Showing posts with label nist. Show all posts
Showing posts with label nist. Show all posts

Wednesday, September 05, 2018

✏️ RFC NIST :: Draft Cybersecurity Practice Guide SP 1800-14, Protecting the Integrity of Internet Routing: Border Gateway Protocol (BGP) Route Origin Validation, is Available for Comment

"It is difficult to overstate the importance of the internet to modern business and society in general. The internet is not a single network, but rather a complex grid of independent interconnected networks that relies on a protocol known as Border Gateway Protocol (BGP) to route traffic to its intended destination.
Unfortunately, BGP was not designed with security in mind and a route hijack attack can deny access to internet services, misdeliver traffic to malicious endpoints, and cause routing instability. A technique known as BPG route origin validation (ROV) is designed to protect against route hijacking.
"NIST’s National Cybersecurity Center of Excellence (NCCoE), together with several technology vendors, has developed proof-of-concept demonstrations of BGP ROV implementation designed to improve the security of the internet's routing infrastructure. 
"Comments for this draft are due by October 15, 2018. To review Draft Special Publication (SP) 1800-14, and for information on submitting comments, please visit the links below.

Friday, August 19, 2016

RFC :: NIST Report on Lightweight Cryptography

NIST Released Draft NIST Internal Report (NISTIR) 8114, Report on Lightweight Cryptography, for public comment.
Link to the DRAFT NISTIR 8114 document and also to the announcement can be found on the CSRC Drafts Publications page:
Send comments to:

Deadline to submit comments: October 31, 2016.

Thursday, June 09, 2016

:: NIST RFC :: Guide for Cybersecurity Event Recovery

Jun. 6, 2016
SP 800-184
DRAFT Guide for Cybersecurity Event Recovery
NIST Draft Special Publication 800-184, Guide for Cybersecurity Event Recovery, is available for public comment. The purpose of this document is to support federal agencies in a technology-neutral way in improving their cyber event recovery plans, processes, and procedures. This publication provides tactical and strategic guidance regarding the planning, playbook developing, testing, and improvement of recovery planning. It also provides an example scenario that demonstrates guidance and informative metrics that may be helpful for improving resilience of the information systems.

The public comment period closes on July 11, 2016. Send comments to: csf-recover@nist.gov.

See second link below for the Comment Template for Draft SP 800-184
Draft SP 800-184
Comment Template for Draft SP 800-184

Thursday, May 12, 2016

:: NIST Cybersecurity Meetings

Earlier this year we (NIST Computer Security Division) had posted an event, on the NIST CSRC website; that was going to take place on May 19-20, 2016.  We received several emails from subscribers asking what happened to this event - High-Performance Computing Security Workshop.
The event has been postponed until later this year (September-October).  We are hoping to have updated information posted to the CSRC website between June-July.  We will also send a follow-up email to this mailing list once details have been finalized.
Upcoming Events:
Open Meeting of the Commission on Enhancing National Cybersecurity
May 16, 2016
Vanderbilt Hall at the New York University (NYU) School of Law, Center on Law and Security
Trustworthy Suppliers Framework Forum
May 25, 2016
NIST, Gaithersburg, MD

Thursday, January 28, 2016

:: NIST Requests Comments on Computer Security Publication on Randomness

"The National Institute of Standards and Technology (NIST) is seeking public comment on its latest draft of a publication intended to help computer security experts use randomness to protect sensitive data.
Television with fuzzy screen 
Thermal noise is one of the physical phenomena that can be used as a source of randomness, and it helps to create the visual representation of “snow” that was once a familiar sight to owners of analog televisions.
Credit: ©Shutterstock/trekandshoot
The Second Draft of Special Publication (SP) 800-90B, Recommendation for the Entropy Sources Used for Random Bit Generation, aims to help security specialists judge whether the source of random numbers they use as part of the data encryption process is sufficiently unpredictable. NIST is requesting public comments by May 9, 2016, on the draft document, which is available at NIST’s CSRC website.
Random numbers are a crucial element in cryptography, which is often used to protect private messages by encrypting them into a form that cannot be understood without knowledge of a secret value generated using the random number.
Creating the randomness needed requires the use of an entropy source, which includes a natural source of entropy, often a physical phenomenon such as thermal noise—the random motions of particles due to their temperature. Entropy sources that comply with SP 800-90B are intended to provide assurance that cryptographic algorithms provide the security needed to protect information.
“This draft document proposes a lot of tests that you can use to validate your entropy source to tell you how good a job it is doing,” says NIST’s Elaine Barker, one of the publication’s authors. “When you’re assessing your process for generating randomness, you want to make sure nothing is broken and that it is performing consistently. We would like the public’s input on ways we can improve these tests.”
The document is one of three interrelated publications that NIST has been developing: The first, SP 800-90A Rev. 1, specifies several random-number generation algorithms, all of which require an entropy source to provide a complete random number generator. SP 800-90B helps to assess an entropy source’s performance. The third publication, SP 800-90C, shows users how to combine the algorithms in SP 800-90A and the entropy sources in SP 800-90B into effective random-number generators.
Barker says that the team is also planning a public workshop to discuss both SP 800-90B and -90C. The workshop (preliminary announcement here) will be held on NIST’s Gaithersburg, Md., campus on May 2-3, 2016. Registration will be required. “We hope to have an updated draft version of SP 800-90C posted online before the workshop as well,” she says.
When completed, NIST’s Cryptographic Algorithm Validation Program (CAVP) and Cryptographic Module Validation Program (CMVP) plan to validate entropy sources using the tests and requirements provided in SP 800-90B.
SP 800-90B is available for free download here. To submit comments, use the provided template and send them with subject line “Comments on Draft SP 800-90B” to rbg_comments@nist.gov by May 9, 2016. Submissions received by the deadline will be used to improve the document, which is now undergoing its second public comment review.


Tuesday, January 26, 2016

:: Influence the Future of Cybersecurity Education—Join the NICE Working Group

"Addressing the nation’s rapidly increasing need for cybersecurity employees, the National Initiative for Cybersecurity Education (NICE) is seeking members from the public and private sectors and academia to join its new working group and encourages interested individuals to participate in a kickoff teleconference the afternoon of January 27, 2016.


NICE Logo 
"NICE, which is led by the National Institute of Standards and Technology (NIST), is a public-private partnership that promotes a robust network of cybersecurity education, training and workforce development to meet the nation’s demand for skilled cybersecurity employees to protect information systems. The number of job openings in the field greatly exceeds the number of trained workers. The NICE Working Group will collaborate to develop concepts, design strategies and pursue actions to advance cybersecurity education, including sharing existing education initiatives and identifying new ones.
The working group has chairs representing academia, private industry and government, and will have six subgroups:
  • Collegiate,
  • Competitions,
  • Workforce Framework,
  • Training and Certifications,
  • Career Development and Workforce Planning, and
  • Kindergarten through 12th Grade.
The kickoff teleconference is Wednesday, January 27, from 3:30 to 5 p.m. ET. NICE program leaders will discuss group goals, member roles and responsibilities, meeting schedules and deadlines. The meetings are planned for the fourth Wednesday of each month.
For more information on the public working group, visit the working group page. For call-in numbers for the teleconference, email nice.nist@nist.gov.

http://www.nist.gov/itl/acd/influence-the-future-of-cybersecurity-education-join-nice-working-group.cfm

Wednesday, October 28, 2015

:: NIST Seeks Comments on New Project Aimed at Protecting Privacy Online

The National Cybersecurity Center of Excellence (NCCoE), in partnership with the National Strategy for Trusted Identities in Cyberspace National Program Office, is seeking comments on a new project focused on protecting privacy and security when reusing credentials at multiple online service providers.
Many organizations now allow online customers to use third-party credentials to create and manage accounts and services. For example, your social media account login can be used to access your fitness tracker account. In effect, the social media company is vouching for you with the tracker company.
Allowing third-party credentials saves businesses time and resources in managing identities. For users, the benefit comes from not having yet another username and password to manage and remember.
As these arrangements become more common, a growing number of organizations are laboring to manage—and integrate—each third-party relationship. So now a new service, called brokered identity management, has emerged. Organizations can engage identity brokers to manage multiple third-party credentialing options on their behalf.
The benefits to organizations and individuals are significant, but there is also a concern that these connections meant to improve security can create opportunities for increased tracking of users.
This new collaborative project will examine how commercially available privacy-enhancing technologies can be integrated into identity broker solutions. The NCCoE is seeking comments on a draft document that describes a potential “building block”—one of a series of solutions that address cybersecurity concerns for multiple industry sectors. The document, Privacy-Enhanced Identity Brokers, describes the technical challenges of adding privacy-enhancing technologies to existing products or services, and the technical controls needed to address the privacy risks inherent in them.
Feedback from businesses and the public will inform the project and solution development. This will ultimately result in an 1800-series NIST Cybersecurity Practice Guide that will demonstrate the example solution and provide all the information necessary to replicate the reference design.
The NCCoE addresses businesses' most pressing cybersecurity problems with practical, standards-based solutions using commercially available technologies. The center collaborates with industry, academic and government experts to build modular, open, end-to-end reference designs that are broadly applicable and repeatable.
The document can be viewed on the NCCoE website. Comments should be submitted to via a web form or to petid-nccoe@nist.gov by Dec. 18, 2015.

:: NIST to Support Cybersecurity Jobs “Heat Map” to Highlight Employer Needs and Worker Skills

"WASHINGTON, DC – As part of the U.S. Department of Commerce’s “Skills for Business” initiative, the National Institute of Standards and Technology (NIST) is funding the development of a visualization tool that will show the demand for and availability of critical cybersecurity jobs across the nation. The project, funded through NIST’s National Initiative for Cybersecurity Education (NICE), will provide data to help employers, job seekers, policy makers, training providers, and guidance counselors in order to meet today’s increasing demand for cybersecurity workers. 

"In partnership with job market analytics and research firm Burning Glass Technologies, CompTIA, a non-profit trade association for IT professionals and organizations, has received a three-year grant to conduct extensive research and create a “heat map” that visualizes the need for, and supply of, cybersecurity workers across the country. Heat maps are a popular data visualization tool that, in this case, will use varying shades of color to show relative differences in the geographic concentration of supply and demand. CompTIA has been awarded $249,000 in first-year funding. "


Friday, October 09, 2015

:: Email. The modern working world cannot exist without it, but hackers exploit this vital service to steal money and valuable information. The National Institute of Standards and Technology (NIST) is tackling this threat with two new projects. hand on keyboard Credit: ©Fotolia.com NIST is publishing a draft document for comment that provides guidelines to enhance trust in email. And the National Cybersecurity Center of Excellence (NCCoE) is seeking collaborators to provide products and expertise to demonstrate a secure, standards-based email system using commercially available software and other tools. In the early, halcyon days of the Internet, researchers were more interested in sharing information rather than securing it. Now, decades later, securing the world’s most widely used medium for business communication is a full-time job for researchers and IT specialists around the globe. “The two main threats to current email services are phishing and leaking confidential information,” explains computer scientist Scott Rose. In phishing, hackers use forged emails to trick email users to unknowingly provide valuable data such as bank account numbers. In other scams, addressees are lured into clicking on a link that downloads malicious code, which can home in on an organization’s most valuable data like a heat-seeking missile or steal personal information. Hackers can also intercept email messages to learn an organization’s proprietary information, or tamper with the information in the message before it is delivered to the recipient. In the draft Trustworthy Email (NIST Special Publication (SP) 800-177), authors provide an overview of existing technologies and best practices, and they offer deployment guidance to meet federal government security requirements. Emerging protocols to make email security and privacy easier for end users also are described. While there are two basic threats to email, there are multiple ways to exploit both, Rose says. Trustworthy Email suggests solutions to address all common exploits. To reduce the risk of spoofing, for example, the authors suggest that organizations use techniques to authenticate domain names used to send emails, and that employees or members digitally sign email. For confidential email, organizations can encrypt email between sender and receiver or secure the transmission between email servers. Trustworthy Email is written for enterprise email administrators, information security specialists and network managers. The document applies to federal IT systems, but can be used in other organizations. The publication is designed to complement NIST’s earlier document, Guidelines on Electronic Mail Security, NIST SP 800-45 version 2. The authors seek input on the draft document. The deadline for comments on Trustworthy Email, SP 800-177, is November 30, 2015. Please send any questions or comments to sp800-177@nist.gov. At the same time, the NCCoE is seeking collaborators to provide products and technical expertise during a project that will demonstrate a secure email system. The NCCoE’s Domain Name System (DNS) Based Secured Email project will lead to a publicly available NIST Cybersecurity Practice Guide. The guide will explain how to employ and build a platform to meet federal and industry security and privacy requirements using commercially available tools and components. More information is available in a recent white paper. If you are interested in participating, details are provided in Federal Register Notice Document 2015-25304. Letters of interest will be accepted on a first-come, first-served basis. Those selected to participate will enter into a Cooperative Research and Development Agreement with NIST. The NCCoE is a partnership of NIST, the State of Maryland and Maryland's Montgomery County. The center is dedicated to furthering rapid adoption of practical, standards-based cybersecurity solutions for businesses and public organizations using commercially available and open-source technologies.

Email. The modern working world cannot exist without it, but hackers exploit this vital service to steal money and valuable information. The National Institute of Standards and Technology (NIST) is tackling this threat with two new projects.
NIST is publishing a draft document for comment that provides guidelines to enhance trust in email. And the National Cybersecurity Center of Excellence (NCCoE) is seeking collaborators to provide products and expertise to demonstrate a secure, standards-based email system using commercially available software and other tools. In the early, halcyon days of the Internet, researchers were more interested in sharing information rather than securing it. Now, decades later, securing the world’s most widely used medium for business communication is a full-time job for researchers and IT specialists around the globe. “The two main threats to current email services are phishing and leaking confidential information,” explains computer scientist Scott Rose. In phishing, hackers use forged emails to trick email users to unknowingly provide valuable data such as bank account numbers. In other scams, addressees are lured into clicking on a link that downloads malicious code, which can home in on an organization’s most valuable data like a heat-seeking missile or steal personal information. Hackers can also intercept email messages to learn an organization’s proprietary information, or tamper with the information in the message before it is delivered to the recipient. In the draft Trustworthy Email (NIST Special Publication (SP) 800-177), authors provide an overview of existing technologies and best practices, and they offer deployment guidance to meet federal government security requirements. Emerging protocols to make email security and privacy easier for end users also are described. While there are two basic threats to email, there are multiple ways to exploit both, Rose says. Trustworthy Email suggests solutions to address all common exploits. To reduce the risk of spoofing, for example, the authors suggest that organizations use techniques to authenticate domain names used to send emails, and that employees or members digitally sign email. For confidential email, organizations can encrypt email between sender and receiver or secure the transmission between email servers. Trustworthy Email is written for enterprise email administrators, information security specialists and network managers. The document applies to federal IT systems, but can be used in other organizations. The publication is designed to complement NIST’s earlier document, Guidelines on Electronic Mail Security, NIST SP 800-45 version 2. The authors seek input on the draft document. The deadline for comments on Trustworthy Email, SP 800-177, is November 30, 2015. Please send any questions or comments to sp800-177@nist.gov. At the same time, the NCCoE is seeking collaborators to provide products and technical expertise during a project that will demonstrate a secure email system. The NCCoE’s Domain Name System (DNS) Based Secured Email project will lead to a publicly available NIST Cybersecurity Practice Guide. The guide will explain how to employ and build a platform to meet federal and industry security and privacy requirements using commercially available tools and components. More information is available in a recent white paper. If you are interested in participating, details are provided in Federal Register Notice Document 2015-25304. Letters of interest will be accepted on a first-come, first-served basis. Those selected to participate will enter into a Cooperative Research and Development Agreement with NIST. The NCCoE is a partnership of NIST, the State of Maryland and Maryland's Montgomery County. The center is dedicated to furthering rapid adoption of practical, standards-based cybersecurity solutions for businesses and public organizations using commercially available and open-source technologies.

Tuesday, September 01, 2015

:: NIST Cyber Supply Chain Risk Management Workshop, October 1-2, 2015

NIST Invites Industry to Cyber Supply Chain Risk Management Workshop, October 1-2, 2015

From NIST Tech Beat: September 1, 2015Contact: Evelyn Brown 
301-975-5661
"The National Institute of Standards and Technology (NIST) will host a workshop on industry best practices in cyber supply chain risk management at its Gaithersburg, Md., campus, October 1-2, 2015.
continents connected by chains
Credit: ©freshidea-Fotolia_com
View hi-resolution image
"The two-day event will feature panels of industry professionals. Topics will include how cyber supply chain risk can affect organizations, proven strategies for managing those risks, existing standards and best practices, and practical guidance for enterprise risk governance.
"The Cyber Supply Chain Risk Management workshop is designed for a broad audience, including senior executives and those involved in enterprise risk management, supply chain management, acquisition or cybersecurity.
The goals of the workshop are to:
• share current research findings,
• validate the current findings and receive additional input from stakeholders, and
• gather input to inform future versions of the Framework for Improving Critical Infrastructure Cybersecurity and other cybersecurity and supply chain risk management initiatives.
NIST developed the framework, commonly referred to as the Cybersecurity Framework, as directed in Executive Order 13636 to assist critical infrastructure organizations to better manage and reduce their cybersecurity risks. NIST also released a companion document, Roadmap for Improving Critical Infrastructure Cybersecurity, which identifies supply chain risk management as a key focus area.
NIST has a Supply Chain Risk Management Program focused on securing the information and communications technology supply chain.
Registration information and the agenda are available here.

Saturday, August 22, 2015

:: NIST Hosts 2015 Cybersecurity Innovation Forum, Sept. 9-11 in D.C.

NIST Hosts 2015 Cybersecurity Innovation Forum, Sept. 9-11 in D.C.

From NIST Tech Beat: August 17, 2015


Contact: Evelyn Brown 
301-975-5661
"The National Institute of Standards and Technology (NIST) will host the 2015 Cybersecurity Innovation Forum on Sept. 9 to 11, 2015, at the Walter E. Washington Convention Center in Washington, D.C.
hacker
Credit: © ra2 studio/Fotolia.com
"At this annual meeting, government, industry and university representatives come together to focus on current, emerging and future challenges in areas such as trusted computing, security automation and information sharing. Leading cybersecurity researchers and executives from the cybersecurity industry will participate in the event.
"The forum’s four tracks—security automation, trusted computing, information sharing and cybersecurity research—will be interspersed with general sessions. Session topics include federal research and privacy, risk management and liability. The event will conclude with a review of the challenges and gaps discussed during the forum and next steps in collaborative efforts to resolve them.
"Presentations will cover Windows 10 security, cryptography, derived PIV credentials proof of concept, public safety cybersecurity, security and the Internet of Things, the NIST Privacy Risk Management Framework and augmenting Federal Information Security Management Act (FISMA) practices with the Cybersecurity Framework.
"The forum also will feature demonstrations and an industry expo on Sept. 9 and 10.
"The agenda is available online. Register for the 2015 Cybersecurity Innovation Forum at: https://www.fbcinc.com/e/cif/attendeereg.aspx.

Thursday, August 13, 2015

RFC :: Interagency Report Advocates Support for International Cybersecurity Standardization

"NIST seeks public comments on Draft NIST Interagency Report (NISTIR) 8074, which comprises two volumes, "Report on Strategic U.S. Government Engagement in International Standardization to Achieve U.S. Objectives for Cybersecurity" (Vol. 1) and "Supplemental Information" (Vol. 2).

"Please send comments to nistir8074@nist.gov (Subject: “Comments on Draft NISTIR 8074”). The public comment period closes September 24, 2015. Those responding are encouraged to use the Comments Templates provided below.
Volume 1: Report
Comment Template for Volume 1
Volume 2: Supplemental Information for the Report
Comment Template for Volume 2


Interagency Report Advocates Support for International Cybersecurity Standardization From NIST Tech Beat: August 11, 2015

"A new draft report by an interagency working group lays out objectives and recommendations for enhancing the U.S. government's coordination and participation in the development and use of international standards for cybersecurity. The report recommends the government make greater effort to coordinate the participation of its employees in international cybersecurity standards development to promote the cybersecurity and resiliency of U.S. information and communications systems and supporting infrastructures. These efforts should include increased training, collaborating with private industry and working to minimize risks to privacy.
shutterstock_2156795_Norebbo_LR
Credit: Norebbo/Shutterstock
"The Cybersecurity Enhancement Act of 2014 directed the National Institute of Standards and Technology (NIST) to work with relevant federal agencies to ensure interagency coordination in "the development of international technical standards related to information system security" and to "ensure consultation with appropriate private sector stakeholders." It also called for NIST to within one year submit a plan to Congress for ensuring that coordination. The International Cybersecurity Standards Working Group, led by the Department of Commerce and NIST, was set up by the National Security Council's Cyber Interagency Policy Committee to draft this report, which will also serve as the basis of the required report to Congress. Public comments on the draft report are due by September 24, 2015.
The draft report outlines four U.S. government strategic objectives for the development and use of international standards for cybersecurity:
  • Enhancing national and economic security and public safety
  • Ensuring standards and assessment tools for the U.S. government are technically sound
  • Facilitating international trade
  • Promoting innovation and competitiveness
The draft report then lays out eight recommendations for how the federal government can achieve those objectives, including by ensuring coordination across the government and collaboration with the private sector and internationally, and promoting federal agency participation in international standards development and federal use of international standards and assessment schemes.
The U.S. standards system differs significantly from the government-driven, centrally coordinated systems common in many other countries. Under the U.S. system, hundreds of standards development organizations (SDOs) provide the infrastructure for the preparation of standards documents. While these organizations are overwhelmingly private sector, government personnel participate in standards development activities along with representatives from industry, academia, and other organizations and consumers.
A supplement to the draft report provides a summary of ongoing activities in critical international cybersecurity standardization and an inventory of U.S. government and private-sector engagement. It also provides guidance for agencies to plan and coordinate more effective participation in these activities.
The working group's draft report supports the 2010 United States Standards Strategy, which was developed through a public-private partnership and outlines the contribution of private-sector led standards development to overall competition and innovation in the U.S. economy and the imperative of public and private-sector participation and collaboration.
The full Report on Strategic U.S. Government Engagement in International Standardization to Achieve U.S. Objectives for Cybersecurity [NISTIR 8074 Volume 1 (Draft)] and supplement [NISTIR 8074 Volume 2 (Draft)] can be found on the NIST website.

Tuesday, July 21, 2015

NIST RFC :: Trusted Geolocation in the Cloud

July 15, 2015
NIST IR 7904
DRAFT (Second Draft) Trusted Geolocation in the Cloud: Proof of Concept Implementation
NIST announces the second public comment release of Interagency Report (IR) 7904, Trusted Geolocation in the Cloud: Proof of Concept Implementation. This report describes a proof of concept implementation that was designed by NIST to address challenges with Infrastructure as a Service (IaaS) cloud technologies and geolocation. Since the initial public comment release, NIST IR 7904 has been extensively updated to reflect advances and changes in the proof of concept implementation technologies.

Please submit comments by August 24, 2015 to ir7904-comments@nist.gov, with "IR 7904 Comments" in the subject line.
Second Draft NISTIR 7904 (2.7 MB)
Comment Template Form for NISTIR 7904

Friday, July 05, 2013

RFC :: NIST :: Draft Outline of Cybersecurity Framework for Critical Infrastructure :: Commets Due July 10th

NIST has released a draft outline of the Cybersecurity Framework in preparation for the upcoming July 10th Cybersecurity Framework Workshop in San Diego.  Comments are requested on or before the workshop.
NIST Tech Beat July 2, 2013: As part of its efforts to develop a voluntary framework to improve cybersecurity in the nation's critical infrastructure, the National Institute of Standards and Technology (NIST) has posted a draft outline of the document to invite public review and gather comments.
The Executive Order calling for NIST to develop the framework directs the agency to collaborate with the public and private sectors. The draft outline reflects input received in response to a February 2013 Request for Information, discussions at two workshops and other forms of stakeholder engagement.
The outline proposes a core structure for the framework and includes a user's guide and an executive overview that describes the purpose, need and application of the framework in business. Reflecting received comments that emphasized the importance of executive involvement in managing cyber risks, the framework is designed to help business leaders evaluate how prepared their organizations are to deal with cyber threats and their impacts.
"We are pleased that many private-sector organizations have put significant time and resources into the framework development process," said Adam Sedgewick, senior information technology policy advisor at NIST. "We believe that both large and small organizations will be able use the final framework to reduce cyber risks to critical infrastructure by aligning and integrating cybersecurity-related policies and plans, functions and investments into their overall risk management."
NIST also released a draft compendium of informative references composed of existing standards, practices and guidelines to reduce cyber risks to critical infrastructure industries. This material was released to foster discussion at upcoming workshops and to further encourage private-sector input before NIST publishes the official draft Cybersecurity Framework for public comment in October 2013.
Interested parties are invited to review the draft framework outline and offer comments before and during the next workshop, July 10-12, 2013, in San Diego. Direct comments should be forwarded to cyberframework@nist.gov. The draft outline and other documents related to the Cybersecurity Framework are available at http://www.nist.gov/itl/cyberframework.cfm.

Wednesday, February 29, 2012

RFC :: NIST :: #FISMA SP 800-53 Security and Privacy Controls for Federal Info Systems and Orgs :: Comments Due Apr 6

From NIST Tech Beat: February 28, 2012 Contact: Evelyn Brown 301-975-5661

"A major revision of a Federal Information Security Management Act (FISMA) publication released today by the National Institute of Standards and Technology (NIST) adds guidance for combating new information security threats and incorporates new privacy controls to the framework that federal agencies use to protect their information and information systems.

"To handle insider threats, supply chain risk, mobile and cloud computing technologies, and other cybersecurity issues and challenges, NIST has released Security and Privacy Controls for Federal Information Systems and Organizations, Special Publication (SP) 800-53, Revision 4 (Initial Public Draft). The document is considered a principal catalog of security standards and guidelines used by federal government agencies that NIST is required to publish by law.

“The changes we propose in Revision 4 are directly linked to the current state of the threat space—the capabilities, intentions and targeting activities of adversaries—and analysis of attack data over time,” explained Ron Ross, FISMA Implementation Project Leader and NIST fellow.

"The revision also adds a new privacy appendix to the publication that provides privacy controls and associated implementation guidance. “Privacy and security are complementary, so we decided to combine them in SP 800-53," said Ross.

"Other areas addressed in the update in addition to those mentioned above include application security, firmware integrity, distributed systems and advanced persistent threat. “Many organizations are concerned about advanced persistent threats, so we added new controls that will allow organizations to use different strategies to combat those types of threats,” Ross added.

"NIST also modified its guidance on security assurance Appendix E, which outlines how agencies can establish measures of confidence that the security controls put in place are providing the necessary security capability to protect critical missions and business operations. Ross explains, “Having security functionality in your information systems without the appropriate assurance is like skydiving without a backup parachute—you don’t need it until you need it. And without it, the outcome is very predictable.”

"As part of the update to SP 800-53, NIST addressed potential gaps in coverage, added new security controls and control enhancements, provided additional supplemental guidance for these controls, and clarified security control requirements and specification language. Keeping the potential threats in mind, the security control baselines were updated and minimum assurance requirements revised.
This document, when finalized, will be used by the entire federal government. The project was conducted as part of the Joint Task Force Transformation Initiative, which is composed of security experts from NIST, the Department of Defense, the Intelligence Community, the Committee on National Security Systems, and the Department of Homeland Security.

The public draft of Security and Privacy Controls for Federal Information Systems and Organizations, Special Publication (SP) 800-53, Revision 4 may be found at http://csrc.nist.gov/publications/PubsDrafts.html#SP-800-53-Rev.%204. Comments on SP 800-53, Revision 4 are requested by April 6, 2012. Email should be sent to sec-cert@nist.gov.

Thursday, November 10, 2011

What is a Cybersecurity Professional, NIST wants to know

So what is a Cybersecurity Professional?  NIST thinks it would be useful to have some sort of standard common means of answering that question, and wants your input:
NICE Issues Cybersecurity Workforce Framework for Public Comment
From NIST Tech Beat: November 8, 2011
Contact: Evelyn Brown
301-975-5661

The National Initiative on Cybersecurity Education (NICE) has published for public comment a draft document that classifies the typical duties and skill requirements of cybersecurity workers. The document is meant to define professional requirements in cybersecurity, much as other professions, such as medicine and law, have done.
NICE is an interagency effort coordinated by the National Institute of Standards and Technology (NIST) and focused on cybersecurity awareness, education, training and professional development. NICE activities include increasing cybersecurity awareness for children and adults of all ages, promoting community college and university-level programs in cybersecurity, and expanding professional training opportunities.
The new document, the NICE Cybersecurity Workforce Framework, was created by the NICE group responsible for creating and maintaining a highly skilled workforce to meet the nation’s computer security needs. Over 20 participating agencies contributed to the group’s efforts.
“One thing NICE has found is that there has not been a consistent way to define or describe cybersecurity work across the federal workforce,” says NICE Lead Ernest McDuffie. Cybersecurity professionals previously have not fit into the standard occupations, job titles, position descriptions and the federal job classification and job grading system managed by the Office of Personnel Management (OPM).
Not having a common language to discuss and understand the work and skill requirements hinders federal employers in setting basic requirements, identifying skill gaps and providing training and professional development opportunities for their workforce. “Other professions have organized their specialties, and now it is time for a common set of definitions for the cybersecurity workforce,” said McDuffie.
The NICE Cybersecurity Workforce Framework provides a working taxonomy, or vocabulary, that is designed to fit into any organization’s existing occupational structure. The framework is based on information gathered from federal agencies through two years of surveys and workshops by OPM, a major Department of Defense study of the cybersecurity workforce and a study by the Federal CIO Council.
In opening the draft document up for public comment, NICE hopes to refine the framework so that it can be useful in both the public and private sectors to better protect the nation from escalating cybersecurity threats. Authors also want the framework to address emerging work requirements to help ensure the nation has the skills to meet them. The authors are requesting input from all of the nation’s cybersecurity stakeholders including academia, professionals, not-for-profit organizations and private industry.
The framework organizes cybersecurity work into high-level categories ranging from the design, operation and maintenance of cybersecurity systems to incident response, information gathering and analysis. The structure is based on job analyses and groups together work and workers that share common major functions, regardless of job title.
To read the document and provide comments, go to http://csrc.nist.gov/nice/framework/. The webpage also provides a template for comments, which are due Dec. 16, 2011.

Wednesday, June 08, 2011

NIST NOI National Strategy for Trusted Identities in Cyberspace NSTIC

NIST Notice of Inquiry: Models for a Governance Structure for the National Strategy for Trusted Identities in Cyberspace

Comments Due on or before July 22, 2011

SUMMARY: The Department of Commerce (Department) is conducting a comprehensive review of governance models for a governance body to administer the processes for policy and standards adoption for the Identity Ecosystem Framework in accordance with the National Strategy for Trusted Identities in Cyberspace (NSTIC or “Strategy”). The Strategy refers to this governance body as the “steering group.” The Department seeks public comment from all stakeholders, including the commercial, academic and civil society sectors, and consumer and privacy advocates on potential models, in the form of recommendations and key assumptions in the formation and structure of the steering group. The Department seeks to learn and understand approaches for: 1) the structure and functions of a persistent and sustainable private sector-led steering group and 2) the initial establishment of the steering group. This Notice specifically seeks comment on the structures and processes for Identity Ecosystem governance. This Notice does not solicit comments or advice on the policies that will be chosen by the steering group or specific issues such as accreditation or trustmark schemes, which will be considered by the steering group at a later date. Responses to this Notice will serve only as input for a Departmental report of government recommendations for establishing the NSTIC steering group.

. . . . .

Written comments may be submitted by mail to the National Institute of Standards and Technology, c/o Annie Sokol, 100 Bureau Drive, Mailstop 8930, Gaithersburg, MD 20899. Electronic comments may be sent to NSTICnoi@nist.gov
. . . . .