Digital Government
A necessary plan for managing privacy risk
As a well-engineered blueprint, NIST's privacy framework will provide voluntary guidelines for managing privacy risk, furthering protections and delivering practical tools that still allow for continued U.S. innovation.
Cybersecurity
IoT poses special cyber risks
Internet-connected devices pose special risks for federal agencies, and the National Institute of Standards and Technology is developing guidance to meet the need.
Digital Government
Quantum lag: Experts fret that the U.S. risks falling behind in computing power
Quantum computing could upend current cryptography standards, and experts are urging government to take an interest in the technology as it develops.
Cybersecurity
NIST pushes on next version of Risk Management Framework
The National Institute of Standards and Technology looks to release the final version of RMF 2.0 early next year.
Cybersecurity
Regulators grapple with supply chain security
The government wants to crack down on cybersecurity threats and counterfeits in the global tech supply chain without harming U.S. companies.
Acquisition
Senate bill looks to secure the IT supply chain
A new bipartisan bill looks to build capacity inside the federal government to evaluate supply chain risks with an eye to making sure the government buys secure tech.
Cybersecurity
Threat indicator data needs a wide net, experts say
Robust, cross-cutting organizational networks are key to disseminating cybersecurity threat information.
Cybersecurity
NIST seeks 'lightweight' encryption standards
The National Institute of Standards and Technology wants public input on the best way to design evaluation criteria dictating new encryption standards for small computing devices.
Cybersecurity
7 Steps for getting right with NIST 800-171
The pressure for DOD contractors to bring their systems into compliance is especially strong, but these best practices can help any organization working with federal data.
Cybersecurity
Why is no one raising a hand to regulate the internet of things?
The U.S. is developing a pair of reports dealing with cybersecurity standards for internet-of-things devices and combatting botnets, but recommendations will be non-binding and officials said not to expect a significant federal regulatory push.
Cybersecurity
Can federal purchasing power counteract botnets?
New guidance required under the cybersecurity EO suggests that government purchasing power could induce tech manufacturers, especially in the emerging IoT space, to market more secure devices.
Cybersecurity
Will new breach reporting rules make defense firms more secure?
A coming 72-hour breach disclosure mandate from the Department of Defense could inadvertently provide a new attack vector for hackers to harass defense contractors.
Cybersecurity
Whitehouse renews call for cyber IG
One lawmaker thinks it's time for a dedicated inspector general with the authority to do penetration testing of federal agency networks and systems.
Cybersecurity
DHS: A 'vast majority' of agencies on track with Kaspersky directive
It is too soon to tell how long it will take to fully purge the embattled vendor from federal systems, according to a DHS official.
Cybersecurity
House bill looks to secure IoT ecosystem
New legislation would improve security and oversight of connected devices.
Cybersecurity
Walter Copan tapped to lead NIST
A former senior executive at the Brookhaven National Lab is President Trump's pick to lead the National Institute of Standards and Technology.
Cybersecurity
New guidelines for hack-proof elections get a key vote of approval
A committee of the Election Assistance Commission approved a set of guidelines designed to make voting more secure and more accessible.
Cybersecurity
NIST retools security and privacy controls for IoT era
NIST expands its security and privacy governance strategies to address the new ecosystem of connected devices.
Cybersecurity
Figuring out multifactor authentication
With NIST now restricting the use of Short Message Service, what are the authentication options for federal agencies?
Cybersecurity