nist

http://www.gcn.com/online/vol1_no1/45794-1.htmlBy William JacksonGCN.com02/06/08A new Web page [1] hosted by the National Institute of Standards and Technology lists products that have been validated to scan the security configurations of Windows operating systems on federal desktop PCs.The scanners use the Security Content Automation Protocol to check for compliance with the Federal Desktop Core Configuration (FDCC) standards. So far, three products have been validated by independent laboratories under NI read more »
addto Add this link to... report Bury 
http://www.gcn.com/online/vol1_no1/45945-1.htmlBy William JacksonGCN.com03/11/08The National Institute of Standards and Technology has released a second draft of its specifications for “Interfaces for Personal Identity Verification” to be used with the standard PIV card that will be issued to all government employees and contractors working on-site.Comments on the document, Special Publication 800-73 Rev. 2, are being accepted until April 4.NIST has also released final versions of two other documents in it read more »
addto Add this link to... report Bury 
http://www.gcn.com/online/vol1_no1/46004-1.htmlBy Dan CampbellSpecial to GCNGCN.com03/25/08Network researchers at the National Institute of Standards and Technology (NIST) have unveiled a method that federal systems administrators can use to protect their systems from increasingly complex attacks launched via the Domain Name System (DNS) of the Internet and private IP networks.DNS has long been a critical function of the Internet and private IP networks, but one that tended to operate somewhat incognito. T read more »
addto Add this link to... report Bury 
http://www.gcn.com/online/vol1_no1/46398-1.htmlBy William JacksonGCN.com06/05/08The National Institute of Standards and Technology is developing a system of standardized measurements to evaluate the impact of security configurations on operating systems and applications."Each security configuration decision can have positive and negative effects of varying degrees to the security of a host," NIST's draft document states. "Without a standardized way to quantify these effects, organizations ca read more »
addto Add this link to... report Bury 
From: InfoSec News <alerts_at_private>Date: Tue, 1 Jul 2008 01:41:36 -0500 (CDT)http://www.gcn.com/online/vol1_no1/46561-1.htmlBy William JacksonGCN.com06/30/08 The National Institute of Standards and Technology has released final revisions to three of its 800 series of special publications on information technology security.NIST calls SP 800-79-1 [1], titled "Guidelines for the Accreditation of Personal Identity Verification Card Issuers," a substantial improvement over the original versio read more »
addto Add this link to... report Bury 
From: InfoSec News <alerts_at_private>Date: Wed, 23 Jul 2008 02:38:57 -0500 (CDT)http://www.gcn.com/online/vol1_no1/46698-1.htmlBy William JacksonGCN.com07/22/08The National Institute of Standards and Technology has released a revised version of guidelines for developing metrics to ensure that agencies meet information technology security requirements.Special Publication 800-55, Revision 1 [1], titled "Performance Measurement Guide for Information Security," is intended to assist agencies i read more »
addto Add this link to... report Bury 
From: InfoSec News <alerts_at_private>Date: Fri, 15 Aug 2008 02:05:56 -0500 (CDT)http://www.gcn.com/online/vol1_no1/46877-1.htmlBy William JacksonGCN.com08/14/08The National Institute of Standards and Technology has updated its guidelines for mapping information in government information systems to categories that specify the types of security controls the data requires.The Federal Information Security Management Act requires that agencies assign levels of risk to information and information systems read more »
addto Add this link to... report Bury 
From: InfoSec News <alerts_at_private>Date: Tue, 4 Nov 2008 00:18:16 -0600 (CST)http://www.gcn.com/online/vol1_no1/47486-1.htmlBy William JacksonGCN.com11/03/08The use of increasingly powerful cell phones and other portable devices as business tools can open an enterprise to a new class of cyber threats, and the National Institute of Standards and Technology has released guidelines for mitigating these risks.Special Publication 800-124 [1], titled "Guidelines on Cell Phone and PDA Security" read more »
addto Add this link to... report Bury