The National Institute of Standards and Technology (NIST) would like feedback on it’s draft scoring system which evaluates various security configurations within operating systems and applications.The NIST website has the draft “Interagency Report 7502: The Common Configuration Scoring System” available for review. Government Computer News said this about the report: “The report proposes a set of measures for security configuration issues and a formula to combine those measures into scores for each issue, collectively called the Common Configuration Scoring System (CCSS). It is derived from the Common Vulnerability Scoring System (CVSS) for measuring the relative severity of vulnerabilities caused by software flaws. CCSS adjusts the basic components of CVSS to focus on security configuration issues rather than software flaws. “Commenting on these documents is a great opportunity for security professionals that want to become engaged in the government processes to ensure that consistent controls are put in place for federal, state, and local networks. More and more federal guidance requires states to comply with federal standards if state or local governments are custodians of federal data. For example: The IRS provides guidane to federal, state, and local entities for use of tax information in their publication 1075. Comments on the draft of CCSS should be e-mailed by July 3 to IR7502comments@nist.gov with “Comments IR 7502” in the subject line. Related content opinion 3 security career lessons from 'Back to the Future' You don't need to be able to predict the future to have a successful security career, but you had darned well better be able to learn from the past. By Dan Lohrmann Jan 12, 2021 6 mins Careers Security interview Secrets of industry-hopping CSOs Who says you can't change industries? Veteran security leaders Mark Weatherford and Cheri McGuire teach you how it’s done. By Dan Lohrmann Mar 02, 2020 12 mins Careers Security opinion Why security pros are addicted to FUD and what you can do about it Despite professing anti-FUD rhetoric, cyber experts fan the flames, breathlessly sharing the details of the latest data breaches. It's a risky addiction that can lead to security apathy in enterprises. Here's how to harness it. By Dan Lohrmann Sep 06, 2018 7 mins Security opinion Bridging the smart cities security divide There are plenty of organizations that seem to be working on answers to secure smart cities, but in many ways it's like the early days of cloud computing with everyone building their own solutions. By Dan Lohrmann Feb 01, 2018 6 mins Internet of Things Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe