* NIST keeps cranking out security documents
endif; ?>The folks at the National Institute of Standards and Technology Computer Security Resource Center very kindly send me notices of new publications, so here are some recent documents that will interest readers.
I’ve edited and shortened the descriptions from NIST but am not bothering with quotation marks and other details. Each of the following is a “NIST Special Publication.”
DRAFT: Computer Security Incident Handling Guide
Helpful for both established and newly formed incident-response teams. Topics include:
1) Organizing a computer security incident response capability.
2) Establishing incident response policies and procedures.
3) Structuring an incident response team.
4) Handling incidents from initial preparation through the post-incident lessons-learned phase.
Finally, it discusses handling a range of incidents, such as denial of service, malicious code, unauthorized access, inappropriate usage, and multiple component incidents.
https://csrc.nist.gov/publications/drafts/draft_sp800-61.pdf
Other draft security publications from the NIST CSRC are available at:
https://csrc.nist.gov/publications/drafts.html
Guide to Information Technology Security Services
Helps in the selection, implementation, and management of IT security services by guiding organizations through the various phases of the IT security services life cycle, from initiation to closeout. Topics include:
* Type of service arrangement.
* Service provider qualifications, operational requirements and capabilities, experience, and viability.
* Trustworthiness of service provider employees.
* Service provider’s ability to deliver adequate protection for the organization systems, applications and information.
https://csrc.nist.gov/publications/nistpubs/800-35/NIST-SP800-35.pdf
Guide to Selecting Information Security Products
Defines broad security product categories, specifies product types within those categories, and then provides a list of general characteristics and questions an organization can ask when selecting a product.
https://csrc.nist.gov/publications/nistpubs/800-36/NIST-SP800-36.pdf
Guideline on Network Security Testing
Identifies network testing requirements and how to prioritize testing activities with limited resources. Describes several network security testing techniques and tools. Focuses on the basic information about techniques and tools for individuals and going on to the system development life cycle.
https://csrc.nist.gov/publications/nistpubs/800-42/NIST-SP800-42.pdf
Building an Information Technology Security Awareness and Training Program
Detailed guidance on designing, developing, implementing, and maintaining an agency security awareness and training program.
https://csrc.nist.gov/publications/nistpubs/800-50/NIST-SP800-50.pdf
Security Considerations in the Information System Development Life Cycle
This guides seeks to help organizations select and acquire cost-effective security controls by explaining how to include information system security requirements in the SDLC.
https://csrc.nist.gov/publications/nistpubs/800-64/NIST-SP800-64.pdf
Good reading, everyone!




