Here are some NIST publications that may
be helpful in you compliance with the HIPAA Security Rule.
If you haven’t taken a look at NIST
SP 800-100 Information Security Handbook: A Guide for Managers, now is a great
time (#4 below). You can access it from the NIST special publications computer
security resource center at http://csrc.nist.gov/publications/nistpubs/
Regards,
Barbara McGowin
(843) 824-8537
Connecting Health Care Organizations with
People,
Products and Services to Achieve HIPAA
Compliance.
From:
compsecpubs@... [mailto:compsecpubs@...] On Behalf Of Patrick O'Reilly
Sent: Monday, March 19, 2007 11:30
AM
To: Multiple recipients of list
Subject: Four NIST Special
Publications updated
Revisions have been made to the following 4 NIST Special Publications,
which are available at http://csrc.nist.gov/publications/nistpubs/index.html
on the NIST's CSRC website:
1. SP 800-56A, Recommendation for Pair-Wise Key Establishment
Schemes Using Discrete Logarithm Cryptography. This revised document is also
available at http://csrc.nist.gov/CryptoToolkit/tkkeymgmt.html. The
revision to this document is identified in Appendix E. It allows the dual use
of keys during certificate requests only.
2. SP 800-57, Part 1, Recommendation for Key Management. This
revised document is also available at http://csrc.nist.gov/CryptoToolkit/tkkeymgmt.html.
The revisions to this document are listed in Appendix D. The latest revisions
allow the dual use of keys during certificate requests only.
3. SP 800-90, Recommendation for Random Number Generation Using
Deterministic Random Bit Generators. This revised document is also available at
http://csrc.nist.gov/CryptoToolkit/tkrng.html.
The revisions to this document are listed in Appendix I. These revisions
include the insertion of a step in the Dual_EC_DRBG specification that
was inadvertently omitted that is needed for the DRBG to provide backtracking
resistance.
4. Special Publication 800-100 Information Security Handbook: A Guide for
Managers. A couple of changes were made to a Table and to a Figure
in Chapter 10. Go to page 5 of 178 for further details.
---------------------
To unsubscribe from this list send e-mail to listproc@... and type in the body of
the e-mail message:
Reminder: You need to make sure that you are unsubscribing from the
original e-mail address that you subscribed to this list from. If not,
you will receive an error message. If that is the case, send
patrick.oreilly@... an e-mail and I will look into resolving the
problem. Thanks.