Cybersecurity imagery. NIST released draft updates to Special Publication 800-53.
The National Institute of Standards and Technology has released draft revisions to Special Publication 800-53 to enhance the secure deployment of software patches and updates.
/

NIST Releases Draft Updates to SP 800-53 to Boost Software Security

1 min read

The National Institute of Standards and Technology has released draft revisions to Special Publication 800-53.

The federal agency said Tuesday the proposed changes aim to enhance the secure and reliable deployment of software patches and updates, following mandates from Executive Order 14306, titled Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity and Amending Executive Order 13694 and Executive Order 14144.

Proposed SP 800-53 Updates

The draft includes the following proposed changes:

  • Update to an existing control enhancement
  • Two new control enhancements
  • Six updates to existing control and control enhancement discussions
  • Updates to related controls for the new control enhancements

These revisions aim to enhance practices in software resiliency, developer testing, secure logging, least privilege for functions and tools, update deployment management, software integrity and validation, delineation of roles between organizations and developers, and root cause analysis and improvement.

The draft updates can be reviewed and commented on through the NIST SP 800-53 Public Comment Site during an expedited two-week public comment period, concluding on August 5. Users can also submit suggestions for new controls and possible updates to existing controls. NIST will review the comments and issue SP 800-53 Release 5.2.0 by Sept. 2.