Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 151 through 175 of 1422 matching records.
Updates

Development of an Internal-Use NCCoE Chatbot | Comment on Draft NIST IR 8579

July 31, 2025
https://csrc.nist.gov/news/2025/draft-nist-ir-8579-nccoe-chatbot

The National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of Internal Report (IR) 8579. The comment period for this NIST IR closes on September 11, 2025.

Updates

Second Public Draft | Supply Chain Traceability: Manufacturing Meta-Framework

July 31, 2025
https://csrc.nist.gov/news/2025/nist-ir-8536-second-public-draft

NIST's NCCoE has posted the second public draft of NIST IR 8536, "Supply Chain Traceability: Manufacturing Meta-Framework," for public comment. The comment period is open through October 3, 2025.

Publications IR 8536 (2nd Public Draft)

Supply Chain Traceability: Manufacturing Meta-Framework

July 31, 2025
https://csrc.nist.gov/pubs/ir/8536/2pd

Abstract: Manufacturing and critical infrastructure supply chains are vital to the security, resilience, and economic strength of the United States. However, increasing global complexity makes tracing product origins more difficult, exposing vulnerabilities to logistical disruptions, fraud, sabotage, and coun...

Publications IR 8579 (Initial Public Draft)

Developing the NCCoE Chatbot: Technical and Security Learnings from the Initial Implementation

July 31, 2025
https://csrc.nist.gov/pubs/ir/8579/ipd

Abstract: Chatbots are emerging as alternative interfaces for structured information retrieval and internal knowledge access. Chatbots can utilize the capabilities of large language models (LLMs) to help interpret user-provided input and provide responses to a variety of requests. This paper describes the dev...

Publications SP 800-63-4 (Final)

Digital Identity Guidelines

July 31, 2025
https://csrc.nist.gov/pubs/sp/800/63/4/final

Abstract: These guidelines cover the identity proofing, authentication, and federation of users (e.g., employees, contractors, or private individuals) who interact with government information systems over networks. They define technical requirements in each of the areas of identity proofing, enrollment, authe...

Updates

Secure Software Development, Security, and Operations (DevSecOps) Practices | Draft SP 1800-44A

July 30, 2025
https://csrc.nist.gov/news/2025/draft-sp-1800-44a-available-for-comment

Volume A of NIST Special Publication 1800-44, "Secure Software Development, Security, and Operations (DevSecOps) Practices," is available for comment through September 14, 2025.

Updates

Draft SP 800-53 Controls on Secure and Reliable Patches Available for Comment

July 22, 2025
https://csrc.nist.gov/news/2025/sp-800-53-draft-controls-available-for-comment

NIST's draft updates to SP 800-53 providing additional guidance on how to securely and reliably deploy patches and updates in response to Executive Order 14306

Topics

Executive Order 14306

https://csrc.nist.gov/topics/laws-and-regulations/executive-documents/executive-order-14306

Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144 (June 6, 2025)

Updates

Considerations for Achieving Crypto Agility | Second Public Draft Available for Comment

July 18, 2025
https://csrc.nist.gov/news/2025/considerations-for-achieving-crypto-agility-2nd-dr

The second public draft of NIST Cybersecurity White Paper (CSWP) 39, Considerations for Achieving Crypto Agility: Strategies and Practices is available for comment. The public comment period for this second draft is open through August 15, 2025.

Updates

Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments | Comment on NIST SP 1334

July 15, 2025
https://csrc.nist.gov/news/2025/cyber-risks-of-portable-storage-media-in-ot-enviro

The NCCoE seeks public comments on the initial public draft of SP 1334, "Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments." Comments are due August 14, 2025.

Projects

Combinatorial Testing for AI-Enabled Systems

https://csrc.nist.gov/projects/combinatorial-testing-for-ai-enabled-systems

*NEW* Short course from the Defense and Aerospace Test and Analysis Workshop 2025 (Dataworks 2025) - complete course presentation here. The goal of this project is to provide practitioners and researchers with a foundational understanding of combinatorial testing techniques and applications to testing AI-enabled software systems (AIES). Resources are being developed in these areas: Combinatorial testing (CT), applying CT to test traditional software systems, including real-world examples and case studies. How Test and Evaluation (T&E) of AIES differ from traditional software systems...

Topics

smart grid

https://csrc.nist.gov/topics/applications/smart-grid

NIST's cybersecurity resources have supported NIST's smart grid development efforts, which resulted from the Energy Independence and Security Act of 2007 (EISA). RT=EISA

Updates

Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46

June 30, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-46

This document, Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46; has been approved as final.

Updates

Network Security Design Principles | Applying 5G Cybersecurity and Privacy Capabilities

June 17, 2025
https://csrc.nist.gov/news/2025/5g-network-security-design-principles-cswp-36e

NCCoE released the sixth white paper in the series, 5G Network Security Design Principles, which provides the network infrastructure security design principles that commercial and private 5G network operators are encouraged to use.

Updates

End-of-Life Announcement: NIST SCAP Validation Program

June 17, 2025
https://csrc.nist.gov/news/2025/end-of-life-announcement-nist-scapval

The National Institute of Standards and Technology (NIST) announces the phased conclusion of the Security Content Automation Protocol (SCAP) Validation Program.

Updates

Implementing a Zero Trust Architecture: NIST Publishes SP 1800-35

June 10, 2025
https://csrc.nist.gov/news/2025/implementing-a-zero-trust-architecture-sp-1800-35

NIST Special Publication 1800-35, "Implementing a Zero Trust Architecture," provides results and best practices from NCCoE's work with 24 vendors to demonstrate end-to-end zero trust architecture.

Publications SP 1800-35 (Final)

Implementing a Zero Trust Architecture: High-Level Document

June 10, 2025
https://csrc.nist.gov/pubs/sp/1800/35/final

Abstract: A zero trust architecture (ZTA) enables secure authorized access to enterprise resources that are distributed across on-premises and multiple cloud environments, while enabling a hybrid workforce and partners to access resources from anywhere, at any time, from any device in support of the organizat...

Updates

Metrics and Methodology for Hardware Security Constructs | NIST Publishes Cybersecurity White Paper 45

June 5, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-45

Metrics and Methodology for Hardware Security Constructs utilizes a comprehensive methodology and two key metrics to analyze different hardware weaknesses and the specific attack patterns that can exploit them.

Project Pages

Supply Chain

https://csrc.nist.gov/projects/risk-management/sp800-53-controls/overlay-repository/nist-developed-overlay-submissions/supply-chain

Overlay Name: NIST SP 800-161, Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations Overlay Publication Date: May 2022 Technology or System: Cyber Supply Chain Overlay Author: Jon Boyens (NIST), Angela Smith (NIST), Nadya Bartol (BCG), Kris Winkler (BCG), Alex Holbrook (BCG), Matthew Fallon (BCG) Comments: Identification and augmentation of cybersecurity supply chain risk management (C-SCRM)-related controls in SP 800-53, Revision 5. Refer to SP 800-161r1, Appendix A, for the C-SCRM Controls. C-SCRM is an enterprise-wide activity that should be...

Updates

Open for Public Comment | Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

June 4, 2025
https://csrc.nist.gov/news/2025/draft-sp-800-18-rev-2-ipd-open-for-public-comment

NIST has released the initial public draft (ipd) of Special Publication (SP) 800-18r2. The comment period is open through July 30, 2025.

Publications SP 800-18 Rev. 2 (Initial Public Draft)

Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

June 4, 2025
https://csrc.nist.gov/pubs/sp/800/18/r2/ipd

Abstract: The system security plan, system privacy plan, and cybersecurity supply chain risk management plan are collectively referred to as system plans. They describe the purpose of the system, the operational status of the controls selected and allocated for meeting risk management requirements, and the re...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>