cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://tag-security.cncf.io
Other
2.09k stars 518 forks source link

NIST / IEEE Candidate Collaborators / Groups #21

Closed knowlengr closed 3 years ago

knowlengr commented 6 years ago

As requested, a list of groups with potential liaison and socialization opportunities

  1. NIST Big Data WG - Mark U can liaise

  2. IEEE P2675 DevOps Security https://standards.ieee.org/develop/project/2675.html

  3. IEEE Product Safety Engineering Society http://ewh.ieee.org/soc/pses/

  4. NIST Cloud Security SP 500-291 https://www.nist.gov/sites/default/files/documents/itl/cloud/NIST_SP-500-291_Jul5A.pdf

  5. IEEE 7009 - Standard for Fail-Safe Design of Autonomous and Semi-Autonomous Systems WG https://standards.ieee.org/develop/project/7009.html

  6. IEEE P1915.1 - Standard for Software Defined Networking and Network Function Virtualization Security https://standards.ieee.org/develop/project/1915.1.html

  7. IEEE P7000 (series of interrelated standards in development, including privacy, transparency, etc. related to ethical concerns in autonomous systems). https://standards.ieee.org/develop/project/7000.html

anweiss commented 6 years ago

Adding a few more for NIST. These all roll up to the Computer Security Division (CSD) of the Information Technology Laboratory (ITL). The NIST National Cybersecurity Center of Excellence (NCCoE) is also a key publisher of security standards and recommendations and is an FFRDC (Federally Funded Research and Development Center) created as a result of Executive Order 13636, "Improving Critical Infrastructure Cybersecurity".

NIST SP 800-53: https://nvd.nist.gov/800-53

NIST SP 800-37 (aka RMF): https://csrc.nist.gov/publications/detail/sp/800-37/rev-1/final

NIST SP 800-190: https://csrc.nist.gov/publications/detail/sp/800-190/final

Security Content Automation Protocol (SCAP): https://csrc.nist.gov/projects/security-content-automation-protocol:

Open Security Controls Assessment Language (OSCAL): https://csrc.nist.gov/Projects/Open-Security-Controls-Assessment-Language:

Software Identification (SWID) Tagging: https://csrc.nist.gov/publications/detail/sp/800-66/rev-1/final

stale[bot] commented 4 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

TheFoxAtWork commented 4 years ago

@knowlengr wanted to check on this - are there any associated actions with this?

stale[bot] commented 3 years ago

This issue has been automatically marked as inactive because it has not had recent activity.

TheFoxAtWork commented 3 years ago

closing issue in favor of linked #638