惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
人人都是产品经理
人人都是产品经理
博客园 - 三生石上(FineUI控件)
aimingoo的专栏
aimingoo的专栏
U
Unit 42
GbyAI
GbyAI
H
Help Net Security
A
Arctic Wolf
SecWiki News
SecWiki News
K
Kaspersky official blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
Blog — PlanetScale
Blog — PlanetScale
B
Blog
Spread Privacy
Spread Privacy
L
Lohrmann on Cybersecurity
C
Check Point Blog
O
OpenAI News
Microsoft Security Blog
Microsoft Security Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
Webroot Blog
Webroot Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
P
Palo Alto Networks Blog
A
About on SuperTechFans
S
SegmentFault 最新的问题
Recent Announcements
Recent Announcements
S
Schneier on Security
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
Jina AI
Jina AI
The Hacker News
The Hacker News
V2EX - 技术
V2EX - 技术
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
腾讯CDC
罗磊的独立博客
G
GRAHAM CLULEY
L
LINUX DO - 热门话题
雷峰网
雷峰网
博客园 - 【当耐特】
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
美团技术团队
M
MIT News - Artificial intelligence
Engineering at Meta
Engineering at Meta
Hacker News: Ask HN
Hacker News: Ask HN
S
Security Affairs
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客

News and Events Feed by Topic

Securing AI Data Center: Architecture, Security Posture, and Emerging Standards New NCCoE Project: Asset Management and Visibility for Operational Technology (OT) Environments NIST Guidelines for Secure Remote Access in Water and Wastewater Systems NIST Workshop on Hardware CPE and CVSS Updates NCCoE Two-Pager Now Available: Effective OT Backup Management The Department of Commerce’s CHIPS Program Announces a Letter of Intent with Coherent for up to $50 Million to Expand Indium Phosphide Production Now Available: Practical Guidelines for Preventing and Mitigating Ransomware NIST NCCoE Genomic Data PETs Testbed & Dioptra Webinar NIST Mathematical Proof Supports Transition to a Continuous-Monitor-and-Update Security Model for AI Systems NCCoE Cybersecurity Connections Event: Accelerating the Adoption of Mobile Driver's Licenses NIST Expands AI Consortium’s Scope, Calls for New Members Now Available: NIST SP 1800-41, Responding to and Recovering from a Cyber Attack NCCoE Manufacturing Project Update NIST NCCoE Cyber AI Profile Virtual Working Session Series: Usability of the Profile Draft PNT Profile Updated to Align with NIST CSF 2.0 NIST NCCoE Cyber AI Profile Virtual Working Session Series: Extending the Technical Content CAISI Signs Agreements Regarding Frontier AI National Security Testing With Google DeepMind, Microsoft and xAI NIST NCCoE Cyber AI Profile Virtual Working Session Series: Updates to Profile Elements and Contents NICE Releases NICE Framework Components v2.2.0 Adoption of Mobile Driver’s Licenses for Financial Institutions Webinar NIST Updates NVD Operations to Address Record CVE Growth New Publication: Automation of the NIST Cryptographic Module Validation Program NIST Workshop on AI Incident Management Cybersecurity for IoT Workshop: Future Directions New Live Guidelines for Secure Software Development, Security, and Operations Practices Workshop on Blockchain and Distributed Ledger Technologies Improving the Nation’s Cybersecurity - an Open Forum NIST Guidelines on Implementing Mobile Driver’s Licenses for Financial Institutions NICE Webinar: Beyond Technical Skills - The Human Element of a Cyber Career Artificial Intelligence (AI) for Manufacturing Workshop Safeguarding Health Information: Building Assurance through HIPAA Security 2026 Workshop on Blockchain and Distributed Ledger Technologies 2026 Time and Frequency Seminar NCCoE Project Portfolio Webinar MLXN: Machine Learning for X-ray and Neutron Scattering Comment Now: Draft Guidelines on Data Classification Practices Technologies and Use Cases for Smart Standards NIST Allocates Over $3 Million to Small Businesses Advancing AI, Biotechnology, Semiconductors, Quantum and More Building the Strategic Supply Chain Network Iris Experts Group Annual Meeting New Concept Paper on Identity and Authority of Software Agents SUSHI@NIST: Rolling Next-Generation Secure Hardware into Standards Now Available! Transit Cybersecurity Framework Community Profile Now Available: NIST NCCoE Project Portfolio Cyber AI Workshop #2 NIST Launches Centers for AI in Manufacturing and Critical Infrastructure Apply on USAJobs: Open CAISI Position for an AI Research Scientist Securing Smart Speakers for Home Health Care: NIST Offers New Guidelines Secure Software Development Framework (SSDF) Version 1.2 is Available for Public Comment Just Published! Final NIST Telehealth Smart Home Integration Cybersecurity White Paper Draft NIST Guidelines Rethink Cybersecurity for the AI Era Comment & Save the Date Now! NIST Cyber AI Profile Preliminary Draft & Workshop Final NCCoE IoT Secure Onboarding Publications Now Available! Mobile Driver’s License Project Update Webinar NCCoE Cybersecurity Connections – Strengthening the Cybersecurity Workforce New Draft White Paper | PQC Migration: Mappings to Risk Framework Docs Now Available: NIST Final SP 1800-37, Addressing Visibility Challenges with TLS 1.3 NIST Awards More Than $3 Million to Support Cybersecurity Workforce Development Across 13 States Feedback Requested: NIST Cryptographic Module Validation Program White Paper New NIST NCCoE Mobile Drivers Licenses Project Resources Now Available! CSF 2.0 Webinar Series: Deep-Dive into the CSF 2.0 Govern Function to Improve Cybersecurity Final Publication Available: NIST IR 8523, Multi-Factor Authentication for Criminal Justice Information Systems Federal Investments in IoT Infrastructure Offer 10-20x Return, NIST Study Finds Final NIST IR 8349 Released: Characterize & Secure Your IoT Devices We Want Your Feedback! Developing a Transit Cybersecurity Framework Community Profile Advances in Automation of Quantum Dot Devices Control Empowering Future Innovators: NIST CTL Connects Cybersecurity Students with Real-World Research NIST Awards Over $1.8 Million to Small Businesses Advancing AI, Semiconductors, Additive Manufacturing and More NIST Researchers Demonstrate that Superconducting Neural Networks Can Learn on Their Own STPPA8: Special Topics on Privacy and Public Auditability — Event 8: Experimenting with Privacy-Enhancing Cryptography (PEC) Implementations NIST Finalizes ‘Lightweight Cryptography’ Standard to Protect Small Devices NIST Releases Test Tools to Accelerate Adoption of Emerging Route Leak Mitigation Standards Second Seminar on Building an In-Space Circular Economy Lessons Learned from the Consortium: Tool Use in Agent Systems
NIST Revises Security and Privacy Control Catalog to Improve Software Update and Patch Releases
Chad Boutin · 2025-08-27 · via News and Events Feed by Topic
  • A revision to NIST’s catalog of security and privacy safeguards aims to help organizations better manage risks related to software updates and patches.
  • The catalog revision is part of NIST’s response to a recent executive order on strengthening the nation’s cybersecurity.
  • Completed with the help of a real-time commenting system, the revision is available in several different formats, some of which are machine-readable.
A laptop screen displays the words “software update” with a progress bar.

Credit: fadfebrian/Shutterstock

Most software needs updating after its initial release to address bugs, newly identified vulnerabilities, and revisions to features and functionality. But software patches and other changes can introduce new cybersecurity and privacy risks and can impair operations if not managed effectively. To support successful, secure software updates and patches, the National Institute of Standards and Technology (NIST) has finalized modifications to its catalog of security and privacy safeguards to assist both the developers who create patches and the organizations that receive and implement them in their own systems.

Many IT professionals will instantly recognize this catalog as one of NIST’s flagship risk management publications: Security and Privacy Controls for Information Systems and Organizations (NIST Special Publication (SP) 800-53). It is a comprehensive catalog of security and privacy safeguards, called controls, for strengthening the systems, products and services that underlie the nation’s businesses, government and critical infrastructure.

The modifications respond to Executive Order 14306, Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144. Completed with the help of a new commenting system in which stakeholders could provide feedback to proposed changes in real time and preview the proposed revisions prior to final publication, the update is available in several electronic formats.

“The changes are intended to emphasize secure software development practices, and to help organizations understand their role in ensuring the security of the software on their systems,” said NIST computer scientist Victoria Pillitteri, who led the project. “Ultimately, we want to help them achieve their goals while minimizing the risk of a patch creating unintended consequences.”

Most software is directly exposed to the internet, which puts it at significant risk of compromise. Patching is a critical component of preventive maintenance that helps to reduce the risk of data breaches and other adverse events.

Update management can be challenging because of the need to balance the trade-offs between deploying patches quickly to address critical vulnerabilities or bugs and thoroughly testing to ensure that critical functions and services are not affected. Once a vendor detects a vulnerability in its software, deploying a patch quickly reduces the window of opportunity for attackers, but it increases the risk that the less thoroughly tested patch might disrupt an organization’s operations. Conversely, thorough testing decreases the risk of operational disruption but increases the window of opportunity for attackers.

“The updated controls emphasize the importance of monitoring the particular component being updated as well as the component’s relationship to the overall system,” Pillitteri said.

The changes to SP 800-53 address multiple aspects of the software development and deployment process, including addressing software and system resiliency by design, developer testing, deployment and management of updates, and software integrity and validation. Among the changes are three entirely new controls:

  • Logging Syntax (SA-15) defines an electronic format for recording security-related events to support better incident response. Defining data formats facilitates automation and helps teams more quickly reconstruct security-related incidents.
  • Root Cause Analysis (SI-02(07)) specifies conducting a review to find the cause of an issue or failure with the software update and coming up with an action plan and implementing it.
  • Design for Cyber Resiliency (SA-24) recommends designing systems for survivability — the ability to anticipate, withstand, respond and recover from attack while maintaining critical functions.

The update also revises the technical content of some existing controls and provides additional examples of how to implement them.

The complete set of changes is available at the Cybersecurity and Privacy Reference Tool (CPRT), where the updated version is listed as SP 800-53 Rev. 5.2.0.

In addition, NIST is now providing updates to the control catalog through CPRT, which allows downloads in machine-readable formats including OSCAL and JSON. The agency has also adopted a new public engagement process that allows stakeholders to respond to proposed changes in real time during comment periods, and to make suggestions at any time.

Pillitteri said that the new engagement process will allow NIST to maintain its usual rigor and transparency, while the different available formats make it easier for users to implement the updated controls.

“We are trying to keep this comprehensive set of security and privacy controls agile,” she said. “NIST can now develop and rapidly issue updates to this guideline while coordinating with stakeholders in a transparent way that meets customer demand. It’s part of our effort to develop and issue standards at the pace of technology.”