Federal Register/Vol. 80, No. 193/Tuesday, October 6, 2015
Total Page:16
File Type:pdf, Size:1020Kb
Federal Register / Vol. 80, No. 193 / Tuesday, October 6, 2015 / Notices 60363 identification card for access to federal and capabilities, but no earlier than Based Security for Electronic Mail facilities if such license or identification November 5, 2015. When the building Building Block. The full building block card is issued by a state that is block has been completed, NIST will description can be viewed at: http:// compliant with the REAL ID Act of 2005 post a notice on the Domain Name nccoe.nist.gov/DNSSecuredEmail. (P.L. 109–13), or by a state that has an System-Based Security for Electronic Interested parties should contact NIST extension for REAL ID compliance. Mail Building Block Web site at using the information provided in the NIST currently accepts other forms of http://nccoe.nist.gov/DNSSecuredEmail FOR FURTHER INFORMATION CONTACT federal-issued identification in lieu of a announcing the completion of the section of this notice. NIST will then state-issued driver’s license. For building block and informing the public provide each interested party with a detailed information please contact Ms. that it will no longer accept letters of letter of interest template, which the Young or visit: http://www.nist.gov/ interest for this building block. party must complete, certify that it is public_affairs/visitor/. ADDRESSES: The NCCoE is located at accurate, and submit to NIST and which 9600 Gudelsky Drive, Rockville, MD identifies the organization requesting Richard Cavanagh, 20850. Letters of interest must be participation in the Domain Name Acting Associate Director for Laboratory submitted to [email protected] System-Based Security for Electronic Programs. or via hardcopy to National Institute of Mail Building Block and the capabilities [FR Doc. 2015–25310 Filed 10–5–15; 8:45 am] Standards and Technology, NCCoE; and components that are being offered BILLING CODE 3510–13–P 9600 Gudelsky Drive; Rockville, MD to the collaborative effort. NIST will 20850. Organizations whose letters of contact interested parties if there are interest are accepted in accordance with questions regarding the responsiveness DEPARTMENT OF COMMERCE the process set forth in the of the letters of interest to the building SUPPLEMENTARY INFORMATION section of block objective or requirements National Institute of Standards and identified below and to obtain Technology this notice will be asked to sign a Cooperative Research and Development additional information. NIST will select [Docket No. 150917865–5865–01] Agreement (CRADA) with NIST. A participants who have submitted CRADA template can be found at: complete letters of interest on a first National Cybersecurity Center of http://nccoe.nist.gov/node/138. come, first served basis within each Excellence (NCCoE) Domain Name FOR FURTHER INFORMATION CONTACT: category of product components or System-Based Security (DNS) for William C. Barker via email to dns- capabilities listed below up to the Electronic Mail Building Block [email protected]; by telephone number of participants in each category necessary to carry out the Domain Name AGENCY: National Institute of Standards 301–975–3655; or by mail to National System-Based Security for Electronic and Technology, Department of Institute of Standards and Technology, Mail Building Block. However, there Commerce. NCCoE; 9600 Gudelsky Drive; Rockville, may be continuing opportunity to ACTION: Notice. MD 20850. Additional details about the Domain Name System-Based Security participate even after initial activity commences. Selected participants will SUMMARY: The National Institute of for Electronic Mail Building Block are be required to enter into a consortium Standards and Technology (NIST) available at http://nccoe.nist.gov/ CRADA with NIST (for reference, see invites organizations to provide DNSSecuredEmail. products and technical expertise to ADDRESSES section above). NIST SUPPLEMENTARY INFORMATION: support and demonstrate security published a notice in the Federal Background: The NCCoE, part of Register on October 19, 2012 (77 FR platforms for the Domain Name System- NIST, is a public-private collaboration Based (DNS) Security for Electronic 64314) inviting U.S. companies to enter for accelerating the widespread into National Cybersecurity Excellence Mail Building Block. This notice is the adoption of integrated cybersecurity initial step for the National Partnerships (NCEPs) in furtherance of tools and technologies. The NCCoE the NCCoE. For this demonstration Cybersecurity Center of Excellence brings together experts from industry, (NCCoE) in collaborating with project, NCEP partners will not be given government, and academia under one priority for participation. technology companies to address roof to develop practical, interoperable cybersecurity challenges identified cybersecurity approaches that address Building Block Objective under the Domain Name System-Based the real-world needs of complex Both public and private sector Security for Electronic Mail Building Information Technology (IT) systems. business operations are heavily reliant Block. Participation in this building By accelerating dissemination and use on electronic mail (email) exchanges. block is open to all interested of these integrated tools and The need to protect business plans and organizations. technologies for protecting IT assets, the tactics, the integrity of transactions, DATES: Interested parties must contact NCCoE will enhance trust in U.S. IT financial and other proprietary NIST to request a letter of interest communications, data, and storage information, and privacy of employees template to be completed and submitted systems; reduce risk for companies and and clients are only four of the factors to NIST that identifies the organization individuals using IT systems; and that motivate organizations to secure requesting participation in the Domain encourage development of innovative, their email exchanges. Whether the Name System-Based Security for job-creating cybersecurity products and security service desired is Electronic Mail Building Block and the services. authentication of the source of an email capabilities and components that are Process: NIST is soliciting responses message, assurance that the message has being offered to the collaborative effort. from all sources of relevant security not been altered by an unauthorized Letters of interest will be accepted on a capabilities (see below) to enter into a party, or confidentiality of message first come, first served basis. Cooperative Research and Development contents, cryptographic functions are Collaborative activities will commence Agreement (CRADA) to provide usually employed in providing the as soon as enough completed and signed products and technical expertise to service. Economies of scale and a need letters of interest have been returned to support and demonstrate security for uniform security implementation address all the necessary components platforms for the Domain Name System- drive most enterprises to rely on mail VerDate Sep<11>2014 18:31 Oct 05, 2015 Jkt 238001 PO 00000 Frm 00015 Fmt 4703 Sfmt 4703 E:\FR\FM\06OCN1.SGM 06OCN1 tkelley on DSK3SPTVN1PROD with NOTICES 60364 Federal Register / Vol. 80, No. 193 / Tuesday, October 6, 2015 / Notices servers to provide security to the addresses encoded as DNS names System-Based Security for Electronic members of an enterprise rather than verified by DNSSEC. These bindings Mail Building Block description (for end-to-end security mechanisms support trust in the use of S/MIME reference, please see the link in the operated by individual users. Most certificates in the end-to-end email PROCESS section above) and include, current server-based email security communication. The resulting building but are not limited to: mechanisms are vulnerable to, and have block will encrypt email traffic between • Client systems been defeated by, attacks on the servers, allow individual email users to • DNS/DNSSEC services integrity of the cryptographic digitally sign and/or encrypt email • Mail transfer agents implementations on which they depend. messages to other end users, and allow • DNS resolvers (stub and recursive) for The consequences frequently involve individual email users to obtain other DNSSEC validation unauthorized parties being able to read users’ certificates in order to validate • Authoritative DNS servers for or modify supposedly secure signed email or send encrypted email. DNSSEC signed zones information, or to use email as a vector The project will include an email • Mail server/mail security systems for inserting malware into the system sending policy consistent with a stated • S/MIME certificates that is intended to deny access to privacy policy that can be parsed by • Extended validation and domain critical information or processes or to receiving servers so that receiving validation TLS certificates damage or destroy system components servers can apply the correct security Each responding organization’s letter and/or information. Improved email checks and report back the correctness of interest should identify how their security can help protect organizations of the email stream. Documentation of product(s) address one or more of the and individuals against these the resulting platform will include desired solution characteristics in consequences and also serve as a statements of the security and privacy section five of the Domain Name marketing discriminator for email policies and standards (e.g., Executive System-Based Security for Electronic