Securing Property Management Systems: Draft SP 1800-27 is Available for Comment

NIST

View As Web Page

NIST CYBERSECURITY and PRIVACY PROGRAM

Securing Property Management Systems: Draft SP 1800-27 is Available for Comment

Hotels have become targets for malicious actors wishing to exfiltrate sensitive data, deliver malware, or profit from undetected fraud. Property management systems, which are central to hotel operations, present attractive attack surfaces.

NIST's National Cybersecurity Center of Excellence (NCCoE) collaborated with the hospitality business community and cybersecurity technology providers to build an example solution demonstrating how hospitality organizations can use a standards-based approach and commercially available technologies to meet their security needs for protecting a hotel's property management system. This example solution is described in Draft Special Publication (SP) 1800-27Securing Property Management Systems.

The principal capabilities found in the guide include protecting sensitive data, enforcing role-based access control, and monitoring for anomalies. Principal recommendations include implementing cybersecurity concepts such as zero trust, moving target defense, tokenization of credit card data, and role-based authentication. 

The comment period for this draft is open through October 28, 2020. See the publication details for a copy of the document and instructions for submitting comments.

 

Publication details:
https://csrc.nist.gov/publications/detail/sp/1800-27/draft

 

Project homepage:
https://www.nccoe.nist.gov/projects/use-cases/securing-property-management-systems