# nist

Published articles for nist.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How Confluent Uses Third-Party Risk Assessments to Support Vendor Due Diligence

DevFeed: [How Confluent Uses Third-Party Risk Assessments to Support Vendor Due Diligence](<https://devfeed.tech/articles/third-party-risk-assessments-how-confluent-helps-you-move-faster-with-confidence-26724.md>)

Original publisher: [Read original article](<https://www.confluent.io/blog/third-party-risk-assessments-or-how-confluent-helps-you-move-faster-with-confidence/>)

Author: Bethany Carter

Published: 2026-09-15T16:40:06Z

Content type: article

Language: en

Sources: [Confluent: Data in motion](<https://devfeed.tech/sources/confluent-data-in-motion.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [apra](<https://devfeed.tech/tags/apra.md>), [automated](<https://devfeed.tech/tags/automated.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [confluent](<https://devfeed.tech/tags/confluent.md>), [confluent-cloud](<https://devfeed.tech/tags/confluent-cloud.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [identity](<https://devfeed.tech/tags/identity.md>), [iso](<https://devfeed.tech/tags/iso.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [third-party](<https://devfeed.tech/tags/third-party.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Confluent explains how its Trust Center provides third-party risk assessment reports to support vendor security, resilience, compliance, procurement, and customer due diligence. The article describes assessments including ProcessUnity Global Risk Exchange and control mapping to customer frameworks.

### Source excerpt

Confluent's Trust Center simplifies vendor risk reviews with CyberGRX, CyberVadis, SIG, CAIQ, and TruSight/KY3P assessments.

## Cisco and the DISA STIG: Turning Zero Trust Policy into Repeatable Practice - Part 2: Cisco SNA

DevFeed: [Cisco and the DISA STIG: Turning Zero Trust Policy into Repeatable Practice - Part 2: Cisco SNA](<https://devfeed.tech/articles/cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-2-cisco-sna-26716.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/industries/cisco-and-the-disa-stig-turning-zero-trust-policy-into-repeatable-practice-part-2-cisco-sna>)

Author: Norman St. Laurent

Published: 2026-09-15T13:13:53Z

Content type: article

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-secure-network-analytics-sna](<https://devfeed.tech/tags/cisco-secure-network-analytics-sna.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [department-of-defense-dod](<https://devfeed.tech/tags/department-of-defense-dod.md>), [government](<https://devfeed.tech/tags/government.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [industries](<https://devfeed.tech/tags/industries.md>), [nist](<https://devfeed.tech/tags/nist.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [stig](<https://devfeed.tech/tags/stig.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

The article explains how the DISA Security Technical Implementation Guide for Cisco Secure Network Analytics turns Zero Trust policy into testable configuration requirements. The STIG provides a shared hardening baseline for the platform and its management functions, with 31 requirements derived from NIST SP 800-53 and related requirements.

### Source excerpt

Discover how the new DISA STIG for Cisco Secure Network Analytics helps defense organizations securely configure and harden their analytics platform, ensuring trusted network visibility for Zero Trust operations.

## Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.

DevFeed: [Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.](<https://devfeed.tech/articles/canada-s-cpcsc-and-bill-c-8-are-coming-here-s-what-you-need-to-do-12917.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/canadas-cpcsc-and-bill-c-8-are-coming-heres-what-you-need-to-do>)

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [bill-c-8](<https://devfeed.tech/tags/bill-c-8.md>), [canada-cmmc](<https://devfeed.tech/tags/canada-cmmc.md>), [canadian-program-for-cyber-security-certification](<https://devfeed.tech/tags/canadian-program-for-cyber-security-certification.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cpcsc](<https://devfeed.tech/tags/cpcsc.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

This article explains Canada's Canadian Program for Cyber Security Certification (CPCSC) and Bill C-8, focusing on the implications for defence suppliers and organizations in critical infrastructure. It describes the CPCSC as a mandatory cybersecurity certification regime, compares its technical basis with CMMC and NIST Special Publications 800-171 and 800-172, and outlines why organizations should prepare for Level 1 requirements. The article also describes how Chainguard can help Canadian defence suppliers meet those requirements with secure, zero-CVE containers.

### Source excerpt

CPCSC compliance is coming fast. Learn how Chainguard helps Canadian defence suppliers meet Level 1 requirements with secure, zero-CVE containers.

## CMMC Phase 2, explained: Requirements, deadlines, and who's affected

DevFeed: [CMMC Phase 2, explained: Requirements, deadlines, and who's affected](<https://devfeed.tech/articles/cmmc-phase-2-explained-requirements-deadlines-and-who-s-affected-13009.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cmmc-phase-2-explained>)

Published: 2026-04-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [cmmc-container-images](<https://devfeed.tech/tags/cmmc-container-images.md>), [cmmc-phase-2](<https://devfeed.tech/tags/cmmc-phase-2.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-maturity-model-certification](<https://devfeed.tech/tags/cybersecurity-maturity-model-certification.md>), [fips](<https://devfeed.tech/tags/fips.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [u-s-dod](<https://devfeed.tech/tags/u-s-dod.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains the requirements, deadlines, and scope of CMMC Phase 2. It describes the CMMC Level 2 certification requirements for organizations handling Controlled Unclassified Information or supporting Department of Defense and certain civilian agency contracts, including MFA, encryption, vulnerability scanning, supported systems, independent assessments, and compliance documentation.

### Source excerpt

CMMC Phase 2 and NIST 800-171 are here. Learn how Chainguard helps teams meet compliance with FIPS, STIGs, and zero-CVE containers.

## NIST CSF 2.0 and Agentic AI: Building Profiles for Autonomous Systems

DevFeed: [NIST CSF 2.0 and Agentic AI: Building Profiles for Autonomous Systems](<https://devfeed.tech/articles/nist-csf-2-0-and-agentic-ai-building-profiles-for-autonomous-systems-29773.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/nist-csf-agentic-ai/>)

Author: info@goteleport.com (Matthew Smith)

Published: 2026-04-20T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how organizations can tailor NIST Cybersecurity Framework 2.0 for autonomous AI systems through a Cyber AI Profile. It focuses on adapting governance, identity, monitoring, and audit practices to account for AI agents operating without continuous human approval.

### Source excerpt

Learn how to tailor NIST CSF 2.0 for autonomous systems using the Cyber AI Profile, with guidance on agent identity, governance, and monitoring

## EU AI Act Compliance: Requirements, Risks, and What to Document

DevFeed: [EU AI Act Compliance: Requirements, Risks, and What to Document](<https://devfeed.tech/articles/eu-ai-act-compliance-requirements-risks-and-what-to-document-29638.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-ai-act-requirements/>)

Author: info@goteleport.com (Kayne McGladrey, CISSP)

Published: 2026-04-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>), [audit](<https://devfeed.tech/topics/audit.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [dataset](<https://devfeed.tech/tags/dataset.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [development](<https://devfeed.tech/tags/development.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [lifecycle](<https://devfeed.tech/tags/lifecycle.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [nist](<https://devfeed.tech/tags/nist.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [versioning](<https://devfeed.tech/tags/versioning.md>)

### AI overview

A practical guide to EU AI Act compliance covering requirements, risks, technical documentation, logging, data governance, lifecycle evidence, traceability, monitoring, and human oversight. It outlines key compliance milestones from August 2025 through August 2027.

### Source excerpt

Cut through EU AI Act complexity with practical guidance on requirements, risks, and documentation.

## NIST 800-171 and Agentic AI: What Autonomous Systems Mean for CUI Protection

DevFeed: [NIST 800-171 and Agentic AI: What Autonomous Systems Mean for CUI Protection](<https://devfeed.tech/articles/nist-800-171-and-agentic-ai-what-autonomous-systems-mean-for-cui-protection-29771.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/nist-800-171-agentic-ai/>)

Author: info@goteleport.com (Matthew Smith)

Published: 2026-04-08T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [deploying agentic AI](<https://devfeed.tech/topics/deploying-agentic-ai.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [audit](<https://devfeed.tech/topics/audit.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [audit](<https://devfeed.tech/tags/audit.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [deploying-agentic-ai](<https://devfeed.tech/tags/deploying-agentic-ai.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how agentic AI affects the practical application of NIST 800-171 requirements for organizations handling Controlled Unclassified Information. It focuses on access control, auditing, and data protection when autonomous agents query databases, trigger workflows, or transfer data to external services.

### Source excerpt

How does agentic AI impact NIST 800-171 compliance? Learn how autonomous systems affect access control, auditing, and CUI protection.

## How to Apply NIST 800-53 to AI Systems

DevFeed: [How to Apply NIST 800-53 to AI Systems](<https://devfeed.tech/articles/how-to-apply-nist-800-53-to-ai-systems-29772.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/nist-800-53-ai-systems/>)

Author: info@goteleport.com (Matthew Smith)

Published: 2026-03-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [audit](<https://devfeed.tech/topics/audit.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [audit](<https://devfeed.tech/tags/audit.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This tutorial explains how NIST SP 800-53 applies to AI and agentic systems. It focuses on how autonomous systems complicate existing security controls and introduces Access Control, Audit and Accountability, and Configuration Management as starting points for further risk assessment.

### Source excerpt

Learn to apply NIST 800-53 to agentic systems and AI infrastructure with control guidance on identity, auditing, configuration management, and monitoring.

## Announcing Kernel-Independent FIPS for Java

DevFeed: [Announcing Kernel-Independent FIPS for Java](<https://devfeed.tech/articles/announcing-kernel-independent-fips-for-java-12886.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-kernel-independent-fips-for-java>)

Published: 2025-08-14T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [ato](<https://devfeed.tech/tags/ato.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fips-images](<https://devfeed.tech/tags/chainguard-fips-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cos](<https://devfeed.tech/tags/cos.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [fedramp-containers](<https://devfeed.tech/tags/fedramp-containers.md>), [fips](<https://devfeed.tech/tags/fips.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [java](<https://devfeed.tech/tags/java.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nist](<https://devfeed.tech/tags/nist.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard announces Kernel-Independent FIPS availability across its Java FIPS image catalog. The update uses FIPS-validated cryptography and validated userspace entropy, allowing Java FIPS workloads to run with any host kernel and on platforms including GKE with COS, Amazon Bottlerocket, Flatcar Linux, and Azure Linux. It is intended to simplify production deployment and accelerate FedRAMP authorization to operate.

### Source excerpt

Kernel-Independent FIPS is now available across the full catalog of Chainguard FIPS images for Java, simplifying and accelerating compliance for FedRAMP ATO.

## Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk

DevFeed: [Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk](<https://devfeed.tech/articles/meeting-the-ai-mandates-with-confidence-why-federal-teams-trust-snyk-8251.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-federal-teams-trust-snyk/>)

Author: Phoebe Nerdahl

Published: 2025-08-07T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [agentic-ai-security](<https://devfeed.tech/tags/agentic-ai-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [github](<https://devfeed.tech/tags/github.md>), [government](<https://devfeed.tech/tags/government.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Snyk for Government helps federal agencies adopt AI securely through secure-by-design development, continuous vulnerability management, compliance support, automation, and governance. It highlights integrations across developer workflows, FedRAMP authorization, standards-aligned practices, and the Snyk AI Trust Platform.

### Source excerpt

Learn how Snyk for Government helps federal agencies meet AI mandates with confidence. Snyk's AI Trust Platform ensures secure-by-design development, compliance, and transparent AI systems.

## FIPS-Validated Container Images: When, Where, and Why

DevFeed: [FIPS-Validated Container Images: When, Where, and Why](<https://devfeed.tech/articles/fips-validated-container-images-when-where-and-why-13046.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fips-validated-container-images-when-where-why>)

Published: 2025-07-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [nist](<https://devfeed.tech/tags/nist.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains why FIPS-validated cryptography is required at the container image level for workloads subject to FedRAMP and NIST 800-53 requirements. It describes Chainguard's FIPS-validated container images, their cryptographic boundaries, and how they help organizations address compliance and authorization requirements in regulated environments.

### Source excerpt

Chainguard's catalog of 1,400+ trusted container images includes 400+ FIPS-validated variants.

## Forging Ahead in Federal Compliance: Chainguard's FIPS 140-3 and 186-5 Milestones

DevFeed: [Forging Ahead in Federal Compliance: Chainguard's FIPS 140-3 and 186-5 Milestones](<https://devfeed.tech/articles/forging-ahead-in-federal-compliance-chainguard-s-fips-140-3-and-186-5-milestones-13048.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/forging-ahead-in-federal-compliance-chainguards-fips-140-3-and-186-5-milestones>)

Published: 2025-06-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fips](<https://devfeed.tech/tags/chainguard-fips.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [digital-signature](<https://devfeed.tech/tags/digital-signature.md>), [ed25519](<https://devfeed.tech/tags/ed25519.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [federal-information-processing-standards](<https://devfeed.tech/tags/federal-information-processing-standards.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [nist](<https://devfeed.tech/tags/nist.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [standards](<https://devfeed.tech/tags/standards.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

Chainguard FIPS container images are being upgraded to support current FIPS 140-3 and FIPS 186-5 standards, including OpenSSL with FIPS 140-3 validation and Ed25519 signing support.

### Source excerpt

Chainguard FIPS images have been upgraded to start using the OpenSSL project 3.1.2 module with FIPS 140-3 validation. Learn more about what this means.

## Chainguard Containers Enabled with PQC Support

DevFeed: [Chainguard Containers Enabled with PQC Support](<https://devfeed.tech/articles/chainguard-containers-enabled-with-pqc-support-12935.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-containers-enabled-with-pqc-support>)

Published: 2025-06-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Post Quantum Cryptography (PQC)](<https://devfeed.tech/topics/post-quantum-cryptography-pqc.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Internet Engineering Task Force (IETF)](<https://devfeed.tech/topics/ietf.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fips](<https://devfeed.tech/tags/fips.md>), [ietf](<https://devfeed.tech/tags/ietf.md>), [nist](<https://devfeed.tech/tags/nist.md>), [post-quantum-cryptography](<https://devfeed.tech/tags/post-quantum-cryptography.md>), [post-quantum-cryptography-pqc](<https://devfeed.tech/tags/post-quantum-cryptography-pqc.md>), [quantum](<https://devfeed.tech/tags/quantum.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

Chainguard Containers now support Post-Quantum Cryptography (PQC), including FIPS 203 ML-KEM and other algorithms used in TLS and SSH communications. The article explains the risks posed by quantum attacks and "harvest now, decrypt later" scenarios, and describes ongoing work toward FIPS-certified PQC implementations.

### Source excerpt

Chainguard Containers support Post-Quantum Cryptography (PQC). Learn more about what PQC is, and what Chainguard is doing to offer it today.

## Chainguard Signs CISA's Secure Software Development Attestation Form

DevFeed: [Chainguard Signs CISA's Secure Software Development Attestation Form](<https://devfeed.tech/articles/chainguard-signs-cisa-s-secure-software-development-attestation-form-12982.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-signs-cisas-secure-software-development-attestation-form>)

Published: 2025-02-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [nist](<https://devfeed.tech/tags/nist.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard announces that it has signed CISA's Secure Software Development Attestation Form. The attestation states that Chainguard products align with NIST's Secure Software Development Framework and federal software supply chain security requirements, including secure development environments, trusted source code supply chains, automated controls, and provenance data.

### Source excerpt

Chainguard has recently signed CISA's Secure Software Development Attestation Form, attesting to the security of Chainguard and its products.

## How NIST is changing standards to safeguard AI

DevFeed: [How NIST is changing standards to safeguard AI](<https://devfeed.tech/articles/how-nist-is-changing-standards-to-safeguard-ai-13092.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-nist-is-changing-standards-to-safeguard-ai>)

Published: 2024-08-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [ai safety](<https://devfeed.tech/topics/ai-safety.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>)

Tags: [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [nist](<https://devfeed.tech/tags/nist.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

The article explains how NIST is developing AI safety and security guidelines in response to the White House's October 2023 Executive Order. It highlights generative AI risks such as disinformation, phishing, malware development, and sensitive-data leaks, and describes planned companion resources for the AI Risk Management Framework and Secure Software Development Framework.

### Source excerpt

New NIST AI standards address generative AI risks with a focus on risk management, security practices, and recognizing synthetic content.

## Achieve CMMC 2.0 compliance with Chainguard FIPS Images

DevFeed: [Achieve CMMC 2.0 compliance with Chainguard FIPS Images](<https://devfeed.tech/articles/achieve-cmmc-2-0-compliance-with-chainguard-fips-images-12862.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/achieve-cmmc-2-0-compliance-with-chainguard-fips-images>)

Published: 2024-08-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard fips images](<https://devfeed.tech/topics/chainguard-fips-images.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-fips](<https://devfeed.tech/tags/chainguard-fips.md>), [chainguard-fips-images](<https://devfeed.tech/tags/chainguard-fips-images.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [cmmc-2-0](<https://devfeed.tech/tags/cmmc-2-0.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fips](<https://devfeed.tech/tags/fips.md>), [government](<https://devfeed.tech/tags/government.md>), [nist](<https://devfeed.tech/tags/nist.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [standards](<https://devfeed.tech/tags/standards.md>), [stig](<https://devfeed.tech/tags/stig.md>)

### AI overview

This article explains how Chainguard FIPS-enabled, STIG-hardened container images may help organizations address CMMC 2.0 requirements. It outlines the framework's three assessment levels, including Level 2 requirements tied to NIST SP 800-171, and discusses compliance risks for organizations seeking U.S. government contracts.

### Source excerpt

Master CMMC 2.0 compliance! Get expert insights, downloadable resources, and guidance to safeguard your sensitive data.

## Understanding NIST's latest updates on container image security

DevFeed: [Understanding NIST's latest updates on container image security](<https://devfeed.tech/articles/understanding-nist-s-latest-updates-on-container-image-security-13301.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/understanding-nists-latest-updates-on-container-image-security>)

Published: 2024-07-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [image-security](<https://devfeed.tech/tags/image-security.md>), [nist](<https://devfeed.tech/tags/nist.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains NIST guidance relevant to container image security, including risks from misconfiguration, runtime threats, limited visibility, governance gaps, and compliance issues. It discusses NIST SP 800-161 Revision 1 and its focus on cybersecurity supply chain risk management, vulnerability monitoring, configuration management, authorization, and authentication.

### Source excerpt

Learn about NIST's latest updates on container image security and how it impacts your organization's security posture.

## NIST's role in enhancing software supply chain security

DevFeed: [NIST's role in enhancing software supply chain security](<https://devfeed.tech/articles/nist-s-role-in-enhancing-software-supply-chain-security-13186.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nists-role-in-enhancing-software-supply-chain-security>)

Published: 2024-07-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [nist](<https://devfeed.tech/tags/nist.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

The article explains NIST's role in software supply chain security, including its Cybersecurity Framework, guidance following Executive Order 14028, and recommended practices such as risk assessment, supplier controls, SBOMs, incident response, and continuous monitoring.

### Source excerpt

NIST's framework for enhancing software supply chain security: Learn how the NIST is guiding organizations to build a more secure software ecosystem.

## Introducing Chainguard's Trust Center

DevFeed: [Introducing Chainguard's Trust Center](<https://devfeed.tech/articles/introducing-chainguard-s-trust-center-13114.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguards-trust-center>)

Published: 2024-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [certifications](<https://devfeed.tech/tags/certifications.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-security-best-practices](<https://devfeed.tech/tags/software-security-best-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>)

### AI overview

Chainguard introduces its Trust Center, a platform that centralizes security, compliance, and privacy information for users and customers. The center provides access to independent penetration-testing assessments, a SOC 2 Type 2 audit report, hardening guidance, privacy information, data-subprocessor details, and information security policies.

### Source excerpt

Learn how Chainguard prioritizes security with our new Trust Center. Find info on our policies, certifications, and how we protect your software supply chain.

## Is your container security FedRAMP Rev 5 ready?

DevFeed: [Is your container security FedRAMP Rev 5 ready?](<https://devfeed.tech/articles/is-your-container-security-fedramp-rev-5-ready-13128.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/is-your-container-security-fedramp-rev-5-ready>)

Published: 2024-05-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [compliance-management](<https://devfeed.tech/tags/compliance-management.md>), [container](<https://devfeed.tech/tags/container.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [federal-contractor](<https://devfeed.tech/tags/federal-contractor.md>), [federal-government-compliance-program-requirements](<https://devfeed.tech/tags/federal-government-compliance-program-requirements.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-rev-5](<https://devfeed.tech/tags/fedramp-rev-5.md>), [government-contract-jobs](<https://devfeed.tech/tags/government-contract-jobs.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [what-are-compliance-requirements](<https://devfeed.tech/tags/what-are-compliance-requirements.md>)

### AI overview

The article explains how FedRAMP Rev 5 changes cloud security expectations for providers serving the US government. It emphasizes NIST SP 800-53 Rev 5 alignment, software supply chain security, container hardening, documentation, monitoring, and transition deadlines.

### Source excerpt

Is your container security FedRAMP Rev 5 compliant? Discover the key requirements and how Chainguard can help.

## Snyk Learn and the NIST Cybersecurity Framework (CSF)

DevFeed: [Snyk Learn and the NIST Cybersecurity Framework (CSF)](<https://devfeed.tech/articles/snyk-learn-and-the-nist-cybersecurity-framework-csf-8146.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-learn-nist-cybersecurity-framework-csf/>)

Author: Michael Biocchi

Published: 2024-03-06T14:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-learn](<https://devfeed.tech/topics/snyk-learn.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [education](<https://devfeed.tech/tags/education.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how Snyk Learn supports the Protect function of NIST Cybersecurity Framework 2.0 through developer-focused cybersecurity training. It covers topics including SQL injection, cryptography, server-side request forgery, and memory leaks, with the goal of helping developers build security into applications earlier in the SDLC and reduce production risk.

### Source excerpt

Find out how Snyk Learn helps development teams with the "Protect" function of NIST CSF 2.0.

## Enhancing code to cloud security with the Common Configuration Scoring System

DevFeed: [Enhancing code to cloud security with the Common Configuration Scoring System](<https://devfeed.tech/articles/enhancing-code-to-cloud-security-with-the-common-configuration-scoring-system-7905.md>)

Original publisher: [Read original article](<https://snyk.io/blog/enhancing-code-to-cloud-security-common-configuration-scoring/>)

Author: Wayne Crissman; Tal Dromi

Published: 2023-12-14T14:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [iac-security](<https://devfeed.tech/topics/iac-security.md>), [snyk-iac](<https://devfeed.tech/topics/snyk-iac.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [developer](<https://devfeed.tech/tags/developer.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [iac](<https://devfeed.tech/tags/iac.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-rules](<https://devfeed.tech/tags/security-rules.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

Snyk is standardizing its code-to-cloud security rules on the Common Configuration Scoring System (CCSS). The change applies to Snyk Infrastructure as Code (IaC), IaC+, and cloud configurations, using technical severity, threat intelligence, and application and business context to produce clearer risk assessments.

### Source excerpt

To eliminate this burden and provide our customers with a clear security assessment for configurations across the SDLC, Snyk will be moving towards standardizing our code to cloud security rules set on the Common Configuration Scoring System (CCSS)!

## An update on Chainguard Images FIPS Validation

DevFeed: [An update on Chainguard Images FIPS Validation](<https://devfeed.tech/articles/an-update-on-chainguard-images-fips-validation-12871.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/an-update-on-chainguard-images-fips-validation>)

Published: 2023-09-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security](<https://devfeed.tech/topics/security.md>), [Utility Software](<https://devfeed.tech/topics/utility.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [migration](<https://devfeed.tech/tags/migration.md>), [nist](<https://devfeed.tech/tags/nist.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes its FIPS-ready Chainguard Images, which use an OpenSSL 3.0.8 module validated by NIST for FIPS 140-2. The article explains the validation process, support for FedRAMP requirements, available FIPS-enabled base images, planned migration toward FIPS 140-3, and a utility for verifying that the module is correctly installed and configured to use approved cryptographic algorithms.

### Source excerpt

Need support on your FedRAMP journey? Chainguard's FIPS Images use the OpenSSL 3.0.8 module that is validated by NIST for 140-2.

## Government perspectives on software self-attestation requirements

DevFeed: [Government perspectives on software self-attestation requirements](<https://devfeed.tech/articles/government-perspectives-on-software-self-attestation-requirements-13071.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/government-perspectives-on-software-self-attestation-requirements>)

Published: 2023-06-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

Chainguard CEO Dan Lorenc and CISA Fellow Chris Hughes discuss CISA's draft software self-attestation form, its relationship to federal software supply chain security requirements, and the regulatory context surrounding secure software development.

### Source excerpt

Chainguard CEO Dan Lorenc and Chris Hughes, CISO & Cofounder of Aquia and CISA Fellow discuss the upcoming software self-attestation form.

[Next page](<https://devfeed.tech/tags/nist.md?cursor=WyIyMDIzLTA2LTE1VDAwOjAwOjAwKzAwOjAwIiwgIjFlOTQ3YzE1LTliNDYtNGRiZi04YTY2LTRkZDUzZDM4YTg3NSJd>)