The standards bodies: NIST, ISOC, ITU-T and ISO
◈ 8 cardsWhich body is which kind of organisation, what each one publishes, and how to place FIPS, the SP 800-series, RFCs, X-series Recommendations and the ISO 27000-series with their publisher.
A small topic that pays well
Four bodies, four kinds of document. It takes ten minutes to learn and it is examined directly, because the discrimination is clean: what kind of organisation is this, and what does it publish? Get the kind right and the rest follows, because each body's output has its own name.
NIST — a US federal agency
The National Institute of Standards and Technology is an agency of the United States federal government, working in measurement standards and applied technology. That is the phrase to hold: federal agency, not a society, not a treaty body, not a membership organisation. Its scope is formally national and its influence is worldwide — the rest of the planet reads its documents whether or not it is bound by them.
NIST publishes two series you will meet constantly. FIPS — Federal Information Processing Standards — are the mandatory-for-US-agencies standards; FIPS 199, the impact-level scheme from Module 1, is one, and FIPS 200 is another. SP, the Special Publications, are the guidance documents, and the 800-series is the computer-security one: SP 800-63 on digital identity is the example this course has already used.
Note the trap in advance: FIPS is a document series, not a body. A question asking which organisation does something can never be answered by FIPS.
ISOC — a voluntary membership society
The Internet Society is a voluntary membership society, and it is the organisational home of the Internet Engineering Task Force (IETF) and the Internet Architecture Board (IAB). Those two do the standardisation work for the Internet's protocols; ISOC is the body they sit inside.
The output is published as RFCs — Requests for Comments. RFC 4949, the Internet Security Glossary that Module 1 took its threat-consequence vocabulary from, is one of these, and so are the documents defining TLS and IPsec that later modules use.
ITU-T — a UN agency's standardisation sector
The International Telecommunication Union is a specialised agency of the United Nations; ITU-T is its Telecommunication Standardization Sector. Its output is not called a standard at all — it is called a Recommendation, and the naming is itself examinable.
The X-series Recommendations are the ones this course cares about: X.800, the security architecture that supplies the vocabulary of security services and mechanisms, and X.509, the certificate format that PKI is built on.
ISO — a nongovernmental international federation
The International Organization for Standardization is a worldwide federation of national standards bodies, one per member country, drawn from more than a hundred and forty countries. It is nongovernmental — that word is the discriminator against ITU-T, which is a UN agency, and against NIST, which is a national government agency. Its output is called an International Standard, and the 27000-series is the information-security management family: ISO 27002, the code of practice for information security controls, is the example met in this course.
Worked example — placing five documents
Five documents this course has already used, each attributed by working from the kind of name backwards:
- FIPS 199 (the low/moderate/high impact levels) — a Federal Information Processing Standard, so NIST.
- SP 800-63 (digital identity guidelines) — a Special Publication in the 800-series, so NIST.
- RFC 4949 (the Internet Security Glossary) — a Request for Comments, so the IETF under ISOC.
- X.800 (the security architecture) — an X-series Recommendation, so ITU-T.
- ISO 27002 (the code of practice for security controls) — an International Standard in the 27000-series, so ISO.
Now do the same for five more and check yourself: FIPS 200, SP 800-53, RFC 8446, X.509, ISO 27001. The answers are NIST, NIST, ISOC (via the IETF), ITU-T, ISO. The document naming convention does the work every time.