(forw) NIST Computer Security Division Released 4 Publications today

Elias Levy <[email protected]> Wed, 12 May 2004 10:12:55 -0600
Newsgroups gmane.comp.security.papers
Message-ID <[email protected]>
----- Forwarded message from Patrick O'Reilly <[email protected]> -----

From: "Patrick O'Reilly" <[email protected]>
Reply-To: [email protected]
To: Multiple recipients of list <[email protected]>
Subject: NIST Computer Security Division Released 4 Publications today
Date: Wed, 12 May 2004 11:55:35 -0400 (EDT)
Message-Id: <[email protected]>
X-Mailer: QUALCOMM Windows Eudora Version 5.1

May 12, 2004 --  NIST's Computer Security Released 4 Security Documents

1.  Special Publication 800-37
The National Institute of Standards and Technology today published 
guidelines on the security certification and accreditation of federal 
information systems. NIST Special Publication 800-37, "Guide for the 
Security Certification and Accreditation of Federal Information Systems", 
is one of several key documents being developed by NIST to support the 
implementation of the Federal Information Security Management Act (FISMA) 
of 2002. The new guidelines provide a standardized approach for assessing 
the effectiveness of the management, operational, and technical security 
controls in an information system and for determining the business or 
mission risk to an agency's operations and assets brought about by the 
operation of that system. NIST Special Publication 800-37 is available on 
the CSRC Special Publications page. A complete description of the NIST 
FISMA Implementation Project is also available at:
http://csrc.nist.gov/sec-cert.
URL for this publication is: 
http://csrc.nist.gov/publications/nistpubs/index.html#sp800-37

2.  Special Publication 800-67
The newly released NIST Special Publication 800-67 Recommendation for the 
Triple Data Encryption Algorithm (TDEA) Block Cipher, is now available. 
NIST SP 800-67 specifies the Triple Data Encryption Algorithm (TDEA), 
including its primary component cryptographic engine, the Data Encryption 
Algorithm (DEA). This recommendation precisely defines the mathematical 
steps required to cryptographically protect data using TDEA and to 
subsequently process such protected data. When implemented in an SP 800-38 
series-compliant mode of operation and in a FIPS 140-2 compliant 
cryptographic module, TDEA may be used by Federal organizations to protect 
sensitive unclassified data. A copy of NIST SP 800-67 can be found on the 
NIST Special Publications web page.
URL for this publication: 
http://csrc.nist.gov/publications/nistpubs/index.html#sp800-67

3.  Special Publication 800-38C
NIST Special Publication 800-38C Recommendation for Block Cipher Modes of 
Operation: the CCM Mode for Authentication and Confidentiality has been 
finalized. This Recommendation specifies the Counter with Cipher Block 
Chaining-Message Authentication Code (CCM) mode, an authenticated 
encryption mode of the Advanced Encryption Standard (AES) algorithm. 
Information on this special publication and the development of modes of 
operation is available at the modes home page 
(http://csrc.nist.gov/CryptoToolkit/modes/index.html).
URL for this publication: 
http://csrc.nist.gov/publications/nistpubs/index.html#sp800-38C


4. DRAFT Special Publication 800-66
NIST Computer Security Division has recently completed a draft of NIST 
Special Publication 800-66, An Introductory Resource Guide for 
Implementation of the Health Insurance Portability and Accountability Act 
(HIPAA) Security Rule, for public comment. The guidance is intended to 
assist in identifying available NIST guidance which can provide useful 
reference material in addressing the HIPAA security standards. In addition, 
for federal agencies subject to both the Federal Information Security 
Management Act (FISMA) and HIPAA, it provides a cross-mapping between the 
two sets of requirements to assist agencies in not doing double work since 
the two sets of requirements overlap. The draft is available on the CSRC 
Drafts Publications page. NIST is requesting comments by July 15, 2004. 
Comments should be addressed to [email protected]
URL for this document: http://csrc.nist.gov/publications/drafts.html#sp800-66

------------------------------
To unsubscribe to this list send e-mail to [email protected] and type in 
the body of the e-mail message:
        unsubscribe compsecpubs

----- End forwarded message -----

-- 
Elias Levy
Symantec
Alea jacta est