Skip to content
COOEY
REGULATORY LIBRARY
17 docs in this shelf

The load-bearing documents for a DIB program — CMMC / DFARS regulatory text (eCFR), federal rulemaking, NIST publications and OIRA review — organized as a library. Pick a document; the reader shows the dex dossier: what it says, why it matters, and the concrete obligations it imposes. Originals open at the source.

DIRECTORY_TREE
CMMC / DFARS · eCFR 98 Federal rulemaking 14 NIST publications 17
IR 8623, Cybersecurity Framework 2.0 Community Profile for Federal Agency Open Radio Access Network (O-RAN) DeploymentInitial Public Draft 2026-09-17 · publication SP 800-38E Rev. 1, Recommendation for Block Cipher Modes of Operation: XTS-AES Mode for Confidentiality on Storage DevicesInitial Public Draft 2026-09-03 · publication SP 800-213A Rev. 1, PRE-DRAFT Call for Comments: IoT Device Cybersecurity Requirement CatalogInitial Preliminary Draft 2026-08-26 · publication IR 8613, Multi-Cloud Architecture Challenges: Security and Compliance ImplicationsInitial Public Draft 2026-08-21 · publication SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and ReportingInitial Public Draft 2026-08-19 · publication CSWP 36F, Initial NAS Message Security: Applying 5G Cybersecurity and Privacy CapabilitiesInitial Public Draft 2026-08-06 · publication SP 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven ApproachInitial Public Draft 2026-07-27 · publication SP 800-209 Rev. 1, Security Guidelines for Storage InfrastructureInitial Public Draft 2026-07-22 · publication Project Description Asset Management as a Foundation for Operational Technology CybersecurityInitial Public Draft 2026-06-25 · publication SP 800-213 Rev. 1, IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity RequirementsInitial Public Draft 2026-06-24 · publication SP 800-219 Rev. 2, Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)Initial Public Draft 2026-06-22 · publication SP 800-73-6, Interfaces for Personal Identity Verification: Part 2 – PIV Card Application Card Command InterfaceInitial Working Draft 2026-06-12 · publication SP 800-73-6, Interfaces for Personal Identity Verification: Part 1 – PIV Card Application Namespace, Data Model and RepresentationInitial Working Draft 2026-06-12 · publication SP 800-78-6, Cryptographic Algorithms and Key Sizes for Personal Identity VerificationInitial Working Draft 2026-06-12 · publication SP 800-38D Rev. 1, Second Pre-Draft Call for Comments: GCM and GMAC Block Cipher Modes of Operation2nd Preliminary Draft 2026-06-01 · publication IR 8320E, Hardware-Enabled Security: Confidential Computing of Data in Cloud WorkloadsInitial Public Draft 2026-05-29 · publication SP 800-38F Rev. 1, PRE-DRAFT Call for Comments: Recommendation for Block Cipher Modes of Operation: Methods for Key WrappingInitial Preliminary Draft 2026-05-05 · publication
OIRA · OMB review 2
LAST_SYNC: 2026-09-21 02:00
DOC_VIEWER open original ↗
NIST publication 2026-09-03 ◆ DEX DOSSIER

SP 800-38E Rev. 1, Recommendation for Block Cipher Modes of Operation: XTS-AES Mode for Confidentiality on Storage DevicesInitial Public Draft

NIST updates SP 800-38E to approve XTS-AES (per IEEE Std. 1619-2025) for storage device confidentiality, clarifying scope, key limits, and ciphertext stealing ordering.

Revision 1 of Special Publication 800-38E approves the XTS-AES mode as specified in IEEE Std. 1619-2025 for protecting the confidentiality of data on block-oriented storage devices. This approval is subject to the applicability statements, conformance requirements, and clarifications in this recommendation. XTS-AES does not provide authentication of the data or its source.

--- [ Regulatory impact ] ---

DIBs must ensure their storage encryption implementations conform to the updated XTS-AES specifications and key-scope limits to maintain CMMC/NIST 800-171 compliance for data-at-rest protection.

Obligations it imposes · 3
  1. Conform to the applicability statements and conformance requirements for XTS-AES as specified in IEEE Std. 1619-2025.
  2. Adhere to the clarified data-unit and key-scope limits for XTS-AES.
  3. Implement the specified ordering convention for ciphertext stealing in XTS-AES.
OPEN_ORIGINAL ↗ PERMALINK ⎘ nist/6e2493d0-38a9-441c-8fa7-4369a95d590e◈ IRIX document body stays at the source — we index, enrich & link