Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 176 through 200 of 1440 matching records.
Updates

Second Public Draft | Supply Chain Traceability: Manufacturing Meta-Framework

July 31, 2025
https://csrc.nist.gov/news/2025/nist-ir-8536-second-public-draft

NIST's NCCoE has posted the second public draft of NIST IR 8536, "Supply Chain Traceability: Manufacturing Meta-Framework," for public comment. The comment period is open through October 3, 2025.

Publications IR 8579 (Initial Public Draft)

Developing the NCCoE Chatbot: Technical and Security Learnings from the Initial Implementation

July 31, 2025
https://csrc.nist.gov/pubs/ir/8579/ipd

Abstract: Chatbots are emerging as alternative interfaces for structured information retrieval and internal knowledge access. Chatbots can utilize the capabilities of large language models (LLMs) to help interpret user-provided input and provide responses to a variety of requests. This paper describes the dev...

Publications SP 800-63-4 (Final)

Digital Identity Guidelines

July 31, 2025
https://csrc.nist.gov/pubs/sp/800/63/4/final

Abstract: These guidelines cover the identity proofing, authentication, and federation of users (e.g., employees, contractors, or private individuals) who interact with government information systems over networks. They define technical requirements in each of the areas of identity proofing, enrollment, authe...

Publications IR 8536 (2nd Public Draft)

Supply Chain Traceability: Manufacturing Meta-Framework

July 31, 2025
https://csrc.nist.gov/pubs/ir/8536/2pd

Abstract: Manufacturing and critical infrastructure supply chains are vital to the security, resilience, and economic strength of the United States. However, increasing global complexity makes tracing product origins more difficult, exposing vulnerabilities to logistical disruptions, fraud, sabotage, and coun...

Updates

Secure Software Development, Security, and Operations (DevSecOps) Practices | Draft SP 1800-44A

July 30, 2025
https://csrc.nist.gov/news/2025/draft-sp-1800-44a-available-for-comment

Volume A of NIST Special Publication 1800-44, "Secure Software Development, Security, and Operations (DevSecOps) Practices," is available for comment through September 14, 2025.

Updates

Draft SP 800-53 Controls on Secure and Reliable Patches Available for Comment

July 22, 2025
https://csrc.nist.gov/news/2025/sp-800-53-draft-controls-available-for-comment

NIST's draft updates to SP 800-53 providing additional guidance on how to securely and reliably deploy patches and updates in response to Executive Order 14306

Topics

Executive Order 14306

https://csrc.nist.gov/topics/laws-and-regulations/executive-documents/executive-order-14306

Sustaining Select Efforts To Strengthen the Nation's Cybersecurity and Amending Executive Order 13694 and Executive Order 14144 (June 6, 2025)

Updates

Considerations for Achieving Crypto Agility | Second Public Draft Available for Comment

July 18, 2025
https://csrc.nist.gov/news/2025/considerations-for-achieving-crypto-agility-2nd-dr

The second public draft of NIST Cybersecurity White Paper (CSWP) 39, Considerations for Achieving Crypto Agility: Strategies and Practices is available for comment. The public comment period for this second draft is open through August 15, 2025.

Updates

Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments | Comment on NIST SP 1334

July 15, 2025
https://csrc.nist.gov/news/2025/cyber-risks-of-portable-storage-media-in-ot-enviro

The NCCoE seeks public comments on the initial public draft of SP 1334, "Reducing the Cybersecurity Risks of Portable Storage Media in OT Environments." Comments are due August 14, 2025.

Projects

Combinatorial Testing for AI-Enabled Systems

https://csrc.nist.gov/projects/combinatorial-testing-for-ai-enabled-systems

*NEW* Short course from the Defense and Aerospace Test and Analysis Workshop 2025 (Dataworks 2025) - complete course presentation here. The goal of this project is to provide practitioners and researchers with a foundational understanding of combinatorial testing techniques and applications to testing AI-enabled software systems (AIES). Resources are being developed in these areas: Combinatorial testing (CT), applying CT to test traditional software systems, including real-world examples and case studies. How Test and Evaluation (T&E) of AIES differ from traditional software systems...

Topics

smart grid

https://csrc.nist.gov/topics/applications/smart-grid

NIST's cybersecurity resources have supported NIST's smart grid development efforts, which resulted from the Energy Independence and Security Act of 2007 (EISA). RT=EISA

Updates

Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46

June 30, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-46

This document, Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46; has been approved as final.

Updates

Network Security Design Principles | Applying 5G Cybersecurity and Privacy Capabilities

June 17, 2025
https://csrc.nist.gov/news/2025/5g-network-security-design-principles-cswp-36e

NCCoE released the sixth white paper in the series, 5G Network Security Design Principles, which provides the network infrastructure security design principles that commercial and private 5G network operators are encouraged to use.

Updates

End-of-Life Announcement: NIST SCAP Validation Program

June 17, 2025
https://csrc.nist.gov/news/2025/end-of-life-announcement-nist-scapval

The National Institute of Standards and Technology (NIST) announces the phased conclusion of the Security Content Automation Protocol (SCAP) Validation Program.

Updates

Implementing a Zero Trust Architecture: NIST Publishes SP 1800-35

June 10, 2025
https://csrc.nist.gov/news/2025/implementing-a-zero-trust-architecture-sp-1800-35

NIST Special Publication 1800-35, "Implementing a Zero Trust Architecture," provides results and best practices from NCCoE's work with 24 vendors to demonstrate end-to-end zero trust architecture.

Publications SP 1800-35 (Final)

Implementing a Zero Trust Architecture: High-Level Document

June 10, 2025
https://csrc.nist.gov/pubs/sp/1800/35/final

Abstract: A zero trust architecture (ZTA) enables secure authorized access to enterprise resources that are distributed across on-premises and multiple cloud environments, while enabling a hybrid workforce and partners to access resources from anywhere, at any time, from any device in support of the organizat...

Updates

Metrics and Methodology for Hardware Security Constructs | NIST Publishes Cybersecurity White Paper 45

June 5, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-45

Metrics and Methodology for Hardware Security Constructs utilizes a comprehensive methodology and two key metrics to analyze different hardware weaknesses and the specific attack patterns that can exploit them.

Project Pages

Supply Chain

https://csrc.nist.gov/projects/risk-management/sp800-53-controls/overlay-repository/nist-developed-overlay-submissions/supply-chain

Overlay Name: NIST SP 800-161, Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations Overlay Publication Date: May 2022 Technology or System: Cyber Supply Chain Overlay Author: Jon Boyens (NIST), Angela Smith (NIST), Nadya Bartol (BCG), Kris Winkler (BCG), Alex Holbrook (BCG), Matthew Fallon (BCG) Comments: Identification and augmentation of cybersecurity supply chain risk management (C-SCRM)-related controls in SP 800-53, Revision 5. Refer to SP 800-161r1, Appendix A, for the C-SCRM Controls. C-SCRM is an enterprise-wide activity that should be...

Updates

Open for Public Comment | Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

June 4, 2025
https://csrc.nist.gov/news/2025/draft-sp-800-18-rev-2-ipd-open-for-public-comment

NIST has released the initial public draft (ipd) of Special Publication (SP) 800-18r2. The comment period is open through July 30, 2025.

Updates

Usable Cybersecurity and Privacy for Immersive Technologies | Workshop Report

May 23, 2025
https://csrc.nist.gov/news/2025/immersive-technologies-workshop-report-ir-8557

NIST has released Internal Report (IR) 8557 for the Virtual Workshop on Usable Cybersecurity and Privacy for Immersive Technologies

Publications IR 8557 (Final)

Report of the Virtual Workshop on Usable Cybersecurity and Privacy for Immersive Technologies

May 23, 2025
https://csrc.nist.gov/pubs/ir/8557/final

Abstract: This document reports on the Virtual Workshop on Usable Cybersecurity and Privacy for Immersive Technologies (the Workshop) hosted by the Symposium in Usable Privacy and Security (SOUPS). The Workshop was held on August 7th, 2024 before the in-person symposium held August 11th and 12th, 2024 in Phil...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>