ThomasNet News Logo
Sign Up | Log In | ThomasNet Home | Promote Your Business

NIST Seeks Comments on guidelines for securing BIOS for servers.

Print | 
Email |  Comment   Share  
August 27, 2012 - NIST requests comments on draft of BIOS Protection Guidelines for Servers, which provides procedures for securing BIOS (Basic Input/Output System) systems for server computers. Publication specifically addresses BIOS security in varied architectures specific to servers, as opposed to BIOS Protection Guidelines (NIST SP 800-147) that NIST published in 2011 which provided instructions for protecting BIOS in desktops and laptops.

Security First: New NIST Guidelines on Securing BIOS for Servers


National Institute of Standards & Technology
100 Bureau Dr., Stop 1070
Gaithersburg, MD, 20899-1070
USA



Press release date: August 21, 2012

The National Institute of Standards and Technology (NIST) is requesting comments on new draft guidelines for securing BIOS systems for server computers. BIOS-Basic Input/output System-is the first major software that runs when a computer starts up. Both obscure and fundamental, the BIOS has become a target for hackers.

Server manufacturers routinely update BIOS to fix bugs, patch vulnerabilities or support new hardware. However, while authorized updates to BIOS can improve functionality or security, unauthorized or malicious changes could be part of a sophisticated, targeted attack on an organization, allowing an attacker to infiltrate an organization's systems or disrupt their operations. BIOS attacks are an emerging threat area. In September, 2011, a security company discovered the first malware designed to infect the BIOS, called Mebromi.*

An important mechanism for protecting BIOS in servers is to secure the BIOS update process, guarding against unauthorized BIOS updates. NIST's 2011 publication on BIOS security** provided instructions for protecting BIOS in desktops and laptops. The guidelines focused on the core principles of authenticating updates using digital signatures, BIOS integrity protection and "non-bypassibility" features that ensure that no mechanisms circumvent the BIOS protections.

BIOS Protection Guidelines for Servers addresses BIOS security in the varied architectures used by servers. "While laptop and desktop computers have largely converged on a single architecture for system BIOS, server class systems have a more diverse set of architectures, and more mechanisms for updating or modifying the system BIOS," says author Andrew Regenscheid. In addition, many servers contain service processors that perform a variety of management functions that may include BIOS updates, and this document provides additional security guidelines for service processors.

Servers require more flexibility, according to Regenscheid, because in addition to having different architectures, they are almost always managed remotely. BIOS Protection Guidelines for Servers is written for server developers and information system security professionals responsible for server security, secure boot processes and hardware security modules. The draft publication BIOS Protections Guidelines for Servers, (NIST Special Publication 800-147B), is available at http://csrc.nist.gov/publications/drafts/800-147b/draft-sp800-147b_july2012.pdf. NIST requests comments on this draft by Sept. 14, 2012. Please email all comments to 800-147comments@nist.gov.

* Information on Mebromi: www.symantec.com/security_response/writeup.jsp?docid=2011-090609-4557-99. ** D.A. Cooper, W.T. Polk, A.R. Regenscheid and M.P. Souppaya. BIOS Protection Guidelines (NIST SP 800-147) is available at www.nist.gov/manuscript-publication-search.cfm?pub_id=908423.

Media Contact: Evelyn Brown, evelyn.brown@nist.gov, 301-975-5661
Print | 
Email |  Comment   Share  
Contacts: View detailed contact information.


 

Post a comment about this story

Name:
E-mail:
(your e-mail address will not be posted)
Comment title:
Comment:
To submit comment, enter the security code shown below and press 'Post Comment'.
 



 See related product stories
More .....
<!-- PNA - News | PNACON |  18860 -->
Don’t hunt for stories like this.
Let Services
Product News Come to You!
Get a Free Subscription
to Product News Alerts.
-- IMT - News | IMTREG2 |  18716 --
Start Your Free
Subscription to
Industry Market Trends.
 See more product news in:
Services
 More New Product News from this company:
NIST-Sponsored Report addresses greenhouse gas measurement.
Disaster/Failure Study Data will be available via NIST website.
NIST Physicist receives 2011 William F. Meggers Award.
More ....
 Other News from this company:
Five at NIST Honored with Flemming Awards
NIST Fire Protection Engineer Named Service to America Finalist
New Report Identifies Strategies to Achieve Net-Zero Energy Homes
NIST Demonstrates Transfer of Ultraprecise Time Signals over a Wireless Optical Channel
Second Cybersecurity Infrastructure Framework Workshop Gathers May 29-31, 2013
More ....
 Tools for you
Watch Company 
View Company Profile
Company web site
More news from this company
E-Mail Story
Save Story
Search for suppliers of
Trade Associations


Home  |  My ThomasNet News®  |  Industry Market Trends®  |  Submit Release  |  Advertise  |  Contact News  |  About Us
Brought to you by Thomasnet.com        Browse ThomasNet Directory

Copyright © 2013 Thomas Publishing Company. All Rights Reserved.
Terms of Use - Privacy Policy



Error close

Please enter a valid email address