Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 301 through 325 of 1222 matching records.
Publications SP 800-201 (Initial Public Draft)

NIST Cloud Computing Forensic Reference Architecture

February 8, 2023
https://csrc.nist.gov/pubs/sp/800/201/ipd

Abstract: This document summarizes research performed by the members of the NIST Cloud Computing Forensic Science Working Group and presents the NIST Cloud Computing Forensic Reference Architecture (CC FRA, also referred to as FRA for the sake of brevity), whose goal is to provide support for a cloud system’s...

Events

Automotive Cybersecurity Community of Interest (COI) Webinar

February 7, 2023 - February 7, 2023
https://csrc.nist.gov/events/2023/automotive-cybersecurity-community-of-interest-coi

The automotive industry is facing significant challenges from increased cybersecurity risk and adoption of AI and opportunities from rapid technological innovations. To provide assistance to the industry, NIST has started a COI for automotive cybersecurity. This webinar will introduce the members of the COI to projects and research currently active at NIST that are of interest to the community. Participants will also be informed of ways to participate in these projects and research.

Updates

NIST Revises the Foundational PNT Profile for Positioning, Navigation, and Timing (PNT) Services: NIST IR 8323r1

January 31, 2023
https://csrc.nist.gov/news/2023/nist-ir-8323-revision-1-pnt-is-now-available

NIST is publishing NIST IR 8323r1 (revision 1), Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services.

Publications IR 8323 Rev. 1 (Final)

Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT) Services

January 31, 2023
https://csrc.nist.gov/pubs/ir/8323/r1/final

Abstract: The national and economic security of the United States (U.S.) is dependent upon the reliable functioning of the nation’s critical infrastructure. Positioning, Navigation, and Timing (PNT) services are widely deployed throughout this infrastructure. In a government-wide effort to mitigate the potent...

Publications Other (Final)

Handout | Users Are Not Stupid: Six Cybersecurity Pitfalls Overturned

January 30, 2023
https://csrc.nist.gov/pubs/other/2023/01/30/handout-users-are-not-stupid-six-cybersecurity-pit/final

Abstract: The cybersecurity community tends to focus and depend on technology to solve today's cybersecurity problems, often without taking into consideration the human element - the key individual and social factors impacting cybersecurity adoption. This handout provides an overview of six human-element misc...

Updates

Concept Paper Released | Comment on Proposed Significant Updates to the CSF & Register for In-Person Event

January 19, 2023
https://csrc.nist.gov/news/2023/csf-2-0-concept-paper-released

The NIST Cybersecurity Framework (CSF) helps organizations better understand, manage, reduce, and communicate cybersecurity risks. NIST is updating the CSF to keep pace with the evolving cybersecurity landscape.

Publications Conference Paper (Final)

An Investigation of Roles, Backgrounds, Knowledge, and Skills of U.S. Government Security Awareness Professionals

January 17, 2023
https://csrc.nist.gov/pubs/conference/2023/01/17/an-investigation-of-roles-backgrounds-knowledge-an/final

Conference: ACM SIGMIS Computers and People Research Conference 2022 Abstract: Security awareness professionals are tasked with implementing security awareness programs within their organizations to assist employees in recognizing and responding to security issues. Prior industry-focused surveys and research studies identified desired skills for these professionals, finding th...

Publications SP 1288 (Final)

Federal Cybersecurity Role-Based Training Approaches, Successes, and Challenges

January 11, 2023
https://csrc.nist.gov/pubs/sp/1288/final

Abstract: Most United States federal government organizations are required to conduct cybersecurity role-based training for federal government personnel and supporting contractors who are assigned roles having security and privacy responsibilities. Despite the training mandate, there has been little prior eff...

Project Pages

Existing Work to Leverage

https://csrc.nist.gov/projects/devsecops/resources

The NIST NCCoE has launched a new project, Software Supply Chain and DevOps Security Practices. In early 2023, the project team will be publishing a Federal Register Notice based on the final project description to solicit collaborators to work with the NCCoE on the project. NIST held a virtual workshop in January 2021 on improving the security of DevOps practices; you can access the workshop recording and materials here. A second virtual workshop was held in September 2022 on the planned NCCoE DevSecOps project; the workshop recording and presentations are posted. NIST will leverage existing...

Updates

Applying the Cybersecurity Framework to Satellite Command and Control: NIST Interagency Report (IR) 8401

January 3, 2023
https://csrc.nist.gov/news/2023/nist-releases-nist-ir-8401

NIST recognizes the importance of the infrastructure that provides positioning, timing, and navigation (PNT) information to the scientific knowledge, economy, and security of the Nation. This infrastructure consists of three parts: the space segment, the ground segment, and the users of PNT.

Publications IR 8401 (Final)

Satellite Ground Segment: Applying the Cybersecurity Framework to Satellite Command and Control

December 30, 2022
https://csrc.nist.gov/pubs/ir/8401/final

Abstract: Space operations are increasingly important to the national and economic security of the United States. Commercial space’s contribution to the critical infrastructure is growing in both volume and diversity of services as illustrated by the increased use of commercial communications satellite (COMSA...

Publications Project Description (Final)

Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector (Rev. 1)

December 22, 2022
https://csrc.nist.gov/pubs/pd/2022/12/22/responding-to-and-recovering-from-a-cyber-attack-m/final

Abstract: The Operational Technology (OT) that runs manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on OT to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing number of cyber attac...

Events

Cybersecurity Measurement Workshop

December 13, 2022 - December 13, 2022
https://csrc.nist.gov/events/2022/cybersecurity-measurement-workshop

For full details of this workshop (virtual), please visit the NIST Event listing at: https://www.nist.gov/news-events/events/2022/12/cybersecurity-measurement-workshop The NIST Cybersecurity Risk Analytics Team is hosting a workshop to provide an overview of the proposed changes for Special Publication 800 – 55, Revision 2, Performance Measurement Guide for Information Security. The purpose of the workshop is to provide clarity, answer questions, and gather stakeholder comments and opinions to ensure that Revision 2 will deliver comprehensive and relevant practices for measurement and...

Publications SP 1800-34 (Final)

Validating the Integrity of Computing Devices

December 9, 2022
https://csrc.nist.gov/pubs/sp/1800/34/final

Abstract: Organizations are increasingly at risk of cyber supply chain compromise, whether intentional or unintentional. Cyber supply chain risks include counterfeiting, unauthorized production, tampering, theft, and insertion of unexpected software and hardware. Managing these risks requires ensuring the int...

Updates

National Online Informative References (OLIR) Program: Two Draft NIST IRs Available for Comment

December 8, 2022
https://csrc.nist.gov/news/2022/nist-releases-two-draft-nist-irs-for-olir

NIST is seeking public comments on two draft NIST Internal Reports (NIST IR) for the National Online Informative References (OLIR) Program.

Events

Federal Cybersecurity & Privacy Professionals Forum Meeting - December 2022

December 6, 2022 - December 6, 2022
https://csrc.nist.gov/events/2022/federal-cybersecurity-privacy-professionals-forum

The Federal Cybersecurity and Privacy Professionals Forum is an informal group sponsored by the National Institute of Standards and Technology (NIST) to promote the sharing of system security and privacy information among federal, state, and local government, and higher education employees. The Forum maintains an extensive e-mail list and holds quarterly meetings to discuss current issues and items of interest to those responsible for protecting non-national security systems. For more information about the Forum and instructions on how to join, see: https://csrc.nist.gov/Projects/forum. A...

Project Pages

Meet the RMF Team

https://csrc.nist.gov/projects/risk-management/meet-the-rmf-team

The NIST Risk Management Framework Team conducts the research and develops the suite of key cybersecurity risk management standards and guidelines, as required by Congressional legislation to support implementation of the Federal Information Security Modernization Act (FISMA) and to assist organizations better understand and manage cybersecurity risk for their systems and organizations. We collaborate with the Cyber Supply Chain Risk Management Team in the NIST Computer Security Division and Privacy Engineering Team in the NIST Applied Cybersecurity Division to develop the suite of...

Updates

NIST Releases IR 8286D: Using Business Impact Analysis to Inform Risk Prioritization and Response

November 17, 2022
https://csrc.nist.gov/news/2022/nist-releases-nistir-8286d

Business impact analyses (BIAs) have been traditionally used for business continuity and disaster recovery (BC/DR) planning to understand the potential impacts of outages that compromise IT infrastructure.

Publications IR 8286D (Final)

Using Business Impact Analysis to Inform Risk Prioritization and Response

November 17, 2022
https://csrc.nist.gov/pubs/ir/8286/d/final

Abstract: While business impact analysis (BIA) has historically been used to determine availability requirements for business continuity, the process can be extended to provide a broad understanding of the potential impacts of any type of loss on the enterprise mission. The management of enterprise risk requi...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>