Date Published: September 29, 2021
                    
                                            Comments Due: November 1, 2021 (public comment period is CLOSED)
                            Email Questions to: sp800-204c-comments@nist.gov
            
The newest generation of software applications—"cloud-native applications"—is a class with various functional layers, such as transaction logic, application services, infrastructure resources, policy enforcement, and monitoring of states. The unique architecture of this application class requires a more agile software life cycle paradigm, and DevSecOps (development, security, and operations) offers faster deployment and updates, while integrating security throughout the life cycle.
Draft NIST SP 800-204C provides guidance for the implementation of DevSecOps primitives for a reference platform hosting a cloud-native application with the functional layers described above. The guidance also discusses the benefits of this approach for high security assurance and enabling continuous authority to operate (C-ATO).
NOTE: A call for patent claims is included on page iii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.
None selected
                    Publication:
                          SP 800-204C (Draft) (DOI)
                                     Local Download
                
                    Supplemental Material:
                        None available
                
                        Document History:
                        
                                    09/29/21: SP  800-204C (Draft)
                                    03/08/22: SP  800-204C (Final)
                        
                    
                            Security and Privacy
                            
                                general security & privacy;                                 security programs & operations                            
                        
                            Technologies
                            
                                cloud & virtualization;                                 software & firmware