Computer Security Division 2011 annual report
2012
The United States (U.S.) economy and U.S. citizens are reliant on information technology (IT).Federal agencies and the private sector cannot function without IT.Protecting IT, including its information and the information infrastructure, is critical for the Nation.The Computer Security Division (CSD), a component of the Information Technology Laboratory at the National Institute of Standards and Technology (NIST) is responsible for developing standards, guidelines, tests and metrics for the protection of non-national security federal information and information systems.The CSD standards, guidelines, tests and metrics have also become leading resources for information security in the private sector.During fiscal year 2011 (FY2011), CSD extended its research and development agenda for high-quality, cost-effective security and privacy mechanisms to foster improved information security across the federal government and the greater information security community.This included addressing challenges for the protection of information and information systems for enterprise environments as well as in cloud computing and mobile infrastructures.In addition, we explored processes and mechanisms to protect personally identifiable information through the application of privacy controls and privacy-enhancing technologies.Our research also extended to non-traditional forms of IT including cyber-physical systems and security for sensor devices.Our ability to interact with the broad federal community continues to be critical to our success.This interaction helps to ensure that our research is consistent with national objectives related to or impacted by information security.This interaction is most prominent in our strengthened collaborations with the Department of Defense, the Intelligence Community, and the Committee on National Security Systems to establish a common foundation for information security across the federal government.The FY2011 release of Special Publication 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, developed by the Joint Task Force Transformation Initiative Interagency Working Group, is not only leading to more uniform and consistent ways to manage risks, but it is also providing a strong basis for greater information sharing among stakeholders.The success of many of our technical programs is dependent on our partnership with industry.In FY2011, we continued to drive greater adoption of security automation protocols by major information technology manufacturers, as well as new and innovative applications of security automation to more diverse use cases including continuous monitoring and health information technology.Lower in the stack, CSD worked with the computer hardware industry on mechanisms to improve security at the hardware layer.Recently issued guidelines on protecting the BIOS in laptop and desktop computers have already had a major impact with several hardware vendors offering products intended to meet the guidelines, laying the foundation for more secure systems.Other significant highlights of our work in FY2011 include NIST's leadership role in supporting the establishment of the Federal Risk and Authorization Management Program (FedRAMP), which facilitates a standard approach for provisional security automation of cloud computing products and services; and in hosting the third round of the SHA-3 competition to determine a successor to the current government-approved cryptographic hash algorithm.For many years, the Computer Security Division (CSD) has made great contributions to help secure the nation's sensitive information and information systems.Looking forward to FY2012, CSD will continue to lead in areas as diverse as risk management and continuous monitoring, awareness and outreach, privacy-enhancing cryptography, security for virtual environments, and mobile computing technology security.CSD will also focus on aligning our resources to not only develop and apply innovative security technologies, but also to enhance our ability to address current and future computer and information security challenges faced by critical national and international priorities.