(forw) NIST Computer Security Division Released 4 Publications today
Elias Levy <[email protected]> Wed, 12 May 2004 10:12:55 -0600
| Newsgroups | gmane.comp.security.papers |
|---|---|
| Message-ID | <[email protected]> |
----- Forwarded message from Patrick O'Reilly <[email protected]> ----- From: "Patrick O'Reilly" <[email protected]> Reply-To: [email protected] To: Multiple recipients of list <[email protected]> Subject: NIST Computer Security Division Released 4 Publications today Date: Wed, 12 May 2004 11:55:35 -0400 (EDT) Message-Id: <[email protected]> X-Mailer: QUALCOMM Windows Eudora Version 5.1 May 12, 2004 -- NIST's Computer Security Released 4 Security Documents 1. Special Publication 800-37 The National Institute of Standards and Technology today published guidelines on the security certification and accreditation of federal information systems. NIST Special Publication 800-37, "Guide for the Security Certification and Accreditation of Federal Information Systems", is one of several key documents being developed by NIST to support the implementation of the Federal Information Security Management Act (FISMA) of 2002. The new guidelines provide a standardized approach for assessing the effectiveness of the management, operational, and technical security controls in an information system and for determining the business or mission risk to an agency's operations and assets brought about by the operation of that system. NIST Special Publication 800-37 is available on the CSRC Special Publications page. A complete description of the NIST FISMA Implementation Project is also available at: http://csrc.nist.gov/sec-cert. URL for this publication is: http://csrc.nist.gov/publications/nistpubs/index.html#sp800-37 2. Special Publication 800-67 The newly released NIST Special Publication 800-67 Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher, is now available. NIST SP 800-67 specifies the Triple Data Encryption Algorithm (TDEA), including its primary component cryptographic engine, the Data Encryption Algorithm (DEA). This recommendation precisely defines the mathematical steps required to cryptographically protect data using TDEA and to subsequently process such protected data. When implemented in an SP 800-38 series-compliant mode of operation and in a FIPS 140-2 compliant cryptographic module, TDEA may be used by Federal organizations to protect sensitive unclassified data. A copy of NIST SP 800-67 can be found on the NIST Special Publications web page. URL for this publication: http://csrc.nist.gov/publications/nistpubs/index.html#sp800-67 3. Special Publication 800-38C NIST Special Publication 800-38C Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality has been finalized. This Recommendation specifies the Counter with Cipher Block Chaining-Message Authentication Code (CCM) mode, an authenticated encryption mode of the Advanced Encryption Standard (AES) algorithm. Information on this special publication and the development of modes of operation is available at the modes home page (http://csrc.nist.gov/CryptoToolkit/modes/index.html). URL for this publication: http://csrc.nist.gov/publications/nistpubs/index.html#sp800-38C 4. DRAFT Special Publication 800-66 NIST Computer Security Division has recently completed a draft of NIST Special Publication 800-66, An Introductory Resource Guide for Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, for public comment. The guidance is intended to assist in identifying available NIST guidance which can provide useful reference material in addressing the HIPAA security standards. In addition, for federal agencies subject to both the Federal Information Security Management Act (FISMA) and HIPAA, it provides a cross-mapping between the two sets of requirements to assist agencies in not doing double work since the two sets of requirements overlap. The draft is available on the CSRC Drafts Publications page. NIST is requesting comments by July 15, 2004. Comments should be addressed to [email protected] URL for this document: http://csrc.nist.gov/publications/drafts.html#sp800-66 ------------------------------ To unsubscribe to this list send e-mail to [email protected] and type in the body of the e-mail message: unsubscribe compsecpubs ----- End forwarded message ----- -- Elias Levy Symantec Alea jacta est