FB pixel

NIST adds flexibility, digital format to security requirements for federal contractors

NIST adds flexibility, digital format to security requirements for federal contractors
 

The U.S. National Institute of Standards and Technology has updated its guidance for how businesses working with the federal government should protect sensitive data with biometrics and other digital technologies.

NIST issued the new “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations” (NIST Special Publication 800-171, Revision 3), and companion document “Assessing Security Requirements for Controlled Unclassified Information” (NIST SP 800-171A, Revision 3) based on its source catalog of security and privacy controls, as outlined in SP 800-53 and SP 800-53A, according to an announcement.

The controls laid out over the 120 pages of SP 800-171 address comprehensive security requirements for federal contractors, from access control to awareness and training, risk assessment to maintenance and incident response. Biometrics are not necessarily required, but are noted among possible technologies for use in identification and authentication, particularly for multi-factor authentication, in authenticator management and physical access control.

SP 800-171r3 updates the guidance for consistency with SP 800-53r5. It provides restructured security requirements to match the controls specified in SP 800-53r5, introduces organization-defined parameters (ODPs), streamlined criteria for tailoring, and recategorized controls based on those criteria. SP 800-171Ar3 adjusts the terminology for assessment procedures to line with the security and privacy controls and builds in ODPs. An FAQ explains that the purpose of ODPs is “to provide flexibility to federal agencies in tailoring controls to support specific organizational missions or business functions and to manage risk.”

The safeguards are now available in machine-readable formats like JSON and Excel through NIST’s Cybersecurity and Privacy Reference Tool.

“Toolmakers often want to import relevant sections of the guidance directly into an electronic form for easier reference and use,” says NIST’s Ron Ross, one of the authors of the revised document. “Providing the guidance in these additional formats will allow them to do that. It will help a wider group of users to understand the requirements and implement them more quickly and efficiently.”

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

World Economic Forum looks to get a GRIP on global regulatory environment

A new piece written by the World Economic Forum (WEF)’s head of digital inclusion, Kelly Ommundsen, looks at the gap…

 

Respected legal authority frames age assurance legislation as segregation, suppression

Language plays a fundamental role in how concepts and technologies are introduced into and evolve alongside society. The debate over…

 

New high scores in fingerprint biometrics accuracy for Dermalog, ROC, Innovatrics

New algorithms submitted to the U.S. National Institute of Standards and Technology for its Proprietary Fingerprint Template (PFT) Evaluation have…

 

Australia’s safety code for search tools takes effect, with age verification rules

Like its counterparts in the EU and UK, Australia’s digital regulator is beginning to formalize its online safety codes. The…

 

Age verification coming to major video game mod site in EU, UK

Want to make sweet love to that frost giant who lives in the fjord? You may have to prove your…

 

Ecuador upgrades border ID verification with Regula forensic devices

Ecuador is upgrading its border identity verification systems by deploying a range of Regula’s ID document examination devices. The deployment…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events