Date Published: September 29, 2021
Comments Due: November 1, 2021 (public comment period is CLOSED)
Email Questions to: sp800-204c-comments@nist.gov
The newest generation of software applications—"cloud-native applications"—is a class with various functional layers, such as transaction logic, application services, infrastructure resources, policy enforcement, and monitoring of states. The unique architecture of this application class requires a more agile software life cycle paradigm, and DevSecOps (development, security, and operations) offers faster deployment and updates, while integrating security throughout the life cycle.
Draft NIST SP 800-204C provides guidance for the implementation of DevSecOps primitives for a reference platform hosting a cloud-native application with the functional layers described above. The guidance also discusses the benefits of this approach for high security assurance and enabling continuous authority to operate (C-ATO).
NOTE: A call for patent claims is included on page iii of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.
None selected
Publication:
SP 800-204C (Draft) (DOI)
Local Download
Supplemental Material:
None available
Document History:
09/29/21: SP 800-204C (Draft)
03/08/22: SP 800-204C (Final)
Security and Privacy
general security & privacy; security programs & operations
Technologies
cloud & virtualization; software & firmware