The file's text, extracted by GovTribe without its formatting.
RFP: 140D0420R0005: Operations and Maintenance Support Services for MRMSS Title: Minerals Revenue Management Support System (MRMSS) - Operations and Support / Development and Enhancement for the Office of Natural Resource Revenue (ONRR)
Section J Technical Exhibit (TE10)
LAWS, REGULATIONS, DIRECTIVES
National Institute of Standards and Technology (NIST) Special Publications Please refer to the current NIST Special Publications website located at:
http://csrc.nist.gov/publications/PubsSPs.html DOI Policy & DOI IT Policy at: http://www.elips.doi.gov
| No. |
| Reference |
| Description/Link |
| 1 |
| OMB Circular A-11, Section 51, Basic Justification Materials |
| The technical instructions formerly found in A-11 Section 53 have been placed under direct control of the E-Government Office (E-Gov) and the Office of Federal Procurement Policy (OFPP). “Basic Justification Materials” will contain broad policy guidance and hyperlinks to the technical instructions maintained by E-Gov and OFPP |
| 2 |
| OMB Circular A-11, Section 25, Summary of Requirements |
| The technical instructions formerly found in A-11 Section 53 have been placed under direct control of E-Gov and OFPP. Hyperlinks to the technical instructions will also appear in section 25 “Summary of Requirements.” |
| 3 |
| OMB Circular A-108 (Revised December 2016), Federal Agency Responsibilities for Review, Reporting and Publication under the Privacy Act |
| This Circular establishes general requirements as well as supplementing and clarifying existing OMB guidance, including OMB Circular No. A-130, Managing Information as a Strategic Resource, Privacy Act Implementation: Guidelines and Responsibilities, Implementation of the Privacy Act of 1974: Supplementary Guidance, and Final Guidance Interpreting the Provisions of Public Law 100-503, the Computer Matching and Privacy Protection Act of 1988. |
| 4 |
| OMB Circular A-123 (Revised December 2004), Management’s Responsibility for Internal Control |
| Management Accountability and Control. This directive specifies the policies and standards for establishing, assessing, correcting, and reporting on management controls in federal agencies. |
| 5 |
| OMB Circular A-123 (Revised July 2016), Management’s Responsibility for Enterprise Risk Management and Internal Control |
| This circular defines management’s responsibilities for enterprise risk management (ERM) and internal control, and provides updated implementation guidance to Federal managers to improve accountability and effectiveness of Federal programs as well as mission support operations through implementation of ERM practices and by establishing, maintaining, and assessing internal control effectiveness. |
| 6 |
| OMB Circular A-123 Appendix A (Revised June 2018), Management of Reporting and Data Integrity Risk |
| This update balances rigor with giving agencies the flexibility to determine which control activities are necessary to achieve reasonable assurances over internal controls and processes that support overall data quality contained in agency reports. This memorandum includes a specific requirement for agencies to develop a Data Quality Plan to achieve the objectives of the Digital Accountability and Transparency Act (DATA Act) |
| 7 |
| OMB Circular A-123 Appendix C (Revised June 2018), Requirements for Payment Integrity Improvement |
| The goal of this revised version of OMB Circular A-123's Appendix C is to transform the improper payment compliance framework to create a more unified, comprehensive, and less burdensome set of requirements. |
| 8 |
| OMB Circular A-123 Appendix D (Revised September 2013), Compliance with the Federal Financial Management Improvement Act… |
| Financial Management Systems. This directive prescribes a uniform policies and standards for executive departments and agencies to follow in developing, operating, evaluating, and reporting on financial management systems and the meeting the purpose of the Federal Financial Management Improvement Act (FFMIA) of 1996. |
| 9 |
| OMB Circular A-130 (Revised July 2016), Managing Federal Information as a Strategic Resource |
| The circular establishes general policy for the planning, budgeting, governance, acquisition, and management of Federal information, personnel, equipment, funds, information technology resources and supporting infrastructure and services. |
| 10 |
| OMB Circular A-131 (Revised December 2013), Value Engineering |
| This Circular provides guidance to support the sustained use of value engineering (VE) by Federal Departments and Agencies to reduce program and acquisition costs, improve performance, enhance quality, and foster the use of innovation. |
| 11 |
| OMB Memorandum M-04-04, E-Authentication Guidance for Federal Agencies |
| This guidance takes in account current practices in the area of authentication (or e-authentication) for access to certain electronic transactions and a need for government-wide standards and will assist agencies in determining their authentication needs for electronic transactions. This guidance directs agencies to conduct “e-authentication risk assessments” on electronic transactions to ensure that there is a consistent approach across government. (See Attachment A). It also provides the public with clearly understood criteria for access to Federal government services online. Attachment B summarizes the public comments received on an earlier version of this guidance. |
| 12 |
| OMB Memorandum M-04-16, Software Acquisition |
| This memorandum reminds agencies of policies and procedures covering acquisition of software to support agency operations. |
| 13 |
| OMB Memorandum M-04-26, Personal Use Policies and "File Sharing" Technology |
| The purpose of this memorandum is to detail specific actions agencies must take to ensure the appropriate use of certain technologies used for file sharing across networks. |
| 14 |
| OMB Memorandum M-05-04, Policies for Federal Agency Public Websites |
| This memorandum and attachment fulfill the requirements of section 207(f) of the E-Government Act of 2002 (Pub. L. No. 107-347). Overall, the management of agencies' public websites should be in compliance with Federal information resource management law and policy. |
| 15 |
| OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6) |
| This memorandum and its attachments provide guidance to the agencies to ensure an orderly and secure transition from Internet Protocol Version 4 (IPv4) to Version 6 (IPv6). |
| 16 |
| OMB Memorandum M-05-23, Improving Information Technology (IT) Project Planning and Execution |
| This guidance is provided to assist in monitoring and improving project planning and execution and fully implementing Earned Value Management Systems (EVMS) for IT projects. |
| 17 |
| OMB Memorandum M-05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy... |
| Following implementation, Federal departments and agencies will be able to recognize and accept a common identification standard. |
| 18 |
| OMB Memorandum M-06-02, Improving Public Access to and Dissemination of Government Information and Using the Federal Enterprise Architecture Data Reference Model |
| This memorandum identifies procedures to organize and categorize information and make it searchable across agencies to improve public access and dissemination (section I),1 discusses using the Federal Enterprise Architecture Data Reference Model (DRM) (section II), and reminds agencies of the breadth of their existing responsibilities primarily related to information access and dissemination, including under the Paperwork Reduction Act of 1995 (44 U.S.C. Ch. 35) and the E-Government Act of 2002 (Pub. L. No. 107-347) |
| 19 |
| OMB Memorandum M-06-15, Safeguarding Personally Identifiable Information |
| This memorandum reemphasizes your many responsibilities under law and policy to appropriately safeguard sensitive personally identifiable information and train your employees on their responsibilities in this area. |
| 20 |
| OMB Memorandum M-06-19, Reporting Incidents Involving Personally Identifiable Information... |
| This memorandum provides updated guidance on the reporting of security incidents involving personally identifiable information and to remind you of existing requirements, and explain new requirements your agency will need to provide addressing security and privacy |
| 21 |
| OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information |
| Safeguarding personally identifiable information in the possession of the government and preventing its breach are essential to ensure the government retains the trust of the American public. It is also a function of applicable laws, such as the Federal Information Security Management Act of 2002 (FISMA) and the Privacy Act of 1974 |
| 22 |
| OMB Memorandum M-08-05, Implementation of Trusted Internet Connections (TIC) |
| Announces the Trusted Internet Connections (TIC) initiative to optimize our individual network services into a common solution for the federal government. |
| 23 |
| OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure |
| This memorandum describes existing and new policies for deploying Domain Name System Security (DNSSEC) to all Federal information systems |
| 24 |
| OMB Memorandum M-08-27, Guidance for Trusted Internet Connection (TIC) Compliance |
| Additional guidance and clarification on the implementation of Trusted Internet Connections |
| 25 |
| OMB Memorandum M-10-22, Guidance for Online Use of Web Measurement and Customization Technologies |
| This Memorandum establishes new procedures and provides updated guidance and requirements for agency use of web measurement and customization technologies. |
| 26 |
| OMB Memorandum M-10-23, Guidance for Agency Use of Third-Party Websites and Applications |
| This Memorandum requires Federal agencies to take specific steps to protect individual privacy whenever they use third-party websites and applications to engage with the public. |
| 27 |
| OMB Memorandum M-10-28, Clarifying Cybersecurity Responsibilities and Activities... |
| This memorandum outlines and clarifies the respective responsibilities and activities of the Office of Management and Budget (OMB), the Cybersecurity Coordinator, and DHS, in particular with respect to the Federal Government’s implementation of the Federal Information Security Management Act of 2002 (FISMA; 44 U.S.C. §§ 3541-3549). |
| 28 |
| OMB Memorandum M-11-11, Continued Implementation of Homeland Security Presidential Directive (HSPD) 12... |
| In the attached memorandum, DHS outlines a plan of action for agencies full use of the PIV credentials for access to federal facilities and information systems. |
| 29 |
| OMB Memorandum M-11-27, Implementing the Telework Enhancement Act of 2010: Security Guidelines |
| This memorandum provides guidelines on security requirements for the implementation of the Telework Enhancement Act of 2010 (Public Law 111-292), as required by 5 U.S.C. § 6504(c). |
| 30 |
| OMB Memorandum M-13-13, Open Data Policy – Managing Information as an Asset |
| This Memorandum establishes a framework to help institutionalize the principles of effective information management at each stage of the information's life cycle to promote interoperability and openness. |
| 31 |
| OMB Memorandum M-14-03, Enhancing the Security of Federal Information and Information Systems |
| This memorandum provides agencies with guidance for managing information security risk on a continuous basis and builds upon efforts towards achieving cybersecurity goals. |
| 32 |
| OMB Memorandum M-15-13, Policy to Require Secure Connections across Federal Websites and Web Services |
| This Memorandum requires that all publicly accessible Federal websites and web services only provide service through a secure connection. |
| 33 |
| OMB Memorandum M-15-14, Management and Oversight of Federal Information Technology |
| The purpose of this memorandum is to provide implementation guidance for the Federal Information Technology Acquisition Reform Act (FITARA) and related information technology (IT) management practices. |
| 34 |
| OMB Memorandum M-16-03, Fiscal Year 2015-2016 Guidance on Federal Information Security and Privacy Management Requirements |
| This memorandum establishes current Administration information security priorities and provides agencies with Fiscal Year (FY) 2016 Federal Information Security Modernization Act (FISMA) and Privacy Management reporting guidance and deadlines, as required by the Federal Information Security Modernization Act of 2014. In many cases, this memorandum establishes new guidance to address discrete challenges identified over the last fiscal year. |
| 35 |
| OMB Memorandum M-16-04, Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government |
| Strengthening the cybersecurity of Federal networks, systems, and data is one of the most important challenges we face as a Nation. As a result, the Federal Government is bringing significant resources to bear to ensure cybersecurity remains a top priority. This includes strengthening government-wide processes for developing, implementing, and institutionalizing best practices; developing and retaining the cybersecurity workforce; and working with public and private sector research and development communities to leverage the best of existing, new, and emerging technology. |
| 36 |
| OMB Memorandum M-16-15, Federal Cybersecurity Workforce Strategy |
| These initiatives focus primarily on the Federal workforce with the understanding that contractors also play vital roles in Federal cybersecurity. |
| 37 |
| OMB Memorandum M-16-19, Data Center Optimization Initiative (DCOI) |
| This memorandum defines a framework for achieving the data center consolidation and optimization requirements of FITARA, the criteria for successful agency data center strategies, and the metrics OMB OFCIO will use to evaluate the success of those strategies. |
| 38 |
| OMB Memorandum M-16-21, Federal Source Code Policy: Achieving… |
| This policy seeks to address these challenges by ensuring that new custom-developed Federal source code be made broadly available for reuse across the Federal Government |
| 39 |
| OMB Memorandum M-17-05, Fiscal Year 2016 - 2017 Guidance on Federal Information Security and Privacy Management Requirements |
| This memorandum establishes current Administration information security priorities and provides agencies with Fiscal Year (FY) 2016-2017 Federal Information Security Modernization Act (FISMA) and Privacy Management reporting guidance and deadlines, as required by the Federal Information Security Modernization Act of 2014 (Pub. L. No. 113-283, 128 Stat. 3073) (FISMA 2014), to ensure consistent government-wide performance and best practices to protect national security, privacy and civil liberties while limiting economic and mission impact of incidents. |
| 40 |
| OMB Memorandum M-17-06, Policies for Federal Agency Public Websites and Digital Services |
| The requirements in this Memorandum support building effective and user-centric digital services as outlined in the Digital Government Strategy and U.S. Digital Services Playbook. |
| 41 |
| OMB Memorandum M-17-09, Management of Federal High Value Assets |
| This Memorandum contains general guidance for the planning, identification, categorization, prioritization, reporting, assessment, and remediation of Federal High Value Assets (HVAs), as well as the handling of information related to HVAs by the Federal Government. |
| 42 |
| OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information |
| This Memorandum sets forth the policy for Federal agencies to prepare for and respond to a breach of personally identifiable information (PII). |
| 43 |
| OMB Memorandum M-17-25, Reporting Guidance for Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure |
| This Memorandum provides implementing guidance |
| 44 |
| OMB Memorandum M-17-26, Reducing Burden for Federal Agencies by Rescinding and Modifying OMB Memoranda |
| This Memorandum rescinds, modifies, and/or pauses the listed previously issued OMB memoranda to alleviate reporting and compliance burdens and allow agencies to focus their efforts on higher value activities |
| 45 |
| OMB Memorandum M-18-02, Fiscal Year 2017-2018 Guidance on Federal Information Security and Privacy Management Requirements |
| Additionally, this memorandum consolidates requirements from prior OMB annual FISMA guidance to ensure consistent, government-wide performance and agency adoption of best practices. |
| 46 |
| OMB Memorandum M-19-02, Fiscal Year 2018-2019 Guidance on Federal Information Security and Privacy Management Requirements |
| This memorandum also consolidates several government-wide reporting requirements into a single document to eliminate duplicative or burdensome processes |
| 47 |
| OMB Memorandum M-19-03, Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program |
| This memorandum provides guidance on the enhancement of the High Value Asset (HVA) program operated by the Department of Homeland Security (DHS), in coordination with the Office of Management and Budget (OMB). |
| 48 |
| OMB Memorandum M-19-17, Enabling Mission Delivery through Improved Identity, Credential, and Access Management |
| This memorandum sets forth the Federal Government's Identity, Credential, and Access Management (ICAM) policy |
| 49 |
| OMB Memorandum M-19-19, Update to Data Center Optimization Initiative (DCOI) |
| This Memorandum contains requirements for the consolidation and optimization of Federal data centers in accordance with FITARA. It establishes consolidation and optimization targets and metrics for Federal agencies, as well as requirements for reporting on their progress. |
| 50 |
| OMB Memorandum M-19-21, Transition to Electronic Records |
| Additionally, this memorandum consolidates requirements from prior OMB records management guidance to ensure consistent, government-wide policy and practices. |
| 51 |
| NIST SP 800-12 Revision 1 (2017), An Introduction to Information Security |
| This publication introduces the information security principles that organizations may leverage to understand the information security needs of their respective systems. |
| 52 |
| NIST SP 800-15 (1998), MISPC Minimum Interoperability Specification for PKI Components, Version 1 |
| The Minimum Interoperability Specification for PKI Components (MISPC) supports interoperability for a large scale public key infrastructure (PKI) that issues, revokes and manages X.509 version 3 digital signature public key certificates and version 2 certificate revocation lists (CRLs). |
| 53 |
| NIST SP 800-16 (1998), Information Technology Security Training Requirements: a Role- and Performance-Based Model |
| This document supersedes NIST SP 500-172, Computer Security Training Guidelines, published in 1989. The new document supports the Computer Security Act (Public Law 100-235) and OMB Circular A-130 Appendix III requirements that NIST develop and issue computer security training guidance. |
| 54 |
| NIST SP 800-18 Revision 1 (2006), Guide for Developing Security Plans for Federal Information Systems |
| The objective of system security planning is to improve protection of information system resources. All federal systems have some level of sensitivity and require protection as part of good management practice. The protection of a system must be documented in a system security plan. |
| 55 |
| NIST SP 800-22 Revision 1a (2010), A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications |
| This paper discusses some aspects of selecting and testing random and pseudorandom number generators. The outputs of such generators may be used in many cryptographic applications, such as the generation of key material. |
| 56 |
| NIST SP 800-25 (2000), Federal Agency Use of Public Key Technology for Digital Signatures and Authentication |
| This document builds on the Federal IT Security Assessment Framework (Framework) developed by NIST. This document provides guidance on applying the Framework by identifying 17 control areas, such as those pertaining to identification and authentication and contingency planning |
| 57 |
| NIST SP 800-28 Version 2 (2008), Guidelines on Active Content and Mobile Code |
| The purpose of this document is to provide an overview of active content and mobile code technologies in use today and offer insights for making informed IT security decisions on their application and treatment. |
| 58 |
| NIST SP 800-30 Revision 1 (2012), Guide for Conducting Risk Assessments |
| The purpose of Special Publication 800-30 is to provide guidance for conducting risk assessments of federal information systems and organizations |
| 59 |
| NIST SP 800-32 (2001), Introduction to Public Key Technology and the Federal PKI Infrastructure |
| This publication was developed to assist agency decision-makers in determining if a PKI is appropriate for their agency, and how PKI services can be deployed most effectively within a Federal agency. It is intended to provide an overview of PKI functions and their applications |
| 60 |
| NIST SP 800-34 Revision 1 (2010), Contingency Planning Guide for Federal Information Systems |
| This document provides guidance to help personnel evaluate information systems and operations to determine contingency planning requirements and priorities. |
| 61 |
| NIST SP 800-35 (2003), Guide to Information Technology Security Services |
| This guide provides assistance with the selection, implementation, and management of IT security services by guiding organizations through the various phases of the IT security services life cycle. |
| 62 |
| NIST SP 800-37 Revision 2 (2018), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy |
| This publication describes the Risk Management Framework (RMF) and provides guidelines for applying the RMF to information systems and organizations. The RMF provides a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring. |
| 63 |
| NIST SP 800-38A (2001), Recommendation for Block Cipher Modes of Operation: Methods and Techniques |
| This recommendation defines five confidentiality modes of operation for use with an underlying symmetric key block cipher algorithm |
| 64 |
| NIST SP 800-38A Addendum (2010), Recommendation for Block Cipher Modes of Operation: Three Variants of Ciphertext Stealing for CBC Mode |
| A limitation to Cipher Block Chaining (CBC) mode, as specified in NIST Special Publication 800-38A, is that the plaintext input must consist of a sequence of blocks. Ciphertext stealing is a padding method in which the required padding bits are "stolen" from the penultimate Ciphertext block. This addendum to SP 800-38A specifies three variants of CBC mode with Cipher text stealing. |
| 65 |
| NIST SP 800-38B (2016), Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication |
| This Recommendation specifies a message authentication code (MAC) algorithm based on a symmetric key block cipher. This block cipher-based MAC algorithm, called CMAC, may be used to provide assurance of the authenticity and, hence, the integrity of binary data. |
| 66 |
| NIST SP 800-38C (2007), Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality |
| This Recommendation defines a mode of operation, called Counter with Cipher Block Chaining-Message Authentication Code (CCM), for a symmetric key block cipher algorithm. CCM may be used to provide assurance of the confidentiality and the authenticity of computer data by combining the techniques of the Counter (CTR) mode and the Cipher Block Chaining-Message Authentication Code (CBC-MAC) algorithm. |
| 67 |
| NIST SP 800-38D (2007), Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC |
| This Recommendation specifies the Galois/Counter Mode (GCM), an algorithm for authenticated encryption with associated data, and its specialization, GMAC, for generating a message authentication code (MAC) on data that is not encrypted. GCM and GMAC are modes of operation for an underlying approved symmetric key block cipher |
| 68 |
| NIST SP 800-38E (2010), Recommendation for Block Cipher Modes of Operation: the XTS-AES Mode for Confidentiality on Storage Devices |
| This publication approves the XTS-AES mode of the AES algorithm by reference to IEEE Std. 1619-2007, subject to one additional requirement, as an option for protecting the confidentiality of data on storage devices. The mode does not provide authentication of the data or its source. |
| 69 |
| NIST SP 800-38F (2012), Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping |
| This publication describes cryptographic methods that are approved for “key wrapping,” i.e., the protection of the confidentiality and integrity of cryptographic keys. In addition to describing existing methods, this publication specifies two new, deterministic authenticated-encryption modes of operation of the Advanced Encryption Standard (AES) algorithm |
| 70 |
| NIST SP 800-38G (2016), Recommendation for Block Cipher Modes of Operation: Methods for Format-Preserving Encryption |
| This Recommendation specifies two methods, called FF1 and FF3, for format-preserving encryption. Both of these methods are modes of operation for an underlying, approved symmetric-key block cipher algorithm. |
| 71 |
| NIST SP 800-39 (2011), Managing Information Security Risk: Organization, Mission, and Information System View |
| Special Publication 800-39 provides a structured, yet flexible approach for managing information security risk that is intentionally broad-based, with the specific details of assessing, responding to, and monitoring risk on an ongoing basis provided by other supporting NIST security standards and guidelines. |
| 72 |
| NIST SP 800-40 Revision 3 (2013), Guide to Enterprise Patch Management Technologies |
| This publication is designed to assist organizations in understanding the basics of enterprise patch management technologies. It explains the importance of patch management and examines the challenges inherent in performing patch management. |
| 73 |
| NIST SP 800-41 Revision 1 (2009), Guidelines on Firewalls and Firewall Policy |
| This publication provides an overview of several types of firewall technologies and discusses their security capabilities and their relative advantages and disadvantages in detail. |
| 74 |
| NIST SP 800-44 Version 2 (2007), Guidelines on Securing Public Web Servers |
| This document is intended to assist organizations in installing, configuring, and maintaining secure public Web servers. |
| 75 |
| NIST SP 800-45 Version 2 (2007), Guidelines on Electronic Mail Security |
| This document was developed in furtherance of NIST's statutory responsibilities under the Federal Information Security Management Act (FISMA) of 2002, Public Law 107-347. The purpose of the publication is to recommend security practices for designing, implementing, and operating email systems on public and private networks. |
| 76 |
| NIST SP 800-46 Revision 2 (2016), Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security |
| This publication provides information on security considerations for several types of remote access solutions, and it makes recommendations for securing a variety of telework, remote access, and BYOD technologies. It also gives advice on creating related security policies. |
| 77 |
| NIST SP 800-47 (2002), Security Guide for Interconnecting Information Technology Systems |
| The Security Guide for Interconnecting Information Technology Systems provides guidance for planning, establishing, maintaining, and terminating interconnections between information technology (IT) systems that are owned and operated by different organizations. |
| 78 |
| NIST SP 800-49 (2002), Federal S/MIME V3 Client Profile |
| This profile document identifies requirements for a secure and interoperable S/MIME V3 client implementation. |
| 79 |
| NIST SP 800-50 (2003), Building an Information Technology Security Awareness and Training Program |
| The document is a companion publication to NIST Special Publication 800-16, Information Technology Security Training Requirements: A Role- and Performance-Based Model. The two publications are complementary - SP 800-50 works at a higher strategic level, discussing how to build an IT security awareness and training program, while SP 800-16 is at a lower tactical level, describing an approach to role-based IT security training. |
| 80 |
| NIST SP 800-51 Revision 1 (2011), Guide to Using Vulnerability Naming Schemes |
| This publication provides recommendations for using two vulnerability naming schemes: Common Vulnerabilities and Exposures (CVE) and Common Configuration Enumeration (CCE). |
| 81 |
| NIST SP 800-52 Revision 1 (2014), Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations |
| This Special Publication provides guidance to the selection and configuration of TLS protocol implementations while making effective use of Federal Information Processing Standards (FIPS) and NIST-recommended cryptographic algorithms, and requires that TLS 1.1 configured with FIPS-based cipher suites as the minimum appropriate secure transport protocol and recommends that agencies develop migration plans to TLS 1.2 by January 1, 2015. |
| 82 |
| NIST SP 800-53 Revision 4 (2015), Security and Privacy Controls for Federal Information Systems and Organizations |
| This publication provides a catalog of security and privacy controls for federal information systems and organizations and a process for selecting controls to protect organizational operations (including mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation from a diverse set of threats including hostile cyber-attacks, natural disasters, structural failures, and human errors (both intentional and unintentional). |
| 83 |
| NIST SP 800-53A Revision 4 (2014), Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans |
| This publication provides a set of procedures for conducting assessments of security controls and privacy controls employed within federal information systems and organizations. |
| 84 |
| NIST SP 800-54 (2007), Border Gateway Protocol Security |
| This document introduces the Border Gateway Protocol (BGP), explains its importance to the internet, and provides a set of best practices that can help in protecting BGP. |
| 85 |
| NIST SP 800-55 Revision 1 (2008), Performance Measurement Guide for Information Security |
| This document provides guidance on how an organization, through the use of metrics, identifies the adequacy of in-place security controls, policies, and procedures. |
| 86 |
| NIST SP 800-56A Revision 3 (2018), Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography |
| This Recommendation specifies key-establishment schemes based on the discrete logarithm problem over finite fields and elliptic curves, including several variations of Diffie-Hellman and Menezes-Qu-Vanstone (MQV) key establishment schemes. |
| 87 |
| NIST SP 800-56B Revision 2 (2019), Recommendation for Pair-Wise Key-Establishment Using Integer Factorization Cryptography |
| This Recommendation specifies key-establishment schemes using integer factorization cryptography (in particular, RSA). Both key-agreement and key transport schemes are specified for pairs of entities, and methods for key confirmation are included to provide assurance that both parties share the same keying material. |
| 88 |
| NIST SP 800-56C Revision 1 (2018), Recommendation for Key-Derivation Methods in Key-Establishment Schemes |
| This Recommendation specifies techniques for the derivation of keying material from a shared secret established during a key-establishment scheme defined in NIST Special Publications 800-56A or 800-56B. |
| 89 |
| NIST SP 800-57 Part 1 Revision 4 (2016), Recommendation for Key Management, Part 1: General |
| This Recommendation provides cryptographic key management guidance. It consists of three parts. Part 1 provides general guidance and best practices for the management of cryptographic keying material. Part 2 provides guidance on policy and security planning requirements for U.S. government agencies. Finally, Part 3 provides guidance when using the cryptographic features of current systems. |
| 90 |
| NIST SP 800-57 Part 2 Revision 1 (2019), Recommendation for Key Management: Part 2 – Best Practices for Key Management Organizations |
| NIST Special Publication (SP) 800-57 provides cryptographic key management guidance. It consists of three parts. Part 1 provides general guidance and best practices for the management of cryptographic keying material. Part 2 provides guidance on policy and security planning requirements. Finally, Part 3 provides guidance when using the cryptographic features of current systems |
| 91 |
| NIST SP 800-57 Part 3 Revision 1 (2015), Recommendation for Key Management, Part 3: Application-Specific Key Management Guidance |
| NIST Special Publication 800-57 provides cryptographic key management guidance. It consists of three parts. Part 1 provides general guidance and best practices for the management of cryptographic keying material. Part 2 provides guidance on policy and security planning requirements for U.S. government agencies. Finally, Part 3 provides guidance when using the cryptographic features of current systems. |
| 92 |
| NIST SP 800-60 Volume 1 Revision 1 (2008), Guide for Mapping Types of Information and Information Systems to Security Categories |
| The revision to Volume I contains the basic guidelines for mapping types of information and information systems to security categories. |
| 93 |
| NIST SP 800-60 Volume 2 Revision 1 (2008), Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices |
| Title III of the E-Government Act, titled the Federal Information Security Management Act (FISMA) of 2002, tasked NIST to develop (1) standards to be used by all Federal agencies to categorize information and information systems collected or maintained by or on behalf of each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels; and (2) guidelines recommending the types of information and information systems to be included in each such category. |
| 94 |
| NIST SP 800-61 Revision 2 (2012), Computer Security Incident Handling Guide |
| This publication assists organizations in establishing computer security incident response capabilities and handling incidents efficiently and effectively. This publication provides guidelines for incident handling, particularly for analyzing incident-related data and determining the appropriate response to each incident. |
| 95 |
| NIST SP 800-63A (2017), Digital Identity Guidelines: Enrollment and Identity Proofing |
| These guidelines provide technical requirements for federal agencies implementing digital identity services and are not intended to constrain the development or use of standards outside of this purpose. |
| 96 |
| NIST SP 800-63B (2017), Digital Identity Guidelines: Authentication and Lifecycle Management |
| These guidelines focus on the authentication of subjects interacting with government systems over open networks, establishing that a given claimant is a subscriber who has been previously authenticated. |
| 97 |
| NIST SP 800-63C (2017), Digital Identity Guidelines: Federation and Assertions |
| This document and its companion documents, SP 800-63, SP 800-63A, and SP 800-63B, provide technical and procedural guidelines to agencies for the implementation of federated identity systems and for assertions used by federations |
| 98 |
| NIST SP 800-63-3 (2017), Digital Identity Guidelines |
| The guidelines cover identity proofing and authentication of users (such as employees, contractors, or private individuals) interacting with government IT systems over open networks. |
| 99 |
| NIST SP 800-67 Revision 2 (2017), Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher |
| This publication specifies the Triple Data Encryption Algorithm (TDEA), including its primary component cryptographic engine, the Data Encryption Algorithm (DEA). TDEA is intended to be used with a Special Publication (SP) 800-38-series-compliant mode of operation in a Federal Information Processing Standard (FIPS) 140-2-compliant cryptographic module, TDEA may be used by federal organizations to protect sensitive unclassified data. |
| 100 |
| NIST SP 800-70 Revision 4 (2018), National Checklist Program for IT Products: Guidelines for Checklist Users and Developers |
| A security configuration checklist is a document that contains instructions or procedures for configuring an information technology (IT) product to an operational environment, for verifying that the product has been configured properly, and/or for identifying unauthorized changes to the product. |
| 101 |
| NIST SP 800-73-4 (2016), Interfaces for Personal Identity Verification |
| This document, SP 800-73, contains the technical specifications to interface with the smart card to retrieve and use the PIV identity credentials. The specifications reflect the design goals of interoperability and PIV Card functions. |
| 102 |
| NIST SP 800-76-2 (2013), Biometric Specifications for Personal Identity Verification |
| The Personal Identity Verification (PIV) standard for Federal Employees and Contractors, Federal Information Processing Standard Personal Identity Verification (PIV) of Federal Employees and Contractors (FIPS 201), was developed to define procedures and specifications for issuance and use of an interoperable identity credential. This document, Special Publication 800-76 (SP 800-76), is a companion document to FIPS 201. |
| 103 |
| NIST SP 800-77 (2005), Guide to IPsec VPNs |
| This document discusses the need for network layer security and introduces the concept of virtual private networking (VPN). It covers the fundamentals of IPsec, focusing on its primary components. |
| 104 |
| NIST SP 800-78-4 (2015), Cryptographic Algorithms and Key Sizes for Personal Identity Verification |
| This document contains the technical specifications needed for the mandatory and optional cryptographic keys specified in FIPS 201-2 as well as the supporting infrastructure specified in FIPS 201-2 and the related NIST Special Publication 800-73-4, Interfaces for Personal Identity Verification [SP800-73], and NIST SP 800-76-2, Biometric Specifications for Personal Identity Verification [SP800-76], that rely on cryptographic functions. |
| 105 |
| NIST SP 800-79-2 (2015), Guidelines for the Authorization of Personal Identity Verification Card Issuers (PCI) and Derived PIV Credential Issuers (DPCI) |
| The purpose of this SP is to provide appropriate and useful guidelines for assessing the reliability of issuers of PIV Cards and Derived PIV Credentials. These issuers store personal information and issue credentials based on OMB policies and on the standards published in response to HSPD-12 and therefore are the primary target of the assessment and authorization under this guideline. |
| 106 |
| NIST SP 800-81-2 (2013), Secure Domain Name System (DNS) Deployment Guide |
| This document provides deployment guidelines for securing DNS within an enterprise. |
| 107 |
| NIST SP 800-83 Revision 1 (2013), Guide to Malware Incident Prevention and Handling for Desktops and Laptops |
| This publication provides recommendations for improving an organization’s malware incident prevention measures. It also gives extensive recommendations for enhancing an organization’s existing incident response capability so that it is better prepared to handle malware incidents, particularly widespread ones. |
| 108 |
| NIST SP 800-84 (2006), Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities |
| This publication seeks to assist organizations in designing, developing, conducting, and evaluating test, training, and exercise (TT&E) events in an effort to aid personnel in preparing for adverse situations involving information technology (IT). |
| 109 |
| NIST SP 800-85A-4 (2016), PIV Card Application and Middleware Interface Test Guidelines (SP 800-73-4 Compliance) |
| This document, SP 800-85A, contains the test assertions and test procedures for testing smart card middleware as well as the card application. The tests reflect the design goals of interoperability and PIV Card functions. |
| 110 |
| NIST SP 800-85B (2006), PIV Data Model Test Guidelines |
| This document provides test requirements for the PIV data model. This test guidance document specifies the test plan, processes, derived test requirements, and the detailed test assertions / conformance tests for testing the PIV data model. |
| 111 |
| NIST SP 800-86 (2006), Guide to Integrating Forensic Techniques into Incident Response |
| This publication is intended to help organizations in investigating computer security incidents and troubleshooting some information technology (IT) operational problems by providing practical guidance on performing computer and network forensics. The guide presents forensics from an IT view, not a law enforcement view. |
| 112 |
| NIST SP 800-87 Revision 2 (2018), Codes for Identification of Federal and Federally-Assisted Organizations |
| This document provides the organizational codes for federal agencies to establish the Federal Agency Smart Credential Number (FASC-N) that is required to be included in the FIPS 201 Card Holder Unique Identifier. SP 800-87 is a companion document to FIPS 201. |
| 113 |
| NIST SP 800-88 Revision 1 (2014), Guidelines for Media Sanitization |
| Media sanitization refers to a process that renders access to target data on the media infeasible for a given level of effort. This guide will assist organizations and system owners in making practical sanitization decisions based on the categorization of confidentiality of their information. |
| 114 |
| NIST SP 800-89 (2006), Recommendation for Obtaining Assurances for Digital Signature Applications |
| This Recommendation specifies methods for obtaining the assurances necessary for valid digital signatures: assurance of domain parameter validity, assurance of public key validity, assurance that the key pair owner actually possesses the private key, and assurance of the identity of the key pair owner. |
| 115 |
| NIST SP 800-90A Revision 1 (2015), Recommendation for Random Number Generation Using Deterministic Random Bit Generators |
| This Recommendation specifies mechanisms for the generation of random bits using deterministic methods. The methods provided are based on either hash functions or block cipher algorithms. |
| 116 |
| NIST SP 800-90B (2018), Recommendation for the Entropy Sources Used for Random Bit Generation |
| This Recommendation specifies the design principles and requirements for the entropy sources used by Random Bit Generators, and the tests for the validation of entropy sources. These entropy sources are intended to be combined with Deterministic Random Bit Generator mechanisms that are specified in SP 800-90A to construct Random Bit Generators. |
| 117 |
| NIST SP 800-92 (2006), Guide to Computer Security Log Management |
| This publication seeks to assist organizations in understanding the need for sound computer security log management. It provides practical, real-world guidance on developing, implementing, and maintaining effective log management practices throughout an enterprise. |
| 118 |
| NIST SP 800-94 (2007), Guide to Intrusion Detection and Prevention Systems (IDPS) |
| This publication seeks to assist organizations in understanding intrusion detection system (IDS) and intrusion prevention system (IPS) technologies and in designing, implementing, configuring, securing, monitoring, and maintaining intrusion detection and prevention systems (IDPS) |
| 119 |
| NIST SP 800-95 (2007), Guide to Secure Web Services |
| This document describes how to implement those security mechanisms in Web services. It also discusses how to make Web services and portal applications robust against the attacks to which they are subject. |
| 120 |
| NIST SP 800-96 (2006), PIV Card to Reader Interoperability Guidelines |
| The purpose of this document is to present recommendations for Personal Identity Verification (PIV) card readers in the area of performance and communications characteristics to foster interoperability. This document is not intended to re-state or contradict requirements specifically identified in Federal Information Processing Standard 201 (FIPS 201) or its associated documents. |
| 121 |
| NIST SP 800-100 (2007), Information Security Handbook: A Guide for Managers |
| This Information Security Handbook provides a broad overview of information security program elements to assist managers in understanding how to establish and implement an information security program. |
| 122 |
| NIST SP 800-102 (2009), Recommendation for Digital Signature Timeliness |
| Establishing the time when a digital signature was generated is often a critical consideration. A signed message that includes the (purported) signing time provides no assurance that the private key was used to sign the message at that time unless the accuracy of the time can be trusted. |
| 123 |
| NIST SP 800-106 (2009), Randomized Hashing for Digital Signatures |
| The security provided by the cryptographic hash function is vital to the security of a digital signature application. This Recommendation specifies a method to enhance the security of the cryptographic hash functions used in digital signature applications by randomizing the |
| 124 |
| NIST SP 800-107 Revision 1 (2012), Recommendation for Applications Using Approved Hash Algorithms |
| This document provides security guidelines for achieving the required or desired security strengths when using cryptographic applications that employ the approved hash functions specified in Federal Information Processing Standard (FIPS) 180-4. These include functions such as digital signatures, Keyed-hash Message Authentication Codes (HMACs) and Hash-based Key Derivation Functions (Hash-based KDFs). |
| 125 |
| NIST SP 800-108 (2009), Recommendation for Key Derivation Using Pseudorandom Functions (Revised) |
| This Recommendation specifies techniques for the derivation of additional keying material from a secret key, either established through a key establishment scheme or shared through some other manner, using pseudorandom functions. |
| 126 |
| NIST SP 800-111 (2007), Guide to Storage Encryption Technologies for End User Devices |
| This publication explains the basics of storage encryption, which is the process of using encryption and authentication to restrict access to and use of stored information. The appropriate storage encryption solution for a particular situation depends primarily upon the type of storage, the amount of information that needs to be protected, the environments where the storage will be located, and the threats that need to be mitigated. |
| 127 |
| NIST SP 800-113 (2008), Guide to SSL VPNs |
| This document seeks to assist organizations in understanding SSL VPN technologies. The publication also makes recommendations for designing, implementing, configuring, securing, monitoring, and maintaining SSL VPN solutions. |
| 128 |
| NIST SP 800-114 Revision 1 (2016), User's Guide to Telework and Bring Your Own Device (BYOD) Security |
| This publication provides recommendations for securing BYOD devices used for telework and remote access, as well as those directly attached to the enterprise’s own networks. |
| 129 |
| NIST SP 800-115 (2008), Technical Guide to Information Security Testing and Assessment |
| The purpose of this document is to assist organizations in planning and conducting technical information security tests and examinations, analyzing findings, and developing mitigation strategies |
| 130 |
| NIST SP 800-116 Revision 1 (2018), Guidelines for the Use of PIV Credentials in Facility Access |
| This recommendation provides a technical guideline to use Personal Identity Verification (PIV) Cards in facility access; enabling federal agencies to operate as government-wide interoperable enterprises. These guidelines cover the risk-based strategy to select appropriate PIV authentication mechanisms as expressed within Federal Information Processing Standard (FIPS) 201 |
| 131 |
| NIST SP 800-119 (2010), Guidelines for the Secure Deployment of IPv6 |
| This document provides guidelines for organizations to aid in securely deploying IPv6. |
| 132 |
| NIST SP 800-122 (2010), Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) |
| The purpose of this document is to assist Federal agencies in protecting the confidentiality of personally identifiable information (PII) in information systems. |
| 133 |
| NIST SP 800-123 (2008), Guide to General Server Security |
| The purpose of this document is to assist organizations in understanding the fundamental activities performed as part of securing and maintaining the security of servers that provide services over network communications as a main function. |
| 134 |
| NIST SP 800-125 (2011), Guide to Security for Full Virtualization Technologies |
| The purpose of SP 800-125 is to discuss the security concerns associated with full virtualization technologies for server and desktop virtualization, and to provide recommendations for addressing these concerns |
| 135 |
| NIST SP 800-125A Revision 1 (2018), Security Recommendations for Server-based Hypervisor Platforms |
| The security recommendations in this document relate to ensuring the secure execution of baseline functions of the hypervisor and are therefore agnostic to the hypervisor architecture. Further, the recommendations are in the context of a hypervisor deployed for server virtualization and not for other use cases such as embedded systems and desktops. |
| 136 |
| NIST SP 800-125B (2016), Secure Virtual Network Configuration for Virtual Machine (VM) Protection |
| This document analyzes the configuration options under these areas and presents a corresponding set of recommendations for secure virtual network configuration for VM protection. |
| 137 |
| NIST SP 800-126 Revision 3 (2018), The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.3 |
| This publication, along with its annex (NIST Special Publication 800-126A) and a set of schemas, collectively define the technical composition of SCAP version 1.3 in terms of its component specifications, their interrelationships and interoperation, and the requirements for SCAP content. |
| 138 |
| NIST SP 800-126A (2018), SCAP 1.3 Component Specification Version Updates: An Annex to NIST Special Publication 800-126 Revision 3 |
| This document allows the use of particular minor version updates to SCAP 1.3 component specifications and the use of particular Open Vulnerability and Assessment Language (OVAL) core schema and platform schema versions. Allowing use of these updates and schemas provides additional functionality for SCAP 1.3 without causing any loss of existing functionality. |
This is the start of the file's text. The full file is on GovTribe.