On 1 April 2024, the National Institute of Standards and Technology (NIST) closed its consultation on the draft practice guide, "Addressing Visibility Challenges with TLS 1.3 within the Enterprise (NIST Special Publication (SP) 1800-37)". The guide, developed at the NIST National Cybersecurity Center of Excellence (NCCoE), offers technical methods to help businesses in key industries such as finance and healthcare comply with the most up-to-date ways of securing data that travels over the public internet to their internal servers, while simultaneously adhering to regulations that require continuous monitoring and auditing of this data for evidence of malware and other cyberattacks. Furthermore, the guide outlines six techniques for organisations to access encryption keys securely, safeguarding data from unauthorised access. Despite TLS 1.3 discarding keys upon receiving data, the guide's methods enable organisations to retain raw and decrypted data temporarily for security monitoring. This information is stored securely for audit and forensics but is destroyed after security processing. While risks exist in storing keys, the NIST guide presents secure alternatives.
Original source