NIST
11 items tagged with "nist"
Standards3
NIST SP 800-53 Rev 5
Adhering to NIST standards during software migrations is crucial for managing risks and ensuring regulatory compliance. By implementing structured frameworks, organizations can navigate the complexities of transitioning from legacy systems to modern platforms while maintaining data integrity and security. This comprehensive guide outlines key requirements, tools, and best practices to help teams achieve successful migrations.
NIST SP 800-171 Rev 3
Adhering to NIST standards during software migrations is crucial for maintaining data integrity, enhancing security, and ensuring compliance with regulations. This guide outlines the key requirements, compliance considerations, and practical strategies for effectively managing migration projects while aligning with NIST frameworks.
NIST Cybersecurity Framework (CSF) 2.0
Govern/Identify/Protect/Detect/Respond/Recover framework for managing cybersecurity risk. CSF 2.0 (2024) adds the Govern function.
Best Practices2
NIST AI Risk Management Framework 1.0
Guidelines to integrate trustworthiness considerations into the design, development, and deployment of AI systems.
Zero Trust Architecture Principles (NIST SP 800-207)
Conceptual zero-trust model: continuous verification, least privilege, assume breach.
Regulations4
Federal Information Security Modernization Act
US law requiring federal agencies and their contractors to secure information systems using risk-based controls and continuous oversight.
Cybersecurity Maturity Model Certification
US Department of Defense program requiring defense contractors to certify cybersecurity maturity to protect controlled unclassified information.
Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence
US federal executive order directing agencies to set safety, security, and rights standards for AI development and deployment across government and industry.
Internet of Things Cybersecurity Improvement Act of 2020
U.S. law requiring IoT devices bought by the federal government to meet NIST security standards, with vulnerability disclosure guidance.
Glossaries2
Likely Exploited Vulnerabilities (LEV)
LEV is a proposed NIST metric (CSWP 41) that estimates, from a CVE’s EPSS history, the cumulative probability the vulnerability has ever been exploited — a conservative lower bound.
National Vulnerability Database (NVD)
The NVD is NIST’s database that enriches CVE records with CVSS severity scores, product identifiers, and reference data.