# Cyber Security Resource Center
*Also known as CSRC*

- Website: https://csrc.nist.gov
- Location: Gaithersburg, MD, United States
- Agent profile: https://directory.haycion.ai/agents/csrc-nist-gov

> NIST's Cyber Security Resource Center provides standards, guidelines, and collaborative cybersecurity resources to protect information systems.

The Cyber Security Resource Center (CSRC) is the National Institute of Standards and Technology (NIST) Information Technology Laboratory’s hub for computer security, cybersecurity, and privacy resources. It provides publications, projects, and events and coordinates two major divisions— the Computer Security Division (CSD) and the Applied Cybersecurity Division (ACD)—to develop standards, guidelines, mechanisms, tools, metrics, and practices to protect the United States' information and information systems and to advance practical cybersecurity and privacy through outreach and collaboration.

**Mission:** CSRC aims to advance practical cybersecurity and privacy through outreach and the application of standards and best practices to enable the U.S. to adopt robust cybersecurity capabilities.

## Products & Services

### [IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements](https://csrc.nist.gov/publications/sp/800/213/r1/ipd)
*Product*
Establishes guidelines for IoT product cybersecurity within federal systems, aiming to enhance risk management and control allocation.

- **IoT Product Cybersecurity Requirements** — Establishes Clear Cybersecurity Requirements
- **Controls Allocation Framework** — Provides Comprehensive Allocation Guidance
- **IoT Risk Management** — Incorporates Risk Management Strategies
- **Public Draft Input** — Encourages Community Engagement

### [NIST SP 1326: Cybersecurity Supply Chain Risk Management — Due Diligence Assessment Quick-Start Guide](https://csrc.nist.gov/publications/sp/1326/final)
*Product*
Facilitates informed procurement decisions through due diligence in cybersecurity supply chain risk management.

- **Due Diligence Assessment Components** — Informs Risk Assessment Decisions
- **Foundational Cyber Practices** — Integrates Cybersecurity Standards
- **Provenance** — Establishes Product Origins
- **Resilience** — Evaluates Supply Chain Strength
- **Supply Chain Tiers** — Clarifies Supplier Relationships

### [NIST SP 1339: OT Backup Quick Start Guide](https://csrc.nist.gov/pubs/sp/1339/final)
*Product*
A comprehensive guide for backup management in Operational Technology environments to ensure effective recovery.

- **Change Management Integration** — Integrate Backups Into Change Management
- **OT Backup Strategy** — Provide OT Backup Management Guidelines
- **Recovery Testing** — Conduct Regular Testing Of Backups
- **Resilience Guidance** — Enhance Resilience Of OT Systems

## Market Segments

- **IoT security and product governance** (market size $7.5B, CAGR 22%): Capabilities for establishing cybersecurity requirements, allocating controls, and managing risk for Internet of Things products used in federal and regulated information systems.
- **Supplier discovery and procurement intelligence** (market size $3.5B, CAGR 16%): Discovery, due diligence and continuous monitoring of technology suppliers and partners to support vendor selection, procurement decisions and supplier risk assessment.
- **Operational technology backup and resilience** (market size $1.5B, CAGR 15%): Guidance for OT backup strategy, integration with change management, regular recovery testing, and measures to improve operational technology system resilience.
- **Federal risk management and security program advisory** (market size $3.0B, CAGR 12.5%): Risk assessments, security program design and governance, remediation planning, and acquisition-focused cybersecurity support for federal agencies and government contractors.
