Use this form to search content on CSRC pages.
A second public draft of NIST SP 800-207, "Zero Trust Architecture," is available for comment. The comment period closes March 13, 2020.
NIST solicits feedback on Draft NISTIR 8246, National Vulnerability Database (NVD) Metadata Submission Guidelines for Common Vulnerabilities and Exposures (CVE) Numbering Authorities (CNAs) and Authorized Data Publishers. Comments are due March 20, 2020.
NIST is initiating an update of Special Publication (SP) 800-161, "Supply Chain Risk Management Practices for Federal Information Systems and Organizations," seeking preliminary comments on possible clarifications, additions, and removal of information. Comments are due by February 28, 2020.
Draft NISTIR 8276, "Key Practices in Cyber Supply Chain Risk Management: Observations from Industry” is available for comment; the comment period closes March 4, 2020. Six new Case Studies in Cyber SCRM are also available, along with a "Summary of Findings and Recommendations."
NIST has released Draft NISTIR 8278, "National Cybersecurity Online References (OLIR) Program: Guidance for OLIR Users and Developers." Public comments are due by February 24, 2020.
NIST has released Draft NIST Special Publication (SP) 800-204A, "Building Secure Microservices-based Applications Using Service-Mesh Architecture," for comment. The public comment period ends February 14, 2020.
NIST has published the Cybersecurity White Paper "A Taxonomic Approach to Understanding Emerging Blockchain Identity Management Systems."
NIST has released Draft Special Publication (SP) 800-137A, "Assessing Information Security Continuous Monitoring (ISCM) Programs: Developing an ISCM Program Assessment." Public comments are due by February 28, 2020.
NIST has released the second public draft of NISTIR 8259, "Recommendations for IoT Device Manufacturers: Foundational Activities and Core Device Cybersecurity Capability Baseline." The public comment period ends February 7, 2020.
NIST has published Special Publication (SP) 800-189, "Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation," which superseded SP 800-54, "Border Gateway Protocol Security."
NIST has released Draft NIST Special Publication (SP) 800-208, "Recommendation for Stateful Hash-Based Signature Schemes." The public comment period ends February 28, 2020.
NIST has released Special Publication (SP) 800-160 Volume 2, "Developing Cyber Resilient Systems: A Systems Security Engineering Approach."
NIST has released Draft NISTIR 8011 Volume 4, "Automation Support for Security Control Assessments: Software Vulnerability Management," for public comment. The comment period ends December 20, 2019.
NIST has released Draft NISTIR 8214A, "Towards NIST Standards for Threshold Schemes for Cryptographic Primitives: A Preliminary Roadmap," for public comment. The comment period closes February 10, 2020.
Digital signature algorithms and elliptic curves: NIST is requesting comments on two drafts that specify digital signature algorithms (Draft FIPS 186-5) and NIST-recommended elliptic curves (Draft SP 800-186). The public comment period ends January 29, 2020.
The NCCoE has released Draft NISTIR 8269, "A Taxonomy and Terminology of Adversarial Machine Learning," for public comment. Comments are due by January 30, 2020.
NIST has released a second public draft of Special Publication 800-189, "Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation." The public comment period closes November 15, 2019.
NIST has updated Special Publication (SP) 800-128, "Guide for Security-Focused Configuration Management of Information Systems"
NIST has released the Draft Special Publication (SP) 800-140x subseries for public comment. They directly support FIPS 140-3 and the Cryptographic Module Validation Program (CMVP). Comments are due by December 9, 2019.
NIST releases Draft SP 800-57 Part 1 Revision 5, "Recommendation for Key Management: Part 1 – General," for public comment. Comments are due by December 6, 2019.
NIST publishes NISTIR 8268, "Status Report on the First Round of the NIST Lightweight Cryptography Standardization Process."
NIST has released a draft of NISTIR 8267, "Security Review of Consumer Home Internet of Things (IoT) Products," for public comment. The comment period closes November 1, 2019.
NIST has published NISTIR 8183A (3 volumes), "Cybersecurity Framework Manufacturing Profile Low Impact Level Example Implementations Guide."
The NCCoE has released Draft SP 1800-23, "Energy Sector Asset Management," for public comment. The comment period ends November 25, 2019.
NIST has released Draft Special Publication (SP) 800-207, Zero Trust Architecture. Public comments are due by November 22, 2019.