New NIST security publications

Opinion
Nov 6, 20033 mins

* NIST keeps cranking out security documents

The folks at the National Institute of Standards and Technology Computer Security Resource Center very kindly send me notices of new publications, so here are some recent documents that will interest readers.

I’ve edited and shortened the descriptions from NIST but am not bothering with quotation marks and other details. Each of the following is a “NIST Special Publication.”

DRAFT: Computer Security Incident Handling Guide

Helpful for both established and newly formed incident-response teams. Topics include:

1) Organizing a computer security incident response capability.

2) Establishing incident response policies and procedures.

3) Structuring an incident response team.

4) Handling incidents from initial preparation through the post-incident lessons-learned phase.

Finally, it discusses handling a range of incidents, such as denial of service, malicious code, unauthorized access, inappropriate usage, and multiple component incidents.

https://csrc.nist.gov/publications/drafts/draft_sp800-61.pdf

Other draft security publications from the NIST CSRC are available at:

https://csrc.nist.gov/publications/drafts.html

Guide to Information Technology Security Services

Helps in the selection, implementation, and management of IT security services by guiding organizations through the various phases of the IT security services life cycle, from initiation to closeout. Topics include:

* Type of service arrangement.

* Service provider qualifications, operational requirements and capabilities, experience, and viability.

* Trustworthiness of service provider employees.

* Service provider’s ability to deliver adequate protection for the organization systems, applications and information.

https://csrc.nist.gov/publications/nistpubs/800-35/NIST-SP800-35.pdf

Guide to Selecting Information Security Products

Defines broad security product categories, specifies product types within those categories, and then provides a list of general characteristics and questions an organization can ask when selecting a product.

https://csrc.nist.gov/publications/nistpubs/800-36/NIST-SP800-36.pdf

Guideline on Network Security Testing

Identifies network testing requirements and how to prioritize testing activities with limited resources. Describes several network security testing techniques and tools. Focuses on the basic information about techniques and tools for individuals and going on to the system development life cycle.

https://csrc.nist.gov/publications/nistpubs/800-42/NIST-SP800-42.pdf

Building an Information Technology Security Awareness and Training Program

Detailed guidance on designing, developing, implementing, and maintaining an agency security awareness and training program.

https://csrc.nist.gov/publications/nistpubs/800-50/NIST-SP800-50.pdf

Security Considerations in the Information System Development Life Cycle

This guides seeks to help organizations select and acquire cost-effective security controls by explaining how to include information system security requirements in the SDLC.

https://csrc.nist.gov/publications/nistpubs/800-64/NIST-SP800-64.pdf

Good reading, everyone!