Advertisement
Top

Tag: NIST


Network security, Security

NIST updates Cybersecurity Framework after a decade of lessons

February 27, 2024

Via: The Register

After ten years operating under the original model, and two years working to revise it, the National Institute of Standards and Technology (NIST) has released version 2.0 of its Cybersecurity Framework (CSF). Unlike the original, which was designed with critical […]


Network security, Security

Former CIO accuses Penn State of faking cybersecurity compliance

September 18, 2023

Via: The Register

Last October, Pennsylvania State University (Penn State) was sued by a former chief information officer for allegedly falsifying government security compliance reports. The lawsuit, recently unsealed, is a qui tam complaint (in Latin “who as well,”) meaning it was filed […]


Threats & Malware, Virus & Malware

Why Now? The Rise of Attack Surface Management

June 12, 2023

Via: The Hacker News

The term “attack surface management” (ASM) went from unknown to ubiquitous in the cybersecurity space over the past few years. Gartner and Forrester have both highlighted the importance of ASM recently, multiple solution providers have emerged in the space, and […]


Threats & Malware, Vulnerabilities

CISA Issues Advisory on Critical RCE Affecting ME RTU Remote Terminal Units

May 3, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday released an Industrial Control Systems (ICS) advisory about a critical flaw affecting ME RTU remote terminal units. The security vulnerability, tracked as CVE-2023-2131, has received the highest severity rating of […]


Network security, Security

Cybersecurity is hands-on learning, but everyone must be on the same page

August 11, 2021

Via: Help Net Security

In this interview with Help Net Security, Amanda L. Joyce, Group Leader, Strategic Cybersecurity Analysis & Research, Argonne National Laboratory, offers her unique perspective on the modern information security landscape. What are the most important takeaways from your decade of […]


Network security, Security

Manufacturers turning to zero trust to better secure their networks

July 23, 2021

Via: Help Net Security

In response to the 62% global increase in ransomware since 2019 (158% increase in North America) and over 40% of manufacturing firms suffering a cyberattack last year, Onclave Networks recommends manufacturers adopt zero trust architecture and security guidelines as supported […]


Mobile, Privacy protection

Facial-Recognition Flop: Face Masks Thwart Virus, Stump Security Systems

July 29, 2020

Via: Threat Post

Face masks not only have shown in research to slow the spread of COVID-19, they also deter facial-recognition technology from correctly identifying people, according to a new study. New research from the National Institute of Standards and Technology (NIST) found […]


Privacy protection

RSA Conference 2019: NIST’s Privacy Framework Starts to Take Shape

March 7, 2019

Via: Threat Post

Data privacy has been thrust into the limelight with the passage of the General Data Protection Regulation in Europe last year and a string of high-profile consumer privacy snafus. The National Institute of Standards and Technology has plans to help […]


Vulnerabilities

IBM Watson will be used by NIST to assign CVSS scores to vulnerabilities

November 6, 2018

Via: Security Affairs

The National Institute of Standards and Technology (NIST) is planning to use Artificial Intelligence to assign the CVSS scores to reported vulnerabilities. The Common Vulnerabilities and Exposures (CVE) system provides a reference-method for publicly known information security vulnerabilities and exposures. […]


Network security

NIST Small Business Cybersecurity Act passed into law

August 20, 2018

Via: Hot for Security

US president Donald Trump signed the NIST Small Business Cybersecurity Act last week, a law that will help small businesses with resources to fend off cyberattacks, as part of a comprehensive governmental strategy to improve cybersecurity. The act was written […]


Network security

Bill Seeks Metrics for NIST Cybersecurity Framework

March 2, 2017

Via: DataBreach Today

Legislation calling on the National Institute of Standards and Technology to develop outcome metrics to demonstrate the effectiveness of the NIST Cybersecurity Framework is scheduled to be considered – and likely amended – at a markup session of the House […]


Network security

NIST issues suggestions to fight off cyberattacks on utility industry

February 23, 2017

Via: Hot for Security

US federal entities are trying to help energy companies improve their security strategies after a series of hacks of US companies intensified concern. The attacks followed one last year that lead to a blackout in Kiev and attacks in 2015 […]


Cyber-crime

NIST Issues Draft of Revisions to Cybersecurity Framework

January 18, 2017

Via: DataBreach Today

The National Institute of Standards and Technology has published a draft of its first revision to its cybersecurity framework, describing it as an update, not a major overhaul. “Just to be clear, we’re not headed toward a version 2.0 right […]


Access control

SMS Two-Factor Authentication is unreliable but still in use

December 8, 2016

Via: Hot for Security

Two-factor authentication (2FA), also known as multi-factor authentication, might not be enough, the US National Institute of Standards and Technology (NIST) has repeatedly warned us this year. Meant to provide an extra layer of security by sending a code to […]


Access control, Privacy protection

NIST Proposes Ban on SMS-Based Two-Factor Authentication

July 26, 2016

Via: Hot for Security

The National Institute for Standards and Technology (NIST) has released a Digital Authentication Guideline draft proposing that all services abandon SMS-based two-factor authentication and use tokens and software cryptographic authenticators. Because messages can be redirected to a VoIP service and […]


Editorial, Network security, Vulnerabilities

SCADA Systems security -just how important is it?

January 28, 2016

Via: Russel Edwards

SCADA stands for Supervisory Control and Data Acquisition, being the consecrated denomination since the 70s for the remote monitoring and control activities necessary in modern industrial activities. A subcategory of the general ICS (Industrial Control Systems), SCADA systems gained importance […]


Phishing

NIST drafts guidelines to enhance trust in email

October 7, 2015

Via: phishing

The National Institute of Standards and Technology (#nist) has published a draft document for comment, in order to tackle two main threats to email services: #phishing Leaking confidential information NIST says that “In phishing, hackers use forged emails to trick […]