Compare with different regulatory event:

Description

NIST publishes definition for "critical software"

The National Institute of Standards and Technology (NIST) defines "critical software", as requested in May 2021 via the Executive Order on Improving the Nation's Cybersecurity (EO 14028). Per the Executive Order, the software products classified as "critical software" shall become subject to federal agencies' guidance on encryption, authentification and monitoring software operation. The NIST definition classifies software as "critical" according to five criteria described in the publication. Furthermore, a closer collaboration between the government and private sector is targeted, with an information-sharing system set up to increase protection from cyber threats. Finally, a Cybersecurity Safety Review Board is to be created.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
software provider: other software
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2021-05-12
adopted

President Biden seeks to enhance the security of the critical software supply chain via Executive O…

2021-06-24
adopted

The National Institute of Standards and Technology (NIST) defines "critical software", as requested…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity software provider: other software
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
government data (all forms): storage (any form)
Regulatory tool
Creation of other oversight body
Preventive security requirement
Responsive security requirement
Sanctions
Regulated subjects
1
corporate data (all forms): storage (any form)
Regulatory tool
Creation of other oversight body
Preventive security requirement
Responsive security requirement
Sanctions
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

government data (all forms): storage (any form)

corporate data (all forms): storage (any form)