Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 26 through 50 of 2807 matching records.
Publications SP 800-85A-1 (Final) (Withdrawn) March 31, 2009

https://csrc.nist.gov/pubs/sp/800/85/a/1/final

Abstract: The objective of this document [SP 800-85A-1] is to provide test requirements and test assertions that could be used to validate the compliance/conformance of two PIV components PIV middleware and PIV card application with the specifications in NIST SP 800-73-2.

Publications Conference Paper (Final) June 3, 2008
https://csrc.nist.gov/pubs/conference/2008/06/03/policy-specification-and-enforcement-for-smart-id/final

Conference: IEEE Workshop on Policies for Distributed Systems and Networks (IEEE Policy 2008) Abstract: Deployment of Smart Cards for Identity Verification requires collection of credentials and provisioning of credentials from and to heterogeneous and sometimes legacy systems. To facilitate this process, a centralized identity store called Identity Management System (IDMS) is often used. To protect t...

Publications SP 800-76-1 (Final) (Withdrawn) January 17, 2007

https://csrc.nist.gov/pubs/sp/800/76/1/final

Abstract: This document, Special Publication 800-76, is a companion document to FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors. It describes technical acquisition and formatting specifications for the biometric credentials of the PIV system, including the PIV Card itself....

Publications SP 800-85A (Final) (Withdrawn) April 5, 2006

https://csrc.nist.gov/pubs/sp/800/85/a/final

Abstract: This document provides derived test requirements and test assertions for generating conformance tests for the following classes of specification in SP 800-73: (a) End-Point Client-Application Programming Interface (Chapter 6 of SP 800-73). (b) End-Point PIV Card Application Card Command Interface (C...

Publications SP 800-85 (Final) (Withdrawn) October 19, 2005

https://csrc.nist.gov/pubs/sp/800/85/final

Abstract: This document specifies the test plan, processes, derived test requirements, and detailed test assertions for testing the following: (a)PIV middleware (client application API conformance) (b)PIV on-card application (for conformance to card application card command interface) (c)PIV Data objects repr...

Publications Conference Paper (Final) July 30, 2003
https://csrc.nist.gov/pubs/conference/2003/07/30/specification-and-validation-of-enterprise-access/final

Conference: 7th World Multi-conference on Systemics, Cybernetics and Informatics (WMSCI 2003) Abstract: The effectiveness of an enterprise access control framework depends upon the integrity of the various components or the building blocks used in that framework. The essential components of that framework are: (a) an Enterprise Access Control Model (b) a Validation mechanism to verify the enterprise a...

Publications Conference Paper (Final) October 1, 1998
https://csrc.nist.gov/pubs/conference/1998/10/01/formal-specification-for-role-based-access-control/final

Conference: Third ACM Workshop on Role-Based Access Control (RBAC '98) Abstract: Role Based Access Control (RBAC), an access control mechanism, reduces the cost of administering access control policies as well as making the process less error-prone. The Admin Tool developed for the NIST RBAC Model manages user/role and role/role relationships stored in the RBAC Database. This pa...

Publications Journal Article (Final) December 1, 1992
https://csrc.nist.gov/pubs/journal/1992/12/a-technique-for-analyzing-the-effects-of-changes-i/final

Journal: The Computer Journal Abstract: Formal specifications are increasingly used in modeling software systems. An important aspect of a model is its value as an analytical tool to investigate the effect of changes. This paper defines the notion of predicate differences and shows how predicate differences may be used to analyze the effe...

Publications Journal Article (Final) September 1, 1989
https://csrc.nist.gov/pubs/journal/1989/09/generating-extended-state-transitions-from-structu/final

Journal: Software Engineering Journal Abstract: The paper describes a method for providing improved prototyping capabilities in a process control system emulation tool. The tool, the NIST Hierarchical Control System Emulator, allows concurrent execution of modules emulating both physical processes and decision processes. The concurrent modules ar...

Updates April 23, 2024
https://csrc.nist.gov/news/2024/giving-nist-sp-80063b-a-boost

Today, we published our first supplement to the Digital Identity Guidelines. A supplement is a specific document type that is intended to enhance,

Updates April 10, 2024
https://csrc.nist.gov/news/2024/online-intro-courses-for-nist-sp-800-53

NIST has released three self-guided online introductory courses on the NIST Special Publication (SP) 800-53 security and privacy control catalog.

Updates April 3, 2024
https://csrc.nist.gov/news/2024/incident-response-recommendations-and-consideratio

The initial public draft of Special Publication (SP) 800-61r3 (Revision 3), "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile," is available for public comment, with comments due by May 20, 2024.

Updates March 5, 2024
https://csrc.nist.gov/news/2024/nist-to-revise-sp-80038d-gcm-and-gmac-modes

After two periods of public comment, NIST has decided to revise Special Publication 800-38D, "Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC."

Updates February 14, 2024
https://csrc.nist.gov/news/2024/nist-publishes-sp-80066-revision-2-implementing-th

NIST published the final version of Special Publication (SP) 800-66r2 (Revision 2), Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide.

Updates February 12, 2024
https://csrc.nist.gov/news/2024/nist-publishes-sp-800204d

NIST is releasing Special Publication (SP) 800-204D, Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines.

Updates February 10, 2024
https://csrc.nist.gov/news/2024/nist-to-revise-special-publication-80038e

After two public comment periods, NIST has decided to revise SP 800-38E, "Recommendation for Block Cipher Modes of Operation: the XTS-AES Mode for Confidentiality on Storage Devices."

Updates February 9, 2024
https://csrc.nist.gov/news/2024/nist-releases-sp-800-223

NIST has published Special Publication (SP) 800-223, High-Performance Computing Security: Architecture, Threat Analysis, and Security Posture.

Updates January 31, 2024
https://csrc.nist.gov/news/2024/nist-requests-comments-on-sp-800-60r2

NIST seeks to update and improve the guidance in Special Publication (SP) 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories.

Updates January 30, 2024
https://csrc.nist.gov/news/2024/2nd-prelim-draft-of-nist-sp-180037

Volumes A (2nd preliminary draft) and B (initial prelim. draft) of NIST Special Publication 1800-37, Addressing Visibility Challenges with TLS 1.3 within the Enterprise, are available for public comment through April 1, 2024.

Updates January 17, 2024
https://csrc.nist.gov/news/2024/nist-sp-800-55-draft-available-for-comment

NIST Special Publication (SP) Draft 800-55, Measurement Guide for Information Security, Volume 1 — Identifying and Selecting Measures, and Volume 2 — Developing an Information Security Measurement Program, are now available for public review and comment through March 18, 2024.

Updates December 13, 2023
https://csrc.nist.gov/news/2023/comment-on-nist-sp-800-79-revision-3

The initial public draft (ipd) of SP 800-79r3 (Revision 3), Guidelines for the Authorization of PIV Card and Derived PIV Credential Issuers, provides appropriate and useful guidelines for assessing the reliability of PIV Card and derived PIV credential issuers. Comment deadline is January 29, 2024.

Updates December 11, 2023
https://csrc.nist.gov/news/2023/just-released-draft-nist-sp-800-226

Just released for Public Comment: Initial Public Draft of SP 800-26, Guidelines for Evaluating Differential Privacy Guarantees publication for public comment until Thursday, January 25, 2024!

Updates November 17, 2023
https://csrc.nist.gov/news/2023/just-released-nist-sp-800-221-nist-sp-800-221a

Today, NIST is issuing best practices on how to better integrate ICT risk programs into an overarching ERM portfolio—given special attention to coordination and communication across risk programs.

Updates November 9, 2023
https://csrc.nist.gov/news/2023/drafts-of-800-171-rev-3-and-800-171a-rev-3-availab

The final public draft (fpd) of NIST Special Publication (SP) 800-171r3 (Revision 3) and initial public draft (ipd) of NIST SP 800-171Ar3 (Revision 3) are now available for public review. The comment period is open through January 26, 2024.

Updates November 7, 2023
https://csrc.nist.gov/news/2023/cybersecurity-and-privacy-reference-tool-update

NIST has issued SP 800-53 Release 5.1.1 in the Cybersecurity and Privacy Reference Tool (CPRT).

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>