October 8, 2024

The initial public draft of NIST Internal Report (IR) 8539, Security Property Verification by Transition Model, is now available for public comment. The public comment period is open through November 25, 2024.

August 14, 2024

NIST has released the initial public draft of Interagency Report (IR) 8532, Workshop on Enhancing Security of Devices and Components Across the Supply Chain. The comment period closes September 16, 2024.

January 30, 2024

The initial public draft of NIST Internal Report (IR) 8504, Access Control on NoSQL Databases, is now available for public comment. The deadline to submit comments is March 15, 2024.

May 10, 2024

NIST IR 8498 initial public draft, "Cybersecurity for Smart Inverters: Guidelines for Residential and Light Commercial Solar Energy Systems," is open for comment through June 10, 2024.

October 7, 2024

Initial Public Draft (IPD) NIST IR 8480, Attribute Validation Services for Identity Management, is available for public comment through Friday, November 8, 2024.

September 16, 2024

The initial public draft (ipd) of NIST Interagency Report (IR) 8446, Bridging the Gap between Standards on Random Number Generation: Comparison of SP 800-90 Series and AIS 20/31, is now available for public comment through December 20, 2024.

December 24, 2024

NIST indicated its interest in vetting another Rijndael variant for approval: Rijndael with 256-bit blocks (i.e., Rijndael-256) with a single key size of 256-bits. NIST plans to develop a draft standard for Rijndael-256 over the next year and requests public comments on this plan by June 25, 2025.

AITalks

Apr 24, 2025

Waldorf Astoria, Washington D.C.

Register
The National Institute of Standards and Technology will host a developer conference on Tuesday, March 25, and Wednesday, March 26, 2025. The event will focus on the macOS Security Compliance Project (mSCP) and is tailored for vendors developing
January 3, 2025

NIST has released the initial public draft (IPD) of Revision 1 of NIST Special Publication (SP) 800-189, Border Gateway Protocol Security and Resilience. The public comment period ends February 25, 2025.

November 8, 2024

The initial public draft of Special Publication (SP) 800-232, Ascon-Based Lightweight Cryptography Standards for Constrained Devices: Authenticated Encryption, Hash, and Extendable Output Functions is available for public comment through February 7, 2025.

December 5, 2024

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the draft of the practice guide, Implementing a Zero Trust Architecture (NIST SP 1800-35), for public comment. The public comment period is open through January 31, 2025.

December 11, 2024

NIST's Crypto Publication Review Board has requested initial public comments on NIST Special Publications (SP) 800-56A, 800-56B, and 800-56C, in the "Recommendations for Key Establishment" subseries. The comment period is open through January 31, 2025.

December 16, 2024

The second public draft of NIST Internal Report (IR) 8467, "Genomic Data Cybersecurity and Privacy Frameworks Community Profile" and the initial public draft of NIST Cybersecurity White Paper (CSWP) 35, "Cybersecurity Threat Modeling the Genomic Data Sequencing Workflow" are open for public comment through January 30, 2025.

November 21, 2024

The NIST Privacy Framework Team is pleased to announce the release of the NIST Privacy Workforce Taxonomy, Initial Public Draft (IPD)! We welcome stakeholder feedback on the Workforce Taxonomy IPD by January 17, 2025.

Speakers: Karen Wetzel NICE Framework Manager NICE Additional speakers to be announced. Synopsis: When the NICE Workforce Framework for Cybersecurity (NICE Framework) was published as NIST Special Publication 800-181 in 2017, there was input from the
November 15, 2024

NIST's Crypto Publication Review Board has requested initial public comments on NIST Special Publication 800-102, Recommendation for Digital Signature Timeliness. The comment period is open through January 14, 2025.

November 12, 2024

The initial public draft of NIST Internal Report (IR) 8547,  Transition to Post-Quantum Cryptography Standards, is now available for public comment. The public comment period is open through January 10, 2025.

November 13, 2024

The initial public draft (ipd) of NIST Special Publication (SP) 800-172 Revision 3, Enhanced Security Requirements for Protecting Controlled Unclassified Information (CUI), is available for comment. The public comment period is open through January 10, 2025.

November 14, 2024

The final public drafts (fpd) of NIST Special Publication (SP) 800-157 Revision 1, Guidelines for Derived Personal Identity Verification (PIV) Credentials, and SP 800-217, Guidelines for Personal Identity Verification (PIV) Federation, are now available for public review and comment. The public comment period for both final drafts are open through January 10, 2025.

November 7, 2024

The NCCoE has released for public comment the draft of NIST Cybersecurity White Paper (CSWP) 34, Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration. The comment period for the draft is now open through January 6, 2025.

I have an employee who recently retired from the military in a relevant position raising questions about why we make it painful to access information from BYOD. Namely, the Navy's Flankspeed M365 system allows users to access DoD SharePoint that contains CUI from BYOD with the conditional access restriction that prevents downloads. So they can use the web apps in a browser to view and edit CUI documents from an unmanaged device without any virtualized container or VPN.

My understanding was that the DoD had to meet the same NIST 800-171 standards at a minimum as a requirement by congress. If that is the case, is this an option for contractors? How would I address about half of the controls in the SSP that are suddenly not applicable (even though they claim every control is applicable)? Do I just claim a PC is an alternative worksite, or how is the Navy pulling that off?

submitted by /u/imscavok
[link] [comments]

With the recent release of the CMMC final rule, I'm looking for clarity on the amendments to 48CFR. Could anyone help outline the key changes, critical deadlines, and the detailed descriptions of the phases and levels involved?

submitted by /u/CryThis6167
[link] [comments]
Loading ...