Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

NIST Updates Computer Security Guides

Guidelines focus on wireless security and protecting mobile devices from intrusion.

10 New Mobile Government Apps
10 New Mobile Government Apps
(click image for larger view and for slideshow)
The National Institute of Standards and Technology has released updated guidance on how federal agencies and businesses can deal with network attacks and malware.

The advice comes in the form of two publications that have been revised to reflect the latest in security best practices: NIST's Guide to Intrusion Detection and Prevention Systems and Guide to Malware Incident Prevention and Handling for Desktop and Laptops. The agency is seeking public comments on the draft publications before releasing them in final form.

This is the first revision to the intrusion detection and prevention system (IDPS) guide since its original release in February 2007. The most substantive changes are in the areas of mobile devices and wireless networking, including the emergence of the 802.11n wireless standard.

"Wireless technology is used so much more than it used to be, and there are many more wireless threats now," said Karen Scarfone, a guest researcher at NIST and co-author of the revised Guide to Intrusion Detection and Prevention Systems.

[ For more on NIST's updated security guidelines, see Uncle Sam Wants To Secure Your Smartphone. ]

In other areas, intrusion detection hasn't changed much, according to Scarfone. In her research, she said, some sources said IDPSs aren't "quite as valuable as they used to be," raising questions of whether they need to improve or are the right tools at all.

The guide covers wireless, network-based, and host-based intrusion detection, as well as network behavior analysis, architecture, detection methodologies, and security capabilities. "They'll monitor IP addresses, protocols--it could even be a geographic location--to try to assess whether activity is benign or malicious," Scarfone said. The deadline for filing comments on the draft IDPS guide is August 31.

NIST also revised its Guide to Malware Incident Prevention and Handling for Desktops and Laptops, which has been updated to correspond with a refreshed version of its Computer Security Incident Handling Guide, expected to be issued in final form later this summer.

Scarfone, who co-authored both guides, said the malware incident guide was updated "to take today's threats into account." Whereas malware in the past tended to be fast-spreading and easy to spot, it now spreads more slowly, eventually leading to exfiltration of sensitive data, she said.

Earlier this month, NIST issued new guidelines for securing mobile devices.

The Office of Management and Budget demands that federal agencies tap into a more efficient IT delivery model. The new Shared Services Mandate issue of InformationWeek Government explains how they're doing it. Also in this issue: Uncle Sam should develop an IT savings dashboard that shows the returns on its multibillion-dollar IT investment. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-30477
PUBLISHED: 2021-04-15
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing webhooks to private streams meant that an outgoing webhook bot could be used to send messages to private streams that the user was not intended to be able to send messages to.
CVE-2021-30478
PUBLISHED: 2021-04-15
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (previously is_api_super_user) resulted in users with this permission being able to send messages appearing as if sent by a system bot, including to other organizations hosted by the sa...
CVE-2021-30479
PUBLISHED: 2021-04-15
An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature resulted in guest users being able to receive message traffic to public streams that should have been only accessible to members of the organization.
CVE-2021-30487
PUBLISHED: 2021-04-15
In the topic moving API in Zulip Server 3.x before 3.4, organization administrators were able to move messages to streams in other organizations hosted by the same Zulip installation.
CVE-2020-36288
PUBLISHED: 2021-04-15
The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused ...