These are the best NIST Resources resources to use for software security. (To launch in a new window, hold down the ctrl key.)
- Draft Cyber Supply Chain Risk Management Practices for Systems and Organization, NIST SP 800-161 Rev. 1 (2nd draft)
- Secure Software DevelopmentFramework (SSDF) Version 1.1
- Secure Software Development Framework (SSDF)
- NIST: Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1
- NIST: SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
- Defending Against Software Supply Chain Attacks (joint CISA-NIST publication issued by CISA)
- Key Practices in Cyber Supply Chain Risk Management: Observations from Industry, NISTIR 8276
- Criticality Analysis Process Model: Prioritizing Systems and Components, NISTIR 8179
- NIST: SP 800-160 Vol. 1, Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
These are the best Non-NIST Resources resources to use for software security. (To launch in a new window, hold down the ctrl key.)
- BSIMM: Building Security in Maturity Model (BSIMM) Version 11
- BSA: The BSA Framework for Secure Software: A New Approach to Securing the Software Lifecycle, Version 1.1
- International Organization for Standardization/International Electrotechnical Commission (ISO/IEC): Information technology – Security techniques – Application security – Part 1: Overview and concepts, ISO/IEC 27034-1:2011
- Microsoft: Microsoft Security Development Lifecycle
- OWASP: Software Assurance Maturity Model Version 1.5
- Payment Card Industry (PCI) Security Standards Council: Secure Software Lifecycle (Secure SLC) Requirements and Assessment Procedures Version 1.1
- Software Assurance Forum for Excellence in Code (SAFECode): Fundamental Practices for Secure Software Development: Essential Elements of a Secure Development Lifecycle Program, Third Edition
- Institute for Defense Analyses (IDA): State-of-the-Art Resources (SOAR) for Software Vulnerability Detection, Test, and Evaluation
- Open Web Application Security Project (OWASP): OWASP Application Security Verification Standard 4.0.2
- SAFECode: Managing Security Risks Inherent in the Use of Third-Party Components
- SAFECode: Practical Security Stories and Security Tasks for Agile Development Environments
- SAFECode: Software Integrity Controls: An Assurance-Based Approach to Minimizing Risks in the Software Supply Chain
- SAFECode: Tactical Threat Modeling
*Non-NIST resources are provided for information. Inclusion does not mean that NIST endorses these resources.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics