80_FR_60556 80 FR 60363 - National Cybersecurity Center of Excellence (NCCoE) Domain Name System-Based Security (DNS) for Electronic Mail Building Block

80 FR 60363 - National Cybersecurity Center of Excellence (NCCoE) Domain Name System-Based Security (DNS) for Electronic Mail Building Block

DEPARTMENT OF COMMERCE
National Institute of Standards and Technology

Federal Register Volume 80, Issue 193 (October 6, 2015)

Page Range60363-60365
FR Document2015-25304

The National Institute of Standards and Technology (NIST) invites organizations to provide products and technical expertise to support and demonstrate security platforms for the Domain Name System- Based (DNS) Security for Electronic Mail Building Block. This notice is the initial step for the National Cybersecurity Center of Excellence (NCCoE) in collaborating with technology companies to address cybersecurity challenges identified under the Domain Name System-Based Security for Electronic Mail Building Block. Participation in this building block is open to all interested organizations.

Federal Register, Volume 80 Issue 193 (Tuesday, October 6, 2015)
[Federal Register Volume 80, Number 193 (Tuesday, October 6, 2015)]
[Notices]
[Pages 60363-60365]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2015-25304]


-----------------------------------------------------------------------

DEPARTMENT OF COMMERCE

National Institute of Standards and Technology

[Docket No. 150917865-5865-01]


National Cybersecurity Center of Excellence (NCCoE) Domain Name 
System-Based Security (DNS) for Electronic Mail Building Block

AGENCY: National Institute of Standards and Technology, Department of 
Commerce.

ACTION: Notice.

-----------------------------------------------------------------------

SUMMARY: The National Institute of Standards and Technology (NIST) 
invites organizations to provide products and technical expertise to 
support and demonstrate security platforms for the Domain Name System-
Based (DNS) Security for Electronic Mail Building Block. This notice is 
the initial step for the National Cybersecurity Center of Excellence 
(NCCoE) in collaborating with technology companies to address 
cybersecurity challenges identified under the Domain Name System-Based 
Security for Electronic Mail Building Block. Participation in this 
building block is open to all interested organizations.

DATES: Interested parties must contact NIST to request a letter of 
interest template to be completed and submitted to NIST that identifies 
the organization requesting participation in the Domain Name System-
Based Security for Electronic Mail Building Block and the capabilities 
and components that are being offered to the collaborative effort. 
Letters of interest will be accepted on a first come, first served 
basis. Collaborative activities will commence as soon as enough 
completed and signed letters of interest have been returned to address 
all the necessary components and capabilities, but no earlier than 
November 5, 2015. When the building block has been completed, NIST will 
post a notice on the Domain Name System-Based Security for Electronic 
Mail Building Block Web site at http://nccoe.nist.gov/DNSSecuredEmail 
announcing the completion of the building block and informing the 
public that it will no longer accept letters of interest for this 
building block.

ADDRESSES: The NCCoE is located at 9600 Gudelsky Drive, Rockville, MD 
20850. Letters of interest must be submitted to [email protected] or via hardcopy to National Institute of Standards and 
Technology, NCCoE; 9600 Gudelsky Drive; Rockville, MD 20850. 
Organizations whose letters of interest are accepted in accordance with 
the process set forth in the SUPPLEMENTARY INFORMATION section of this 
notice will be asked to sign a Cooperative Research and Development 
Agreement (CRADA) with NIST. A CRADA template can be found at: http://nccoe.nist.gov/node/138.

FOR FURTHER INFORMATION CONTACT: William C. Barker via email to [email protected]; by telephone 301-975-3655; or by mail to National 
Institute of Standards and Technology, NCCoE; 9600 Gudelsky Drive; 
Rockville, MD 20850. Additional details about the Domain Name System-
Based Security for Electronic Mail Building Block are available at 
http://nccoe.nist.gov/DNSSecuredEmail.

SUPPLEMENTARY INFORMATION:
    Background: The NCCoE, part of NIST, is a public-private 
collaboration for accelerating the widespread adoption of integrated 
cybersecurity tools and technologies. The NCCoE brings together experts 
from industry, government, and academia under one roof to develop 
practical, interoperable cybersecurity approaches that address the 
real-world needs of complex Information Technology (IT) systems. By 
accelerating dissemination and use of these integrated tools and 
technologies for protecting IT assets, the NCCoE will enhance trust in 
U.S. IT communications, data, and storage systems; reduce risk for 
companies and individuals using IT systems; and encourage development 
of innovative, job-creating cybersecurity products and services.
    Process: NIST is soliciting responses from all sources of relevant 
security capabilities (see below) to enter into a Cooperative Research 
and Development Agreement (CRADA) to provide products and technical 
expertise to support and demonstrate security platforms for the Domain 
Name System-Based Security for Electronic Mail Building Block. The full 
building block description can be viewed at: http://nccoe.nist.gov/DNSSecuredEmail.
    Interested parties should contact NIST using the information 
provided in the FOR FURTHER INFORMATION CONTACT section of this notice. 
NIST will then provide each interested party with a letter of interest 
template, which the party must complete, certify that it is accurate, 
and submit to NIST and which identifies the organization requesting 
participation in the Domain Name System-Based Security for Electronic 
Mail Building Block and the capabilities and components that are being 
offered to the collaborative effort. NIST will contact interested 
parties if there are questions regarding the responsiveness of the 
letters of interest to the building block objective or requirements 
identified below and to obtain additional information. NIST will select 
participants who have submitted complete letters of interest on a first 
come, first served basis within each category of product components or 
capabilities listed below up to the number of participants in each 
category necessary to carry out the Domain Name System-Based Security 
for Electronic Mail Building Block. However, there may be continuing 
opportunity to participate even after initial activity commences. 
Selected participants will be required to enter into a consortium CRADA 
with NIST (for reference, see ADDRESSES section above). NIST published 
a notice in the Federal Register on October 19, 2012 (77 FR 64314) 
inviting U.S. companies to enter into National Cybersecurity Excellence 
Partnerships (NCEPs) in furtherance of the NCCoE. For this 
demonstration project, NCEP partners will not be given priority for 
participation.

Building Block Objective

    Both public and private sector business operations are heavily 
reliant on electronic mail (email) exchanges. The need to protect 
business plans and tactics, the integrity of transactions, financial 
and other proprietary information, and privacy of employees and clients 
are only four of the factors that motivate organizations to secure 
their email exchanges. Whether the security service desired is 
authentication of the source of an email message, assurance that the 
message has not been altered by an unauthorized party, or 
confidentiality of message contents, cryptographic functions are 
usually employed in providing the service. Economies of scale and a 
need for uniform security implementation drive most enterprises to rely 
on mail

[[Page 60364]]

servers to provide security to the members of an enterprise rather than 
end-to-end security mechanisms operated by individual users. Most 
current server-based email security mechanisms are vulnerable to, and 
have been defeated by, attacks on the integrity of the cryptographic 
implementations on which they depend. The consequences frequently 
involve unauthorized parties being able to read or modify supposedly 
secure information, or to use email as a vector for inserting malware 
into the system that is intended to deny access to critical information 
or processes or to damage or destroy system components and/or 
information. Improved email security can help protect organizations and 
individuals against these consequences and also serve as a marketing 
discriminator for email service providers as well as improve the 
trustworthiness of enterprise email exchanges.
    Domain Name System Security Extensions (DNSSEC) for the Domain Name 
System (DNS) are technical mechanisms employed by internet service 
providers to protect against unauthorized modification to network 
management information and connections to devices operated by 
untrustworthy parties. DNS-based Authentication of Named Entities 
(DANE) is a protocol that securely associates domain names with 
cryptographic certificates and related security information so that 
they can't be fraudulently modified or replaced to breach the security 
of Internet exchanges. In spite of the dangers of failure to 
authenticate the identities of network devices, adoption of DNSSEC has 
been slow. Demonstration of DANE-supported applications such as 
reliably secure email may support increased user demand for domain name 
system security. Follow-on projects might include HTTPS, IOT, IPSEC 
keys in DNS, and DNS service discovery.
    The current project will demonstrate a proof of concept security 
platform composed of off the shelf components that provides trustworthy 
mail server-to-mail server email exchanges across organizational 
boundaries. The DANE protocol will be used to authenticate servers and 
certificates in two roles in the DNS-Based Security for Email Project: 
(1) By binding the X.509 certificates used for Transport Layer Security 
(TLS) to DNS names verified by DNSSEC and supporting the use of these 
certificates in the mail server-to-mail server communication; and (2) 
by binding the X.509 certificates used for Secure Secure/Multipurpose 
Internet Mail Extensions (S/MIME) to email addresses encoded as DNS 
names verified by DNSSEC. These bindings support trust in the use of S/
MIME certificates in the end-to-end email communication. The resulting 
building block will encrypt email traffic between servers, allow 
individual email users to digitally sign and/or encrypt email messages 
to other end users, and allow individual email users to obtain other 
users' certificates in order to validate signed email or send encrypted 
email. The project will include an email sending policy consistent with 
a stated privacy policy that can be parsed by receiving servers so that 
receiving servers can apply the correct security checks and report back 
the correctness of the email stream. Documentation of the resulting 
platform will include statements of the security and privacy policies 
and standards (e.g., Executive Orders, NIST standards and guidelines, 
IETF RFCs) supported, technical specifications for hardware and 
software, implementation requirements, and a mapping of implementation 
requirements to the applicable policies, standards, and best practices.
    The secure email project will involve composition of a variety of 
components that will be provided by a number of different vendors. 
Client systems, DNS/DNSSEC services, mail transfer agents, and 
certificate providers (CAs) are generally involved. Collaborators are 
being sought to provide components and expertise for DNS resolvers 
(stub and recursive) for DNSSEC, authoritative DNS servers for DNSSEC 
signed zones, mail servers and mail security components, extended 
validation and domain validation TLS certificates.
    This project will result in one or more demonstration prototype 
DNS-based secure email platforms, a publicly available NIST 
Cybersecurity Practice Guide that explains how to employ the 
platform(s) to meet security and privacy requirements, and platform 
documentation necessary to compose a DNS-based email security platform 
from off the shelf components.
    A detailed description of the Domain Name System-Based Security for 
Electronic Mail Building Block is available at: http://nccoe.nist.gov/DNSSecuredEmail.
    Requirements: Each responding organization's letter of interest 
should identify which security platform component(s) or capability(ies) 
it is offering. Letters of interest should not include company 
proprietary information, and all components and capabilities must be 
commercially available. Components are listed in section eight of the 
Domain Name System-Based Security for Electronic Mail Building Block 
description (for reference, please see the link in the PROCESS section 
above) and include, but are not limited to:

 Client systems
 DNS/DNSSEC services
 Mail transfer agents
 DNS resolvers (stub and recursive) for DNSSEC validation
 Authoritative DNS servers for DNSSEC signed zones
 Mail server/mail security systems
 S/MIME certificates
 Extended validation and domain validation TLS certificates

    Each responding organization's letter of interest should identify 
how their product(s) address one or more of the desired solution 
characteristics in section five of the Domain Name System-Based 
Security for Electronic Mail Building Block description (for reference, 
please see the link in the PROCESS section above).
    Additional details about the Domain Name System-Based Security for 
Electronic Mail Building Block are available at: http://nccoe.nist.gov/DNSSecuredEmail.
    NIST cannot guarantee that all of the products proposed by 
respondents will be used in the demonstration. Each prospective 
participant will be expected to work collaboratively with NIST staff 
and other project participants under the terms of the consortium CRADA 
in the development of the Domain Name System-Based Security for 
Electronic Mail Building Block. Prospective participants' contribution 
to the collaborative effort will include assistance in establishing the 
necessary interface functionality, connection and set-up capabilities 
and procedures, demonstration harnesses, environmental and safety 
conditions for use, integrated platform user instructions, and 
demonstration plans and scripts necessary to demonstrate the desired 
capabilities. Each participant will train NIST personnel, as necessary, 
to operate its product in capability demonstrations. Following 
successful demonstrations, NIST will publish a description of the 
security platform and its performance characteristics sufficient to 
permit other organizations to develop and deploy security platforms 
that meet the security objectives of the Domain Name System-Based 
Security for Electronic Mail Building Block. These descriptions will be 
public information.
    Under the terms of the consortium CRADA, participants will commit 
to providing:

1. Access for all participants' project teams to component interfaces 
and

[[Page 60365]]

the organization's experts necessary to make functional connections 
among security platform components
2. Support for development and demonstration of the Domain Name System-
Based Security for Electronic Mail Building Block in NCCoE facilities 
which will be conducted in a manner consistent with Federal 
requirements (e.g., FIPS 200, FIPS 201, SP 800-53, and SP 800-63)

    In addition, NIST will support development of interfaces among 
participants' products by providing IT infrastructure, laboratory 
facilities, office facilities, collaboration facilities, and staff 
support to component composition, security platform documentation, and 
demonstration activities.
    The dates of the demonstration of the Domain Name System-Based 
Security for Electronic Mail Building Block capability will be 
announced on the NCCoE Web site at least two weeks in advance at http://nccoe.nist.gov/. The expected outcome of the demonstration is to 
improve domain name system-based security for electronic mail within 
the enterprise. Participating organizations will gain from the 
knowledge that their products are interoperable with other 
participants' offerings.
    For additional information on the NCCoE governance, business 
processes, and NCCoE operational structure, visit the NCCoE Web site 
http://nccoe.nist.gov/.

Richard Cavanagh,
Acting Associate Director for Laboratory Programs.
[FR Doc. 2015-25304 Filed 10-5-15; 8:45 am]
BILLING CODE 3510-13-P



                                                                           Federal Register / Vol. 80, No. 193 / Tuesday, October 6, 2015 / Notices                                           60363

                                              identification card for access to federal               and capabilities, but no earlier than                 Based Security for Electronic Mail
                                              facilities if such license or identification            November 5, 2015. When the building                   Building Block. The full building block
                                              card is issued by a state that is                       block has been completed, NIST will                   description can be viewed at: http://
                                              compliant with the REAL ID Act of 2005                  post a notice on the Domain Name                      nccoe.nist.gov/DNSSecuredEmail.
                                              (P.L. 109–13), or by a state that has an                System-Based Security for Electronic                    Interested parties should contact NIST
                                              extension for REAL ID compliance.                       Mail Building Block Web site at                       using the information provided in the
                                              NIST currently accepts other forms of                   http://nccoe.nist.gov/DNSSecuredEmail                 FOR FURTHER INFORMATION CONTACT
                                              federal-issued identification in lieu of a              announcing the completion of the                      section of this notice. NIST will then
                                              state-issued driver’s license. For                      building block and informing the public               provide each interested party with a
                                              detailed information please contact Ms.                 that it will no longer accept letters of              letter of interest template, which the
                                              Young or visit: http://www.nist.gov/                    interest for this building block.                     party must complete, certify that it is
                                              public_affairs/visitor/.                                ADDRESSES: The NCCoE is located at                    accurate, and submit to NIST and which
                                                                                                      9600 Gudelsky Drive, Rockville, MD                    identifies the organization requesting
                                              Richard Cavanagh,                                                                                             participation in the Domain Name
                                                                                                      20850. Letters of interest must be
                                              Acting Associate Director for Laboratory                submitted to dns-email-nccoe@nist.gov                 System-Based Security for Electronic
                                              Programs.                                                                                                     Mail Building Block and the capabilities
                                                                                                      or via hardcopy to National Institute of
                                              [FR Doc. 2015–25310 Filed 10–5–15; 8:45 am]                                                                   and components that are being offered
                                                                                                      Standards and Technology, NCCoE;
                                              BILLING CODE 3510–13–P                                  9600 Gudelsky Drive; Rockville, MD                    to the collaborative effort. NIST will
                                                                                                      20850. Organizations whose letters of                 contact interested parties if there are
                                                                                                      interest are accepted in accordance with              questions regarding the responsiveness
                                              DEPARTMENT OF COMMERCE                                  the process set forth in the                          of the letters of interest to the building
                                                                                                      SUPPLEMENTARY INFORMATION section of                  block objective or requirements
                                              National Institute of Standards and                                                                           identified below and to obtain
                                              Technology                                              this notice will be asked to sign a
                                                                                                      Cooperative Research and Development                  additional information. NIST will select
                                              [Docket No. 150917865–5865–01]                          Agreement (CRADA) with NIST. A                        participants who have submitted
                                                                                                      CRADA template can be found at:                       complete letters of interest on a first
                                              National Cybersecurity Center of                        http://nccoe.nist.gov/node/138.                       come, first served basis within each
                                              Excellence (NCCoE) Domain Name                                                                                category of product components or
                                                                                                      FOR FURTHER INFORMATION CONTACT:
                                              System-Based Security (DNS) for                                                                               capabilities listed below up to the
                                                                                                      William C. Barker via email to dns-
                                              Electronic Mail Building Block                                                                                number of participants in each category
                                                                                                      email-nccoe@nist.gov; by telephone
                                                                                                      301–975–3655; or by mail to National                  necessary to carry out the Domain Name
                                              AGENCY: National Institute of Standards
                                                                                                      Institute of Standards and Technology,                System-Based Security for Electronic
                                              and Technology, Department of
                                                                                                      NCCoE; 9600 Gudelsky Drive; Rockville,                Mail Building Block. However, there
                                              Commerce.
                                                                                                      MD 20850. Additional details about the                may be continuing opportunity to
                                              ACTION: Notice.
                                                                                                      Domain Name System-Based Security                     participate even after initial activity
                                              SUMMARY:    The National Institute of                                                                         commences. Selected participants will
                                                                                                      for Electronic Mail Building Block are
                                              Standards and Technology (NIST)                                                                               be required to enter into a consortium
                                                                                                      available at http://nccoe.nist.gov/
                                              invites organizations to provide                                                                              CRADA with NIST (for reference, see
                                                                                                      DNSSecuredEmail.
                                              products and technical expertise to                                                                           ADDRESSES section above). NIST
                                                                                                      SUPPLEMENTARY INFORMATION:                            published a notice in the Federal
                                              support and demonstrate security                           Background: The NCCoE, part of
                                              platforms for the Domain Name System-                                                                         Register on October 19, 2012 (77 FR
                                                                                                      NIST, is a public-private collaboration               64314) inviting U.S. companies to enter
                                              Based (DNS) Security for Electronic                     for accelerating the widespread
                                              Mail Building Block. This notice is the                                                                       into National Cybersecurity Excellence
                                                                                                      adoption of integrated cybersecurity                  Partnerships (NCEPs) in furtherance of
                                              initial step for the National                           tools and technologies. The NCCoE
                                              Cybersecurity Center of Excellence                                                                            the NCCoE. For this demonstration
                                                                                                      brings together experts from industry,                project, NCEP partners will not be given
                                              (NCCoE) in collaborating with                           government, and academia under one
                                              technology companies to address                                                                               priority for participation.
                                                                                                      roof to develop practical, interoperable
                                              cybersecurity challenges identified                     cybersecurity approaches that address                 Building Block Objective
                                              under the Domain Name System-Based                      the real-world needs of complex                          Both public and private sector
                                              Security for Electronic Mail Building                   Information Technology (IT) systems.                  business operations are heavily reliant
                                              Block. Participation in this building                   By accelerating dissemination and use                 on electronic mail (email) exchanges.
                                              block is open to all interested                         of these integrated tools and                         The need to protect business plans and
                                              organizations.                                          technologies for protecting IT assets, the            tactics, the integrity of transactions,
                                              DATES: Interested parties must contact                  NCCoE will enhance trust in U.S. IT                   financial and other proprietary
                                              NIST to request a letter of interest                    communications, data, and storage                     information, and privacy of employees
                                              template to be completed and submitted                  systems; reduce risk for companies and                and clients are only four of the factors
                                              to NIST that identifies the organization                individuals using IT systems; and                     that motivate organizations to secure
                                              requesting participation in the Domain                  encourage development of innovative,                  their email exchanges. Whether the
                                              Name System-Based Security for                          job-creating cybersecurity products and               security service desired is
                                              Electronic Mail Building Block and the                  services.                                             authentication of the source of an email
                                              capabilities and components that are                       Process: NIST is soliciting responses              message, assurance that the message has
tkelley on DSK3SPTVN1PROD with NOTICES




                                              being offered to the collaborative effort.              from all sources of relevant security                 not been altered by an unauthorized
                                              Letters of interest will be accepted on a               capabilities (see below) to enter into a              party, or confidentiality of message
                                              first come, first served basis.                         Cooperative Research and Development                  contents, cryptographic functions are
                                              Collaborative activities will commence                  Agreement (CRADA) to provide                          usually employed in providing the
                                              as soon as enough completed and signed                  products and technical expertise to                   service. Economies of scale and a need
                                              letters of interest have been returned to               support and demonstrate security                      for uniform security implementation
                                              address all the necessary components                    platforms for the Domain Name System-                 drive most enterprises to rely on mail


                                         VerDate Sep<11>2014   18:31 Oct 05, 2015   Jkt 238001   PO 00000   Frm 00015   Fmt 4703   Sfmt 4703   E:\FR\FM\06OCN1.SGM   06OCN1


                                              60364                        Federal Register / Vol. 80, No. 193 / Tuesday, October 6, 2015 / Notices

                                              servers to provide security to the                      addresses encoded as DNS names                        System-Based Security for Electronic
                                              members of an enterprise rather than                    verified by DNSSEC. These bindings                    Mail Building Block description (for
                                              end-to-end security mechanisms                          support trust in the use of S/MIME                    reference, please see the link in the
                                              operated by individual users. Most                      certificates in the end-to-end email                  PROCESS section above) and include,
                                              current server-based email security                     communication. The resulting building                 but are not limited to:
                                              mechanisms are vulnerable to, and have                  block will encrypt email traffic between              • Client systems
                                              been defeated by, attacks on the                        servers, allow individual email users to              • DNS/DNSSEC services
                                              integrity of the cryptographic                          digitally sign and/or encrypt email                   • Mail transfer agents
                                              implementations on which they depend.                   messages to other end users, and allow                • DNS resolvers (stub and recursive) for
                                              The consequences frequently involve                     individual email users to obtain other                   DNSSEC validation
                                              unauthorized parties being able to read                 users’ certificates in order to validate              • Authoritative DNS servers for
                                              or modify supposedly secure                             signed email or send encrypted email.                    DNSSEC signed zones
                                              information, or to use email as a vector                The project will include an email                     • Mail server/mail security systems
                                              for inserting malware into the system                   sending policy consistent with a stated               • S/MIME certificates
                                              that is intended to deny access to                      privacy policy that can be parsed by                  • Extended validation and domain
                                              critical information or processes or to                 receiving servers so that receiving                      validation TLS certificates
                                              damage or destroy system components                     servers can apply the correct security                   Each responding organization’s letter
                                              and/or information. Improved email                      checks and report back the correctness                of interest should identify how their
                                              security can help protect organizations                 of the email stream. Documentation of                 product(s) address one or more of the
                                              and individuals against these                           the resulting platform will include                   desired solution characteristics in
                                              consequences and also serve as a                        statements of the security and privacy                section five of the Domain Name
                                              marketing discriminator for email                       policies and standards (e.g., Executive               System-Based Security for Electronic
                                              service providers as well as improve the                Orders, NIST standards and guidelines,                Mail Building Block description (for
                                              trustworthiness of enterprise email                     IETF RFCs) supported, technical                       reference, please see the link in the
                                              exchanges.                                              specifications for hardware and                       PROCESS section above).
                                                 Domain Name System Security                          software, implementation requirements,                   Additional details about the Domain
                                              Extensions (DNSSEC) for the Domain                      and a mapping of implementation                       Name System-Based Security for
                                              Name System (DNS) are technical                         requirements to the applicable policies,              Electronic Mail Building Block are
                                              mechanisms employed by internet                         standards, and best practices.                        available at: http://nccoe.nist.gov/
                                              service providers to protect against                      The secure email project will involve               DNSSecuredEmail.
                                              unauthorized modification to network                    composition of a variety of components                   NIST cannot guarantee that all of the
                                              management information and                              that will be provided by a number of                  products proposed by respondents will
                                              connections to devices operated by                      different vendors. Client systems, DNS/               be used in the demonstration. Each
                                              untrustworthy parties. DNS-based                        DNSSEC services, mail transfer agents,
                                                                                                                                                            prospective participant will be expected
                                              Authentication of Named Entities                        and certificate providers (CAs) are
                                                                                                                                                            to work collaboratively with NIST staff
                                              (DANE) is a protocol that securely                      generally involved. Collaborators are
                                                                                                                                                            and other project participants under the
                                              associates domain names with                            being sought to provide components
                                                                                                                                                            terms of the consortium CRADA in the
                                              cryptographic certificates and related                  and expertise for DNS resolvers (stub
                                                                                                                                                            development of the Domain Name
                                              security information so that they can’t                 and recursive) for DNSSEC,
                                                                                                                                                            System-Based Security for Electronic
                                              be fraudulently modified or replaced to                 authoritative DNS servers for DNSSEC
                                                                                                                                                            Mail Building Block. Prospective
                                              breach the security of Internet                         signed zones, mail servers and mail
                                                                                                                                                            participants’ contribution to the
                                              exchanges. In spite of the dangers of                   security components, extended
                                                                                                                                                            collaborative effort will include
                                              failure to authenticate the identities of               validation and domain validation TLS
                                              network devices, adoption of DNSSEC                     certificates.                                         assistance in establishing the necessary
                                              has been slow. Demonstration of DANE-                     This project will result in one or more             interface functionality, connection and
                                              supported applications such as reliably                 demonstration prototype DNS-based                     set-up capabilities and procedures,
                                              secure email may support increased                      secure email platforms, a publicly                    demonstration harnesses, environmental
                                              user demand for domain name system                      available NIST Cybersecurity Practice                 and safety conditions for use, integrated
                                              security. Follow-on projects might                      Guide that explains how to employ the                 platform user instructions, and
                                              include HTTPS, IOT, IPSEC keys in                       platform(s) to meet security and privacy              demonstration plans and scripts
                                              DNS, and DNS service discovery.                         requirements, and platform                            necessary to demonstrate the desired
                                                 The current project will demonstrate                 documentation necessary to compose a                  capabilities. Each participant will train
                                              a proof of concept security platform                    DNS-based email security platform from                NIST personnel, as necessary, to operate
                                              composed of off the shelf components                    off the shelf components.                             its product in capability
                                              that provides trustworthy mail server-to-                 A detailed description of the Domain                demonstrations. Following successful
                                              mail server email exchanges across                      Name System-Based Security for                        demonstrations, NIST will publish a
                                              organizational boundaries. The DANE                     Electronic Mail Building Block is                     description of the security platform and
                                              protocol will be used to authenticate                   available at: http://nccoe.nist.gov/                  its performance characteristics sufficient
                                              servers and certificates in two roles in                DNSSecuredEmail.                                      to permit other organizations to develop
                                              the DNS-Based Security for Email                          Requirements: Each responding                       and deploy security platforms that meet
                                              Project: (1) By binding the X.509                       organization’s letter of interest should              the security objectives of the Domain
                                              certificates used for Transport Layer                   identify which security platform                      Name System-Based Security for
tkelley on DSK3SPTVN1PROD with NOTICES




                                              Security (TLS) to DNS names verified by                 component(s) or capability(ies) it is                 Electronic Mail Building Block. These
                                              DNSSEC and supporting the use of these                  offering. Letters of interest should not              descriptions will be public information.
                                              certificates in the mail server-to-mail                 include company proprietary                              Under the terms of the consortium
                                              server communication; and (2) by                        information, and all components and                   CRADA, participants will commit to
                                              binding the X.509 certificates used for                 capabilities must be commercially                     providing:
                                              Secure Secure/Multipurpose Internet                     available. Components are listed in                   1. Access for all participants’ project
                                              Mail Extensions (S/MIME) to email                       section eight of the Domain Name                           teams to component interfaces and


                                         VerDate Sep<11>2014   18:31 Oct 05, 2015   Jkt 238001   PO 00000   Frm 00016   Fmt 4703   Sfmt 4703   E:\FR\FM\06OCN1.SGM   06OCN1


                                                                           Federal Register / Vol. 80, No. 193 / Tuesday, October 6, 2015 / Notices                                                 60365

                                                   the organization’s experts necessary                  OMB Control Number: 0648–0538.                       Written comments and
                                                   to make functional connections                        Form Number(s): None.                              recommendations for the proposed
                                                   among security platform                               Type of Request: Regular (revision                 information collection should be sent
                                                   components                                         and extension of a currently approved                 within 30 days of publication of this
                                              2. Support for development and                          information collection).                              notice to OIRA_Submission@
                                                   demonstration of the Domain Name                      Number of Respondents: 1,000.                      omb.eop.gov or fax to (202) 395–5806.
                                                   System-Based Security for                             Average Hours per Response: One to
                                                                                                      three hours.                                            Dated: October 1, 2015.
                                                   Electronic Mail Building Block in
                                                                                                         Burden Hours: 3,000.                               Sarah Brabson,
                                                   NCCoE facilities which will be
                                                   conducted in a manner consistent                      Needs and Uses: This request is for a              NOAA PRA Clearance Officer.
                                                   with Federal requirements (e.g.,                   revision and extension of a currently                 [FR Doc. 2015–25378 Filed 10–5–15; 8:45 am]
                                                   FIPS 200, FIPS 201, SP 800–53, and                 approved information collection. The                  BILLING CODE 3510–NW–P
                                                   SP 800–63)                                         National Environmental Policy Act
                                                                                                      (‘‘NEPA’’; 42 U.S.C. 4321–4370) requires
                                                 In addition, NIST will support
                                                                                                      federal agencies to complete an                       DEPARTMENT OF COMMERCE
                                              development of interfaces among
                                                                                                      environmental analysis for all major
                                              participants’ products by providing IT                                                                        National Oceanic and Atmospheric
                                                                                                      federal actions, including funding non-
                                              infrastructure, laboratory facilities,                                                                        Administration
                                                                                                      federal projects through federal
                                              office facilities, collaboration facilities,
                                                                                                      financial assistance awards where
                                              and staff support to component                                                                                Proposed Information Collection;
                                                                                                      Federal participation in the funded
                                              composition, security platform                                                                                Comment Request; Limits of
                                                                                                      activity is expected to be significant.
                                              documentation, and demonstration                                                                              Application of the Take Prohibitions
                                                                                                      This Environmental Compliance
                                              activities.
                                                 The dates of the demonstration of the                Questionnaire for National Oceanic and                AGENCY: National Oceanic and
                                              Domain Name System-Based Security                       Atmospheric Administration Federal                    Atmospheric Administration (NOAA),
                                              for Electronic Mail Building Block                      Financial Assistance Applicants                       Commerce.
                                              capability will be announced on the                     (Questionnaire) is used by the National               ACTION: Notice.
                                              NCCoE Web site at least two weeks in                    Oceanic and Atmospheric
                                              advance at http://nccoe.nist.gov/. The                  Administration (NOAA) to collect                      SUMMARY:    The Department of
                                              expected outcome of the demonstration                   information about proposed activities                 Commerce, as part of its continuing
                                              is to improve domain name system-                       for NEPA and other environmental                      effort to reduce paperwork and
                                              based security for electronic mail within               compliance requirements associated                    respondent burden, invites the general
                                              the enterprise. Participating                           with proposed projects, such as federal               public and other Federal agencies to
                                              organizations will gain from the                        consultations. The Questionnaire is                   take this opportunity to comment on
                                              knowledge that their products are                       used in conjunction with NOAA                         proposed and/or continuing information
                                              interoperable with other participants’                  Funding Opportunity Announcements                     collections, as required by the
                                              offerings.                                              (FOA). Applicants are required to                     Paperwork Reduction Act of 1995.
                                                 For additional information on the                    provide only the information from this                DATES: Written comments must be
                                              NCCoE governance, business processes,                   Questionnaire that is specified in the                submitted on or before December 7,
                                              and NCCoE operational structure, visit                  FOA to which they are applying. The                   2015.
                                              the NCCoE Web site http://                              FOA may present these questions in one
                                                                                                                                                            ADDRESSES:    Direct all written comments
                                              nccoe.nist.gov/.                                        of two ways: (1) The applicable
                                                                                                                                                            to Jennifer Jessup, Departmental
                                                                                                      questions can be inserted directly into
                                              Richard Cavanagh,                                                                                             Paperwork Clearance Officer,
                                                                                                      the FOA with reference to the OMB
                                              Acting Associate Director for Laboratory                                                                      Department of Commerce, Room 6616,
                                                                                                      Control Number (0648–0538) for this
                                              Programs.                                                                                                     14th and Constitution Avenue NW.,
                                                                                                      form; or (2) The FOA can specify which
                                                                                                                                                            Washington, DC 20230 (or via the
                                              [FR Doc. 2015–25304 Filed 10–5–15; 8:45 am]             questions (e.g. 1, 2) an applicant must
                                                                                                                                                            Internet at JJessup@doc.gov).
                                              BILLING CODE 3510–13–P                                  answer, with the entire OMB-approved
                                                                                                      Questionnaire attached to the FOA. This               FOR FURTHER INFORMATION CONTACT:
                                                                                                      Questionnaire has been revised to (1)                 Requests for additional information or
                                              DEPARTMENT OF COMMERCE                                  remove repetitive questions; (2) revise               copies of the information collection
                                                                                                      specific questions to use plain language              instrument and instructions should be
                                              National Oceanic and Atmospheric                                                                              directed to Gary Rule, NOAA Fisheries,
                                                                                                      instead of NEPA-specific language; and
                                              Administration                                                                                                1201 NE Lloyd Blvd. Suite 1100,
                                                                                                      (3) add questions that would be helpful
                                                                                                      to a wider range of NOAA programs.                    Portland, OR 97232, (503) 230–5424 or
                                              Submission for OMB Review;                                                                                    gary.rule@noaa.gov.
                                              Comment Request                                         The revision reduced the overall
                                                                                                      number of questions by 22.                            SUPPLEMENTARY INFORMATION:
                                                The Department of Commerce will                          Affected Public: Individuals or                    I. Abstract
                                              submit to the Office of Management and                  households; business or other for-profit
                                              Budget (OMB) for clearance the                          organizations; not-for-profit institutions;              This request is for extension of a
                                              following proposal for collection of                    state, local, or tribal government; and               currently approved information
                                              information under the provisions of the                 federal government.                                   collection. Section 4(d) of the
                                              Paperwork Reduction Act (44 U.S.C.                         Frequency: On occasion.                            Endangered Species Act of 1973 (ESA;
tkelley on DSK3SPTVN1PROD with NOTICES




                                              Chapter 35).                                               Respondent’s Obligation: Required to               16 U.S.C. 1531 et seq.) requires the
                                                Agency: National Oceanic and                          obtain or retain benefits.                            National Marine Fisheries Service
                                              Atmospheric Administration (NOAA).                         This information collection request                (NMFS) to adopt such regulations as it
                                                Title: Environmental Compliance                       may be viewed at reginfo.gov. Follow                  ‘‘deems necessary and advisable to
                                              Questionnaire for National Oceanic and                  the instructions to view Department of                provide for the conservation of’’
                                              Atmospheric Administration Federal                      Commerce collections currently under                  threatened species. Those regulations
                                              Financial Assistance Applicants.                        review by OMB.                                        may include any or all of the


                                         VerDate Sep<11>2014   18:31 Oct 05, 2015   Jkt 238001   PO 00000   Frm 00017   Fmt 4703   Sfmt 4703   E:\FR\FM\06OCN1.SGM   06OCN1



Document Created: 2015-12-15 08:50:58
Document Modified: 2015-12-15 08:50:58
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice.
DatesInterested parties must contact NIST to request a letter of interest template to be completed and submitted to NIST that identifies the organization requesting participation in the Domain Name System- Based Security for Electronic Mail Building Block and the capabilities and components that are being offered to the collaborative effort. Letters of interest will be accepted on a first come, first served basis. Collaborative activities will commence as soon as enough
ContactWilliam C. Barker via email to dns- [email protected]; by telephone 301-975-3655; or by mail to National Institute of Standards and Technology, NCCoE; 9600 Gudelsky Drive; Rockville, MD 20850. Additional details about the Domain Name System- Based Security for Electronic Mail Building Block are available at http://nccoe.nist.gov/DNSSecuredEmail.
FR Citation80 FR 60363 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR