Search the web
Sign In
New User? Sign Up
ShareHIPAA · Share HIPAA
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Message search is now enhanced, find messages faster. Take it for a spin.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
NIST Computer Security Division Releases 2 documents (1 draft and 1   Message List  
Reply | Forward Message #613 of 641 |

 

 


From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of O'Reilly, Patrick D.
Sent: Tuesday, June 16, 2009 1:03 PM
To: Multiple recipients of list
Subject: NIST Computer Security Division Releases 2 documents (1 draft and 1 final)

 

NIST Computer Security Division announces the release of two documents (1 draft NIST IR and 1 final Special Publication (SP)).

 

 #1: SP 800-46 Revision 1, Guide to Enterprise Telework and Remote Access Security, has been published as final. SP 800-46 Revision 1 is intended to help organizations understand and mitigate the risks associated with the technologies they use for telework. The guide emphasizes the importance of securing sensitive information stored on telework devices and transmitted across external networks, and it also provides recommendations for selecting, implementing, and maintaining the necessary security controls. Draft SP 800-46 Revision 1 is a comprehensive update to the original SP 800-46, which was published in 2002.

 

URL to SP 800-46 Rev. 1:

http://csrc.nist.gov/publications/PubsSPs.html#800-46-rev1

 

 

#2: The second public draft of NIST IR 7502, The Common Configuration Scoring System (CCSS): Metrics for Software Security Configuration Vulnerabilities, is now available for public comment. This report proposes a specification for CCSS, a set of standardized measures for the severity of software security configuration vulnerabilities. NISTIR 7502 also provides examples of how CCSS measures and scores would be determined. Once CCSS is finalized and CCSS measures for products are available, organizations can use CCSS to help them make security decisions based on standardized, quantitative vulnerability data.

 

NIST requests comments on Draft NISTIR 7502 by July 17, 2009. Please submit comments to IR7502comments@... with "Comments IR 7502" in the subject line.

 

URL to Draft NIST IR 7502:

http://csrc.nist.gov/publications/PubsDrafts.html#NISTIR_7502

 



Tue Jun 16, 2009 5:34 pm

hitrecruiting
Offline Offline
Send Email Send Email

Forward
Message #613 of 641 |
Expand Messages Author Sort by Date

_____ From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of O'Reilly, Patrick D. Sent: Tuesday, June 16, 2009 1:03 PM To: Multiple recipients...
Barbara McGowin
hitrecruiting
Offline Send Email
Jun 16, 2009
5:58 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help