Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 201 through 225 of 1450 matching records.
Projects

Combinatorial Testing for AI-Enabled Systems

https://csrc.nist.gov/projects/combinatorial-testing-for-ai-enabled-systems

*NEW* Short course from the Defense and Aerospace Test and Analysis Workshop 2025 (Dataworks 2025) - complete course presentation here. The goal of this project is to provide practitioners and researchers with a foundational understanding of combinatorial testing techniques and applications to testing AI-enabled software systems (AIES). Resources are being developed in these areas: Combinatorial testing (CT), applying CT to test traditional software systems, including real-world examples and case studies. How Test and Evaluation (T&E) of AIES differ from traditional software systems...

Topics

smart grid

https://csrc.nist.gov/topics/applications/smart-grid

NIST's cybersecurity resources have supported NIST's smart grid development efforts, which resulted from the Energy Independence and Security Act of 2007 (EISA). RT=EISA

Updates

Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46

June 30, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-46

This document, Analyzing Collusion Threats in the Semiconductor Supply Chain | NIST Cybersecurity White Paper 46; has been approved as final.

Updates

Network Security Design Principles | Applying 5G Cybersecurity and Privacy Capabilities

June 17, 2025
https://csrc.nist.gov/news/2025/5g-network-security-design-principles-cswp-36e

NCCoE released the sixth white paper in the series, 5G Network Security Design Principles, which provides the network infrastructure security design principles that commercial and private 5G network operators are encouraged to use.

Updates

End-of-Life Announcement: NIST SCAP Validation Program

June 17, 2025
https://csrc.nist.gov/news/2025/end-of-life-announcement-nist-scapval

The National Institute of Standards and Technology (NIST) announces the phased conclusion of the Security Content Automation Protocol (SCAP) Validation Program.

Publications Conference Paper (Final)

Smart Home Users' Security and Privacy Perceptions and Actions Differ by Device Category: Results from a U.S. Survey

June 12, 2025
https://csrc.nist.gov/pubs/conference/2025/06/12/smart-home-users-security-and-privacy-percepti-(1)/final

Conference: Human-Computer Interaction International 2025 Conference Abstract: There are few insights into how users’ perspectives on smart home security and privacy differ depending on device category. This may leave the smart home community at a disadvantage in knowing how to focus user education efforts to address device-specific misunderstandings or concerns. As a re...

Updates

Implementing a Zero Trust Architecture: NIST Publishes SP 1800-35

June 10, 2025
https://csrc.nist.gov/news/2025/implementing-a-zero-trust-architecture-sp-1800-35

NIST Special Publication 1800-35, "Implementing a Zero Trust Architecture," provides results and best practices from NCCoE's work with 24 vendors to demonstrate end-to-end zero trust architecture.

Publications SP 1800-35 (Final)

Implementing a Zero Trust Architecture: High-Level Document

June 10, 2025
https://csrc.nist.gov/pubs/sp/1800/35/final

Abstract: A zero trust architecture (ZTA) enables secure authorized access to enterprise resources that are distributed across on-premises and multiple cloud environments, while enabling a hybrid workforce and partners to access resources from anywhere, at any time, from any device in support of the organizat...

Updates

Metrics and Methodology for Hardware Security Constructs | NIST Publishes Cybersecurity White Paper 45

June 5, 2025
https://csrc.nist.gov/news/2025/nist-cybersecurity-white-paper-45

Metrics and Methodology for Hardware Security Constructs utilizes a comprehensive methodology and two key metrics to analyze different hardware weaknesses and the specific attack patterns that can exploit them.

Project Pages

Supply Chain

https://csrc.nist.gov/projects/risk-management/sp800-53-controls/overlay-repository/nist-developed-overlay-submissions/supply-chain

Overlay Name: NIST SP 800-161, Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations Overlay Publication Date: May 2022 Technology or System: Cyber Supply Chain Overlay Author: Jon Boyens (NIST), Angela Smith (NIST), Nadya Bartol (BCG), Kris Winkler (BCG), Alex Holbrook (BCG), Matthew Fallon (BCG) Comments: Identification and augmentation of cybersecurity supply chain risk management (C-SCRM)-related controls in SP 800-53, Revision 5. Refer to SP 800-161r1, Appendix A, for the C-SCRM Controls. C-SCRM is an enterprise-wide activity that should be...

Updates

Open for Public Comment | Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems

June 4, 2025
https://csrc.nist.gov/news/2025/draft-sp-800-18-rev-2-ipd-open-for-public-comment

NIST has released the initial public draft (ipd) of Special Publication (SP) 800-18r2. The comment period is open through July 30, 2025.

Updates

Usable Cybersecurity and Privacy for Immersive Technologies | Workshop Report

May 23, 2025
https://csrc.nist.gov/news/2025/immersive-technologies-workshop-report-ir-8557

NIST has released Internal Report (IR) 8557 for the Virtual Workshop on Usable Cybersecurity and Privacy for Immersive Technologies

Publications IR 8557 (Final)

Report of the Virtual Workshop on Usable Cybersecurity and Privacy for Immersive Technologies

May 23, 2025
https://csrc.nist.gov/pubs/ir/8557/final

Abstract: This document reports on the Virtual Workshop on Usable Cybersecurity and Privacy for Immersive Technologies (the Workshop) hosted by the Symposium in Usable Privacy and Security (SOUPS). The Workshop was held on August 7th, 2024 before the in-person symposium held August 11th and 12th, 2024 in Phil...

Updates

Likely Exploited Vulnerabilities: NIST Publishes Cybersecurity White Paper 41

May 19, 2025
https://csrc.nist.gov/news/2025/nist-publishes-cybersecurity-white-paper-41

NIST Cybersecurity White Paper (CSWP) 41, "Likely Exploited Vulnerabilities: A Proposed Metric for Vulnerability Exploitation Probability", helps organizations identify actively exploited vulnerabilities and measure prioritization after patching.

Updates

Foundational Cybersecurity Activities for IoT Product Manufacturers | IR 8259r1 ipd and IR 8572

May 13, 2025
https://csrc.nist.gov/news/2025/foundational-cyber-activities-for-iot-product-manu

In addition to publishing a report on the "Workshop on Foundational Cybersecurity Activities for IoT Device Manufacturers" (IR 8572), an initial public draft of IR 8259r1, "Foundational Cybersecurity Activities for IoT Product Manufacturers," is available for comment through July 14, 2025.

Publications IR 8572 (Final)

Workshop Summary Report for “Workshop on Foundational Cybersecurity Activities for IoT Device Manufacturers”

May 13, 2025
https://csrc.nist.gov/pubs/ir/8572/final

Abstract: This report summarizes discussions held at the March 5, 2025 "Workshop on Foundational Cybersecurity Activities for IoT Device Manufacturers” organized by the NIST Cybersecurity for the Internet of Things (IoT) program. This workshop follows an earlier event held in December 2024 titled “Workshop on...

Projects

Security Aspects of Electronic Voting

https://csrc.nist.gov/projects/security-aspects-of-electronic-voting

The Help America Vote Act (HAVA) of 2002 was passed by Congress to encourage the upgrade of voting equipment across the United States. HAVA established the Election Assistance Commission (EAC) and the Technical Guidelines Development Committee (TGDC), chaired by the Director of NIST, was well as a Board of Advisors and Standard Board. HAVA calls on NIST to provide technical support to the EAC and TGDC in efforts related to human factors, security, and laboratory accreditation. The Information Technology Laboratory supports the activities of the EAC and TGDC related to voting equipment...

Projects

Attribute Based Access Control

https://csrc.nist.gov/projects/attribute-based-access-control

The concept of Attribute Based Access Control (ABAC) has existed for many years. It represents a point on the spectrum of logical access control from simple access control lists to more capable role-based access, and finally to a highly flexible method for providing access based on the evaluation of attributes. In November 2009, the Federal Chief Information Officers Council (Federal CIO Council) published the Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Plan v1.0, which provided guidance to federal organizations to evolve their logical access control...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>