Tag: nist
-
NIST AI RMF vs. NIST SP 800-53: Which Framework Do You Need for AI Risk?
<div cla First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/nist-ai-rmf-vs-nist-sp-800-53-which-framework-do-you-need-for-ai-risk/
-
NIST Frameworks and SOC 2 Reporting via Continuum GRC Services
As organizations navigate an increasingly complex regulatory environment in 2026, integrating NIST frameworks with SOC 2 reporting offers a strategic advantage that reduces audit fatigue while strengthening overall governance, risk, and compliance postures. Continuum GRC enables this interoperability through unified control mapping that aligns NIST SP 800-53, NIST SP 800-171 Rev 3, and CMMC 2.0″¦…
-
FedRAMP 20x Modernization: Continuous Monitoring Audits
FedRAMP 20x represents a fundamental evolution in cloud authorization, replacing static annual assessments with dynamic, real-time continuous monitoring audits that demand integrated governance and automated evidence pipelines. This modernization requires organizations to embed NIST 800-53 controls into operational workflows rather than treating compliance as a periodic checkpoint. FedRAMP Continuous Monitoring Audits Under 20x Modernization In”¦…
-
NIST Asks for Help Putting People First in Cybersecurity
NIST released a human-centered cybersecurity concept paper and wants public feedback by Sept 30, 2026, to shape people-first security guidelines. First seen on securityonline.info Jump to article: securityonline.info/nist-human-centered-cybersecurity-concept-paper/
-
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. First seen on cyberscoop.com Jump to article: cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/
-
The End of Centralized Enrichment: What NIST’s NVD Shift Means for Vulnerability Management
There’s an assumption baked into most vulnerability management programs that nobody ever wrote down, because nobody had to. When a CVE gets published, NVD enriches it. You get a severity score, product mappings, weakness categorization. All the context your tools and workflows need to actually do something. It was just how the system worked. In..…
-
CMMC 2.0 Audits: Lazarus Alliance Compliance Assessments
In 2026, defense contractors face heightened scrutiny under the CMMC 2.0 Final Rule, where compliance assessments have shifted from preparatory exercises to mandatory gatekeepers for contract eligibility. Lazarus Alliance brings first-hand audit experience to help organizations navigate this landscape with precision, integrating CMMC requirements with broader frameworks like NIST 800-171 and ISO 27001. CMMC 2.0″¦…
-
Claude Mythos Finds Weakness in NIST Post-Quantum Candidate
Anthropic’s Claude model helped uncover a weakness in a post-quantum digital signature scheme that was being considered for a U.S. government standard, prompting its developers to withdraw it from the competition. Anthropic said Claude Mythos Preview found a faster method for recovering keys from HAWK, a candidate in a NIST competition seeking alternatives to widely..…
-
Outdated VPNs should be purged from federal agencies, senator says
Intelligence Committee member Ron Wyden wants CISA, OMB and NIST to lead a federal effort to rout out obsolete VPNs from the U.S. government. First seen on therecord.media Jump to article: therecord.media/federal-purge-outdated-vpns-wyden-letter
-
DNS wird kritischer Bestandteil resilienter IT-Umgebungen – Wie NIST mit SP 800-81r3 die DNS-Sicherheit neu definiert
First seen on security-insider.de Jump to article: www.security-insider.de/nist-sp-800-81r3-dns-sicherheit-a-59634f631e7fe216d1220ef15453c453/
-
Continuous Red Teaming: Warum KI-Systeme permanent getestet werden müssen
Continuous Red Teaming: Einmalige Sicherheitstests reichen für KI nicht aus. NIST zeigt, warum Continuous Red Teaming und Runtime Protection zum neuen Standard werden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/continuous-red-teaming-warum-ki-systeme-permanent-getestet-werden-muessen/a45790/
-
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
The National Institute of Standards and Technology (NIST) scaled back on the number of CVEs it selects for in-depth analysis, but the move has produced mixed results, according to researchers. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/nist-enrichment-reductions-cve-coverage-accuracy
-
NIST seeks public feedback on updated IoT security guidelines
First seen on scworld.com Jump to article: www.scworld.com/brief/nist-seeks-public-feedback-on-updated-iot-security-guidelines
-
How to use NIST and ISO frameworks to govern AI agents
Security leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/12/nist-iso-frameworks-govern-ai-agents/
-
Auditors Rip NIST Management of NVD Program
Auditors Accuse Agency of Mismanagement and Program Overlap. Management by the National Institute of Standards and Technology of a repository of vulnerability data came under sharp criticism from federal auditors who said the agency approached it with lack of strategic planning and decisive action. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/auditors-rip-nist-management-nvd-program-a-31848
-
Inspector general finds NIST mistakes have made vulnerability database ineffective
NIST’s National Vulnerability Database (NVD) backlog mushroomed from 13,000 unprocessed security vulnerabilities in February 2024 to more than 27,000 by the end of 2025, “undermining the NVD’s utility and public trust,” according to an inspector general report. First seen on therecord.media Jump to article: therecord.media/nist-mistakes-vulnerability-database-inspector-general
-
How NIST fumbled management of the National Vulnerability Database
A US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/01/nist-nvd-management-problems/
-
7 tips for accelerating cyber incident recovery
Tags: attack, awareness, backup, breach, business, ceo, cio, ciso, cloud, communications, control, cyber, cybersecurity, data, defense, finance, framework, governance, incident, incident response, infection, insurance, international, lessons-learned, malicious, malware, monitoring, nist, risk, service, technology, threat, updateEmphasize scoping and containment from the outset: Because you can’t recover from what you can’t stop, scoping and containment should be the absolute first priority during incident recovery, says Amit Basu, CIO and CISO at freight shipping firm International Seaway.”Before anything else, you must stop the bleeding,” he says. This means understanding the true scope…
-
10 wichtige CloudTools für Unternehmenssicherheit und Audit-Bereitschaft
Cloud-Compliance im Jahr 2026 ist weit mehr ist als die Vorbereitung auf Audits: In hybriden und Multi-Cloud-Umgebungen wird sie zum zentralen Maßstab für operative Resilienz, Risikotransparenz und regulatorische Sicherheit. Unternehmen stehen unter wachsendem Druck, Anforderungen aus Frameworks wie NIST, ISO27001, SOC2, PC DSS, HIPAA, DSGVO, NIS2 und DORA kontinuierlich nachzuweisen und zwar in Echtzeit […]…
-
NIST will test three major tech firms’ frontier AI models for cybersecurity risks
After Anthropic’s announcement of Claude Mythos, agencies across the government are racing to get ahead of new AI models’ potential dangers. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/nist-ai-model-testing-caisi-google-microsoft/819452/
-
AI finds 20-year-old bugs in PostgreSQL and MariaDB
Tags: ai, breach, credentials, cve, exploit, flaw, github, injection, nist, rce, remote-code-execution, sql, vulnerabilityInadequate JSON parsing allowed RCE on the MariaDB server: In MariaDB, a buffer overflow bug, tracked as CVE-2026-32710, was found in the JSON_SCHEMA_VALID() function using Xint Code. The vulnerability allows an authenticated user to trigger a crash, which, under controlled conditions, could be escalated into remote code execution.Compared to the PostgreSQL flaws, exploitation here is…
-
Cyberresilienz: Ausfallzeiten nach Sicherheitsverstoß minimieren
Ausfallzeiten sind der entscheidende Schadenstreiber nicht nur der Angriff selbst, sondern die Dauer der Wiederherstellung bestimmt die Gesamtkosten. Prävention genügt nicht mehr Unternehmen müssen gleichermaßen in Erkennung, Reaktion und Wiederherstellung investieren. NIST CSF 2.0 bietet ein klares Resilienz”‘Framework Govern, Identify, Protect, Detect, Respond, Recover strukturieren Risiken und Prioritäten. Detect, Respond und Recover… First seen on…
-
Cyberresilienz:Ausfallzeiten nach Sicherheitsverstoß minimieren
Ausfallzeiten sind der entscheidende Schadenstreiber nicht nur der Angriff selbst, sondern die Dauer der Wiederherstellung bestimmt die Gesamtkosten. Prävention genügt nicht mehr Unternehmen müssen gleichermaßen in Erkennung, Reaktion und Wiederherstellung investieren. NIST CSF 2.0 bietet ein klares Resilienz”‘Framework Govern, Identify, Protect, Detect, Respond, Recover strukturieren Risiken und Prioritäten. Detect, Respond und Recover… First seen on…
-
Vulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AI
Tags: access, ai, api, attack, automation, business, ciso, compliance, control, cve, cybersecurity, data, exploit, framework, group, identity, Internet, login, nist, okta, service, supply-chain, threat, update, vulnerability, vulnerability-managementDetecting a vulnerability is easy. Finding the person responsible for fixing it is where remediation programs often break down. See how Tenable Hexa AI uses MCP to connect your exposure data to your identity provider, automating the hunt for asset owners in seconds. Key takeaways The accountability gap is the real bottleneck. Finding a vulnerability…
-
NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover
NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover The NIST Cybersecurity Framework is a useful way to organise cybersecurity work around business risk. For UK SMEs, that matters because most teams do not have the time or budget to do everything at once. A framework gives you……
-
NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover
NIST Cybersecurity Framework for UK SMEs: A Practical Guide to Identify, Protect, Detect, Respond, and Recover The NIST Cybersecurity Framework is a useful way to organise cybersecurity work around business risk. For UK SMEs, that matters because most teams do not have the time or budget to do everything at once. A framework gives you……

