipd (Revision 5, initial public draft), National Checklist Program for IT Products – Guidelines for Checklist Users and Developers, is now available for public comment through January 16, 2026, at 11:59 PM (EST).

Project Pages

Key Management Guidelines

https://csrc.nist.gov/projects/key-management/key-management-guidelines

The following publications provide general key management guidance: Recommendation for Key Management December 5, 2025: An initial public draft of SP 800-57 Part 1 Revision 6 is available for comment through February 5, 2026. SP 800-57 Part 1 Revision 5 - General This Recommendation provides cryptographic key-management guidance. It consists of three parts. Part 1 provides general guidance and best practices for the management of cryptographic keying material, including definitions of the security services that may be provided when using cryptography and the algorithms and key...

Updates

Charting the Course for NIST OSCAL: NIST CSWP 53 is Available for Public Comment

December 2, 2025
https://csrc.nist.gov/news/2025/draft-charting-the-course-for-nist-oscal

The initial public draft of NIST Cybersecurity White Paper (CSWP) 53, Charting the Course for NIST OSCAL, is available for public comment. The public comment period is open through January 13, 2026.

Publications CSWP 53 (Initial Public Draft)

Charting the Course for NIST OSCAL

December 2, 2025
https://csrc.nist.gov/pubs/cswp/53/charting-the-course-for-nist-oscal/ipd

Abstract: This document introduces the Open Security Controls Assessment Language (OSCAL), a NIST-developed, open-source, machine-readable language that modernizes manual, paper-based cybersecurity compliance by enabling automated and scalable processes. OSCAL standardizes security documentation for easier mo...

Projects

Security Research Review Seminar

https://csrc.nist.gov/projects/srr-seminar

Security Research Review Seminar is a biweekly talk arranged by the Computer Security Division (773) of the Information Technology Laboratory (ITL) at NIST. Researchers, academics, and practitioners for within and outside NIST are invited to discuss their work in the areas of hardware, software, AI, and system level security. Interesting topics related to verification, validation, assurance, and standardizations are also discussed. Upcoming Talks The following schedule is tentative: Date Speaker Title Dec/Jan Hamid...

Updates

Secure Onboarding of IoT Devices to Networks: NIST Publishes CSWP 42, IR 8350, and SP 1800-36

November 25, 2025
https://csrc.nist.gov/news/2025/secure-onboarding-of-iot-devices-to-networks

The NCCoE is releasing three publications to help secure IoT devices and their networks: Cybersecurity White Paper 42, Internal Report 8350, and Special Publication 1800-36.

Publications SP 1800-36 (Final)

Trusted Internet of Things (IoT) Device Network-Layer Onboarding and Lifecycle Management: Enhancing Internet Protocol-Based IoT Device and Network Security

November 25, 2025
https://csrc.nist.gov/pubs/sp/1800/36/final

Abstract: Establishing trust between a network and an Internet of Things (IoT) device (as defined in NIST Internal Report 8425) prior to providing the device with the credentials it needs to join the network is crucial for mitigating the risk of potential attacks. There are two possibilities for attack. One h...

Updates

Second Public Draft of CSF 2.0 Quick-Start Guide for Cybersecurity, ERM, and Workforce Management

November 24, 2025
https://csrc.nist.gov/news/2025/nist-sp-1308-second-public-draft-qsg

A second public draft of NIST SP 1308, NIST CSF 2.0: Cybersecurity, Enterprise Risk Management, and Workforce Management Quick-Start Guide, is available for public comment through January 7, 2026.

Projects

Log Management

https://csrc.nist.gov/projects/log-management

NIST is in the process of addressing public comments on Draft Special Publication (SP) 800-92 Revision 1, Cybersecurity Log Management Planning Guide. The purpose of this document is to help all organizations improve their log management so they have the log data they need. The document's scope is cybersecurity log management planning, and all other aspects of logging and log management, including implementing log management technology and making use of log data, are out of scope. This document replaces the original SP 800-92, Guide to Computer Security Log Management. That material was...

Projects

Incident Response

https://csrc.nist.gov/projects/incident-response

In April 2025, NIST finalized Special Publication (SP) 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. NIST SP 800-61 Revision 3 seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities as described by the NIST Cybersecurity Framework (CSF) 2.0. Doing so can help organizations prepare for incident responses, reduce the number and impact of incidents that occur, and improve the efficiency...

Updates

Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments | NIST SP 1334

September 30, 2025
https://csrc.nist.gov/news/2025/cyber-risks-of-portable-storage-media-in-ot

The NCCoE has released Special Publication 1334, "Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments."

Updates

Foundational Cybersecurity Activities for IoT Product Manufacturers | IR 8259r1 2pd

September 30, 2025
https://csrc.nist.gov/news/2025/nist-ir-8259r1-second-public-draft

The second public draft of IR 8259r1, "Foundational Cybersecurity Activities for IoT Product Manufacturers," is available for comment through December 10, 2025.

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>