NIST Publication Catalog

Browse 67 NIST cybersecurity publications organized by series. Click any publication to explore its details and relationships.

Frameworks(5)

CSF 2.0FrameworkFinal
2024-02

NIST Cybersecurity Framework (CSF) 2.0

Provides a comprehensive framework of cybersecurity outcomes organized into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Serves as a voluntary guidance for organizations of all sizes and sectors to manage and reduce cybersecurity risk.

Privacy FWFrameworkFinal
2020-01

NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management, Version 1.0

Provides a voluntary framework for organizations to identify and manage privacy risk. Structured around five functions (Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P) to help organizations build better privacy practices.

NICE FWFrameworkFinal
2020-11

NICE Cybersecurity Workforce Framework

Provides a common language for describing cybersecurity work, organizing it into categories, specialty areas, and work roles. Supports cybersecurity workforce development, education, and training across public and private sectors.

OSCALFrameworkFinal
2023-06

Open Security Controls Assessment Language (OSCAL)

Defines a standardized, machine-readable format for representing security control catalogs, baselines, system security plans, and assessment results. Enables automation of security assessment and authorization processes.

SSDFFrameworkFinal
2022-02

Secure Software Development Framework (SSDF)

Defines a set of fundamental secure software development practices organized into four groups: Prepare the Organization, Protect the Software, Produce Well-Secured Software, and Respond to Vulnerabilities. Helps organizations reduce software vulnerabilities.

SP 800 Series(25)

SP 800-53r5SP 800Final
2020-09

SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations

Provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Serves as the foundational control set referenced by the Risk Management Framework and many compliance programs.

SP 800-53Ar5SP 800Final
2022-01

SP 800-53A Rev. 5 - Assessing Security and Privacy Controls in Information Systems and Organizations

Provides guidelines for building effective assessment plans and managing assessments of security and privacy controls defined in SP 800-53. Supports organizations in determining the effectiveness of controls deployed in information systems.

SP 800-53BSP 800Final
2020-10

SP 800-53B - Control Baselines for Information Systems and Organizations

Establishes security and privacy control baselines for federal information systems categorized at low, moderate, and high impact levels. Provides tailoring guidance for organizations to adjust baselines to their specific needs.

SP 800-37r2SP 800Final
2018-12

SP 800-37 Rev. 2 - Risk Management Framework for Information Systems and Organizations

Describes the Risk Management Framework (RMF) and provides guidelines for applying it to information systems and organizations. Outlines seven steps including categorize, select, implement, assess, authorize, monitor, and prepare.

SP 800-30r1SP 800Final
2012-09

SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments

Provides guidance for conducting risk assessments of federal information systems and organizations. Describes threat sources, threat events, vulnerabilities, impact, and likelihood to help organizations determine risk.

SP 800-39SP 800Final
2011-03

SP 800-39 - Managing Information Security Risk

Provides guidance for an integrated, organization-wide program for managing information security risk across three tiers: organization, mission/business process, and information system. Establishes the foundation for the risk management hierarchy.

SP 800-60v1r1SP 800Final
2008-08

SP 800-60 Vol. 1 Rev. 1 - Guide for Mapping Types of Information and Information Systems to Security Categories

Provides guidance for mapping types of information and information systems to security categories as defined by FIPS 199. Assists organizations in determining the appropriate impact levels for confidentiality, integrity, and availability.

SP 800-60v2r1SP 800Final
2008-08

SP 800-60 Vol. 2 Rev. 1 - Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories

Contains the appendices supporting SP 800-60 Volume 1, providing detailed mappings of information types to recommended security impact levels. Includes provisional impact assignments for common federal information types.

SP 800-63-4SP 800Draft
2024-08

SP 800-63-4 - Digital Identity Guidelines

Provides technical requirements for federal agencies implementing digital identity services including identity proofing, authentication, and federation. Defines assurance levels for digital identity transactions.

SP 800-171r3SP 800Final
2024-05

SP 800-171 Rev. 3 - Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

Provides security requirements for protecting the confidentiality of Controlled Unclassified Information (CUI) in nonfederal systems and organizations. Widely referenced in government contracts and the CMMC program.

SP 800-171Ar3SP 800Final
2024-11

SP 800-171A Rev. 3 - Assessing Security Requirements for Controlled Unclassified Information

Provides procedures for assessing the security requirements in SP 800-171 to ensure CUI protections are implemented correctly. Supports organizations in evaluating their compliance with CUI security requirements.

SP 800-172r3SP 800Final
2024-11

SP 800-172 Rev. 3 - Enhanced Security Requirements for Protecting Controlled Unclassified Information

Provides enhanced security requirements beyond SP 800-171 for protecting CUI associated with critical programs or high-value assets. Addresses advanced persistent threats targeting nonfederal systems.

SP 800-207SP 800Final
2020-08

SP 800-207 - Zero Trust Architecture

Defines zero trust architecture and its logical components, describing deployment models and use cases for zero trust approaches. Provides a roadmap for organizations transitioning to a zero trust security model.

SP 800-137r1SP 800Final
2020-06

SP 800-137 Rev. 1 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

Provides guidance for establishing, implementing, and maintaining an information security continuous monitoring program. Supports ongoing awareness of security posture, vulnerabilities, and threats across the organization.

SP 800-160v1r1SP 800Final
2022-11

SP 800-160 Vol. 1 Rev. 1 - Engineering Trustworthy Secure Systems

Provides systems security engineering processes and practices for developing trustworthy secure systems. Addresses engineering-driven actions to develop more defensible and survivable systems throughout the system lifecycle.

SP 800-160v2r1SP 800Final
2021-12

SP 800-160 Vol. 2 Rev. 1 - Developing Cyber-Resilient Systems

Provides a cyber resiliency engineering framework with goals, objectives, techniques, and approaches for developing cyber-resilient systems. Helps organizations anticipate, withstand, recover from, and adapt to adverse conditions.

SP 800-161r1SP 800Final
2022-05

SP 800-161 Rev. 1 - Cybersecurity Supply Chain Risk Management Practices

Provides guidance for identifying, assessing, and mitigating cybersecurity risks throughout the supply chain. Helps organizations establish C-SCRM practices at all levels of the enterprise.

SP 800-40r4SP 800Final
2022-04

SP 800-40 Rev. 4 - Guide to Enterprise Patch Management Planning

Provides guidance on creating and managing an enterprise patch management program. Helps organizations maintain the security of their software and firmware through timely deployment of patches.

SP 800-61r3SP 800Final
2024-03

SP 800-61 Rev. 3 - Incident Handling Guide

Provides recommendations for handling cybersecurity incidents including preparation, detection, analysis, containment, eradication, and recovery. Assists organizations in establishing effective incident response capabilities.

SP 800-88r1SP 800Final
2014-12

SP 800-88 Rev. 1 - Guidelines for Media Sanitization

Provides guidelines for sanitization of media including clearing, purging, and destroying data on various storage devices. Assists organizations in making practical sanitization decisions based on the confidentiality of the information.

SP 800-115SP 800Final
2008-09

SP 800-115 - Technical Guide to Information Security Testing and Assessment

Provides technical guidance on planning, conducting, and analyzing information security testing and assessments. Covers review techniques, vulnerability scanning, penetration testing, and social engineering testing.

SP 800-128SP 800Final
2019-06

SP 800-128 - Guide for Security-Focused Configuration Management of Information Systems

Provides guidelines for managing the configuration of information systems with a focus on security. Addresses configuration management planning, implementation, and monitoring as part of the system development lifecycle.

SP 800-175Br1SP 800Final
2020-03

SP 800-175B Rev. 1 - Guideline for Using Cryptographic Standards in the Federal Government

Provides guidance on the use of cryptographic standards and algorithms for protecting sensitive federal information. Covers cryptographic mechanisms including encryption, digital signatures, key management, and hashing.

SP 800-181r1SP 800Final
2020-11

SP 800-181 Rev. 1 - Workforce Framework for Cybersecurity (NICE Framework)

Establishes a common lexicon for describing cybersecurity work through categories, specialty areas, work roles, and knowledge/skills/abilities. Supports workforce development, planning, and training across public and private sectors.

SP 800-218SP 800Final
2022-02

SP 800-218 - Secure Software Development Framework (SSDF)

Defines a set of high-level secure software development practices that can be integrated into any software development lifecycle. Helps organizations reduce the number and severity of vulnerabilities in released software.

FIPS Series(8)

FIPS 140-3FIPSFinal
2019-03

FIPS 140-3 - Security Requirements for Cryptographic Modules

Specifies the security requirements for cryptographic modules used within a security system protecting sensitive information. Defines four increasing levels of security to cover a wide range of potential applications and environments.

FIPS 197FIPSFinal
2001-11

FIPS 197 - Advanced Encryption Standard (AES)

Specifies the Advanced Encryption Standard (AES) algorithm, a symmetric block cipher capable of using cryptographic keys of 128, 192, and 256 bits to encrypt and decrypt data in blocks of 128 bits. AES is the most widely used encryption standard worldwide.

FIPS 199FIPSFinal
2004-02

FIPS 199 - Standards for Security Categorization of Federal Information and Information Systems

Establishes security categories for federal information and information systems based on potential impact to confidentiality, integrity, and availability. Provides the foundation for the security categorization step of the Risk Management Framework.

FIPS 200FIPSFinal
2006-03

FIPS 200 - Minimum Security Requirements for Federal Information and Information Systems

Specifies minimum security requirements for federal information and information systems across seventeen security-related areas. Mandates the use of SP 800-53 security controls to meet the minimum requirements based on FIPS 199 categorization.

FIPS 201-3FIPSFinal
2022-01

FIPS 201-3 - Personal Identity Verification (PIV) of Federal Employees and Contractors

Establishes standards for the Personal Identity Verification (PIV) system for federal employees and contractors. Defines the architecture and technical requirements for PIV credentials used in identity verification and physical/logical access control.

FIPS 202FIPSFinal
2015-08

FIPS 202 - SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions

Specifies the SHA-3 family of hash functions and extendable-output functions based on the Keccak permutation. Provides an alternative to the SHA-2 family for generating message digests and supporting other cryptographic applications.

FIPS 203FIPSFinal
2024-08

FIPS 203 - Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)

Specifies the ML-KEM algorithm, a post-quantum key encapsulation mechanism based on the Module Learning with Errors problem. Designed to protect against both classical and quantum computing attacks for secure key exchange.

FIPS 204FIPSFinal
2024-08

FIPS 204 - Module-Lattice-Based Digital Signature Standard (ML-DSA)

Specifies the ML-DSA algorithm, a post-quantum digital signature scheme based on the Module Learning with Errors problem. Provides quantum-resistant digital signatures for authentication and integrity verification.

SP 1800 Series(10)

SP 1800-5SP 1800Final
2018-09

SP 1800-5 - IT Asset Management

Provides a practical guide for automating IT asset management using commercially available tools. Demonstrates how organizations can gain visibility into their networked resources to support security and operational decisions.

SP 1800-10SP 1800Final
2019-01

SP 1800-10 - Protecting Information System Integrity in Automated Manufacturing Environments

Demonstrates a reference architecture for protecting the integrity of data and software in manufacturing systems. Addresses cybersecurity challenges specific to operational technology in automated manufacturing environments.

SP 1800-11SP 1800Final
2020-09

SP 1800-11 - Data Integrity: Recovering from Ransomware and Other Destructive Events

Provides a reference architecture for recovering from data integrity attacks including ransomware. Demonstrates backup, recovery, and integrity-checking solutions to restore operations after a destructive cybersecurity event.

SP 1800-25SP 1800Final
2020-12

SP 1800-25 - Data Integrity: Identifying and Protecting Assets Against Ransomware

Demonstrates a reference architecture for identifying and protecting organizational assets against ransomware and other destructive events. Focuses on proactive measures to prevent data integrity compromises.

SP 1800-26SP 1800Final
2020-12

SP 1800-26 - Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events

Provides a reference architecture for detecting and responding to data integrity events including ransomware attacks. Demonstrates tools and techniques for monitoring, alerting, and responding to destructive cybersecurity incidents.

SP 1800-27SP 1800Final
2022-02

SP 1800-27 - Securing Property Management Systems

Demonstrates a reference design for securing property management systems (PMS) in the hospitality sector. Addresses cybersecurity challenges related to protecting guest data and payment information in hotel and lodging environments.

SP 1800-32SP 1800Final
2022-07

SP 1800-32 - Securing the Industrial Internet of Things

Demonstrates a reference architecture for securing Industrial Internet of Things (IIoT) environments within distributed energy resource systems. Addresses cybersecurity challenges at the intersection of IT and OT in industrial settings.

SP 1800-34SP 1800Final
2022-11

SP 1800-34 - Validating the Integrity of Computing Devices

Demonstrates approaches for validating the integrity of computing devices by verifying firmware and software components. Helps organizations detect unauthorized changes to devices before deployment or during operation.

SP 1800-35SP 1800Draft
2024-04

SP 1800-35 - Implementing a Zero Trust Architecture

Provides a practical guide for implementing a zero trust architecture using commercially available technology. Demonstrates reference designs that align with the zero trust concepts defined in SP 800-207.

SP 1800-36SP 1800Final
2023-12

SP 1800-36 - Trusted Internet of Things (IoT) Device Network-Layer Onboarding and Lifecycle Management

Demonstrates approaches for securely onboarding IoT devices onto networks and managing them throughout their lifecycle. Addresses secure provisioning, authentication, and management of IoT devices at the network layer.

NISTIR Series(18)

NISTIR 8259NISTIRFinal
2020-05

NISTIR 8259 - Foundational Cybersecurity Activities for IoT Device Manufacturers

Identifies foundational cybersecurity activities that IoT device manufacturers should consider performing before their devices are sold. Helps manufacturers understand and address cybersecurity risks associated with their IoT products.

NISTIR 8259ANISTIRFinal
2020-05

NISTIR 8259A - IoT Device Cybersecurity Capability Core Baseline

Defines a core baseline of cybersecurity capabilities that IoT devices should support. Establishes minimum security capabilities including device identification, configuration, data protection, and logical access to interfaces.

NISTIR 7621r1NISTIRFinal
2016-11

NISTIR 7621 Rev. 1 - Small Business Information Security

Provides fundamental cybersecurity guidance tailored to the needs of small businesses. Covers essential security topics in an accessible manner to help small organizations protect their information and systems.

NISTIR 8286NISTIRFinal
2020-10

NISTIR 8286 - Integrating Cybersecurity and Enterprise Risk Management (ERM)

Provides guidance on integrating cybersecurity risk management into broader enterprise risk management programs. Helps organizations communicate cybersecurity risks in the context of overall business risks to senior leadership.

NISTIR 8286ANISTIRFinal
2021-11

NISTIR 8286A - Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management

Provides detailed guidance on identifying and estimating cybersecurity risks within the context of enterprise risk management. Extends NISTIR 8286 with methods for creating cybersecurity risk registers and quantifying risk exposure.

NISTIR 8286BNISTIRFinal
2022-02

NISTIR 8286B - Prioritizing Cybersecurity Risk for Enterprise Risk Management

Provides guidance on prioritizing cybersecurity risks as part of enterprise risk management processes. Describes approaches for comparing and ranking cybersecurity risks alongside other enterprise risks to inform resource allocation.

NISTIR 8286CNISTIRFinal
2022-02

NISTIR 8286C - Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight

Describes how to stage and communicate cybersecurity risk information for enterprise risk management and governance oversight. Addresses risk aggregation, normalization, and presentation for executive-level decision making.

NISTIR 8374NISTIRFinal
2022-02

NISTIR 8374 - Cybersecurity Framework Profile for Ransomware Risk Management

Provides a Cybersecurity Framework profile with security objectives for preventing, responding to, and recovering from ransomware events. Maps CSF subcategories to specific actions organizations can take to manage ransomware risk.

NISTIR 8596NISTIRDraft
2025-12

NISTIR 8596 - Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile)

Provides guidance for managing cybersecurity risks inherent to AI systems using CSF 2.0. Addresses three focus areas: securing AI system components, conducting AI-enabled cyber defense, and thwarting AI-enabled cyberattacks.

NISTIR 8228NISTIRFinal
2019-06

NISTIR 8228 - Considerations for Managing IoT Cybersecurity and Privacy Risks

Helps organizations understand and manage cybersecurity and privacy risks associated with IoT devices throughout their lifecycles. Identifies three high-level risk considerations and three mitigation goals for device security, data security, and individual privacy.

NISTIR 8276NISTIRFinal
2021-02

NISTIR 8276 - Key Practices in Cyber Supply Chain Risk Management

Presents key practices for managing cybersecurity risks in supply chains based on industry interviews and case studies. Provides actionable recommendations for integrating cybersecurity into the system lifecycle, determining supplier criticality, and mentoring suppliers.

NISTIR 8286DNISTIRFinal
2022-11

NISTIR 8286D - Using Business Impact Analysis to Inform Risk Prioritization and Response

Extends traditional business impact analysis beyond availability to include confidentiality and integrity impact analyses. Helps enterprise leaders determine critical and sensitive assets and establish risk appetite and tolerance as input to cybersecurity risk management.

NISTIR 8259BNISTIRFinal
2021-08

NISTIR 8259B - IoT Non-Technical Supporting Capability Core Baseline

Defines non-technical capabilities generally needed from IoT device manufacturers and third parties to support common cybersecurity controls. Covers documentation, information reception, information dissemination, and education and awareness capabilities.

NISTIR 8183r1NISTIRFinal
2020-10

NISTIR 8183 Rev. 1 - Cybersecurity Framework Manufacturing Profile

A CSF Community Profile for manufacturing environments including OT, ICS, and SCADA systems. Provides a voluntary risk-based roadmap for reducing cybersecurity risk aligned with manufacturing sector goals across low, moderate, and high impact levels.

NISTIR 8425NISTIRFinal
2022-09

NISTIR 8425 - Profile of the IoT Core Baseline for Consumer IoT Products

Documents the consumer profile of NIST's IoT core baseline, identifying cybersecurity capabilities commonly needed for consumer IoT products. Foundational to the US Cyber Trust Mark program for IoT device labeling.

NISTIR 8401NISTIRFinal
2022-12

NISTIR 8401 - Satellite Ground Segment: Applying the Cybersecurity Framework

Applies the Cybersecurity Framework to the ground segment of space operations, focusing on command and control of satellite buses and payloads. Part of NIST's broader space cybersecurity effort.

NISTIR 8323r1NISTIRFinal
2023-01

NISTIR 8323 Rev. 1 - Foundational PNT Profile: Applying the Cybersecurity Framework for PNT Services

Helps organizations identify systems dependent on positioning, navigation, and timing (PNT) services, select appropriate PNT sources, detect disturbances and manipulation, and manage risk to PNT services including GPS.

NISTIR 8170NISTIRFinal
2021-08

NISTIR 8170 - Approaches for Federal Agencies to Use the Cybersecurity Framework

Provides eight example approaches for federal agencies to implement the Cybersecurity Framework in a manner that complements existing NIST security and privacy standards. Supports ERM alignment with OMB and FISMA requirements.

AI Series(1)

AI RMF 1.0AIFinal
2023-01

Artificial Intelligence Risk Management Framework (AI RMF 1.0)

Provides a framework for managing risks associated with artificial intelligence systems throughout their lifecycle. Organized around four functions (Govern, Map, Measure, Manage) to help organizations develop trustworthy AI systems.