Security News

NIST Drafts Guidelines for Coping With Ransomware
2020-02-03 21:03

"We are more interested in ransomware that models behavior that we saw in the WannaCry attacks, where ransomware can exploit a vulnerability and propagate across a network," Ekstrom, who helped work on the documents, tells Information Security Media Group. One significant reason why NIST created these practice guidelines now is that the nature of ransomware has changed over the last two years, Ekstrom says.

Week in review: Kubernetes security challenges, NIST Privacy Framework, Mitsubishi Electric breach
2020-01-26 15:15

It's time to patch your Cisco security solutions againCisco has released another batch of security updates and patches for a variety of its offerings, including many of its security solutions. Techniques and strategies to overcome Kubernetes security challengesFive security best practices for DevOps and development professionals managing Kubernetes deployments have been introduced by Portshift.

NIST’s new privacy rules – what you need to know
2020-01-22 10:56

NIST has released a Privacy Framework to help you get your house in order. The brand new Privacy Framework 1.0 is the equivalent document for protecting peoples' personal privacy.

NIST Releases Framework for Privacy Risk Management
2020-01-20 13:27

The National Institute of Standards and Technology last week announced version 1.0 of its Privacy Framework, a tool designed to help organizations manage privacy risks. NIST published a preliminary draft of the Privacy Framework in September 2019, when it requested public feedback.

NIST Privacy Framework 1.0: Manage privacy risk, demonstrate compliance
2020-01-20 05:30

The publication also provides clarification about privacy risk management concepts and the relationship between the Privacy Framework and NIST's Cybersecurity Framework. The NIST Privacy Framework is not a law or regulation, but rather a voluntary tool that can help organizations manage privacy risk arising from their products and services, as well as demonstrate compliance with laws that may affect them, such as the California Consumer Privacy Act and the European Union's General Data Protection Regulation.

NIST 800-171 & Why Organizations Need Password Similarity Blocking in Active Directory
2020-01-07 21:33

Other organizations are also adopting NIST password guidelines and security protocols because they reduce the risk for most organizations. It easy for administrators to enforce a minimum password complexity with the standard Active Directory functionality but enforcing a character changes is more complex.

NIST's New Biometrics Databases Offer Help With IAM
2019-12-20 17:03

Agency Also Releases Study on That Raises Concerns About Facial Recognition TechnologyThe National Institute of Standards and Technology has released three biometric datasets to help organizations...

4 Automated Password Policy Enforcers for NIST Password Guidelines
2019-11-19 21:34

Automate Screening of Exposed Passwords and Password Policy EnforcementHere are four automated password policy options we recommend for NIST compliance.

Getting Ready for the NIST Privacy Framework
2019-11-06 17:03

By year's end, the National Institute of Standards and Technology should be ready to publish the first version of its privacy framework, a tool to help organizations identify, assess, manage and...

HITRUST CSF 9.3 adds CCPA, SCIDSA, and NIST SP 800-171 authoritative sources
2019-10-28 04:15

HITRUST, a leading data protection standards development and certification organization, announced the availability of version 9.3 of the HITRUST CSF information risk and compliance management...