Computer Security Division 2006 annual report
2007
I n 2006, the Computer Security Division (CSD) of NIST's Information Technology Laboratory engaged in a number of initiatives for improving information system security in the Federal government.Both automated tool development and increased outreach activities were initiated to communicate information technology risks, vulnerabilities, and protection requirements-particularly for new and emerging technologies.The CSD continued to research and publicize IT vulnerabilities.Emphasis was placed on development of techniques for affordable security and privacy mechanisms for Federal information systems.We continued to develop standards, metrics, tests, and validation programs to promote, measure, and validate security in systems and services.We also developed guidance to increase secure IT planning, implementation, management, and operation.Affected customer organizations include federal, state, and local governments, the healthcare community, colleges and universities, small businesses, the private sector, and the international community.This year also brought additional security challenges along with the everadvancing improvements in technology, improvements in citizens' access to government systems and information, faster communications, reduced paperwork, and streamlined processes.Our work this year met those security challenges with a breadth and depth of security areas intended to allow our customers to accomplish their missions while providing for confidentiality of their information, maintaining the availability of their resources and ensuring the integrity of their data.High priority was given to initiating a competitive program for replacement of current secure hashing algorithms employed in data source and content integrity protection mechanisms.One highlight of our work in 2006 was expanding and refining the Federal Information Processing Standards (FIPS) 201 standard suites and supporting implementation of Homeland Security Presidential Directive 12's mandate for common procedures and mechanisms for identity verification of Federal employees and contractors.We also continued our progress in fulfilling the mandates of the Federal Information Security Management Act of 2002 (FISMA), which resulted in revision of NIST Special Publication (SP) 800 53, Recommended Security Controls for Federal Information Systems; coordination of the draft SP 800-53A, Guide for Assessing the Security Controls in Federal Information Systems; and publication of FIPS 200, Minimum Security Requirements for Federal Information and Information Systems.The Cryptographic Module Validation Program was expanded to include 13 laboratories in 4 countries and continues to ensure the protection of sensitive information in computer and telecommunication systems, including voice systems.Research and development efforts included security for Radio Frequency IDentification (RFID) devices and other wireless communications systems, digital forensic tools and methods, Internet security protocols, and expansion of the National Vulnerability Database.We will continue to strive to provide products and services that protect and enhance confidence in the nation's information technology systems.