Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Guide to Selecting Information Technology Security Products



Timothy Grance, Marc Stevens, Marissa Myers


The selection of IT security products is an integral part of the design, development and maintenance of an IT security infrastructure that ensures confidentiality, integrity, and availability of mission critical information. The guide seeks to assist in choosing IT security products that meet an organization's requirements. It should be used with other NIST publications to develop a comprehensive approach to meeting an organization's computer security and information assurance requirements. This guide defines broad security product categories, specifies product types within those categories, and then provides a list of characteristics and pertinent questions an organization should ask when selecting a product from within these categories.
Special Publication (NIST SP) - 800-36
Report Number


computer security, enterprise architecture, life cycle, products, security controls


Grance, T. , Stevens, M. and Myers, M. (2003), Guide to Selecting Information Technology Security Products, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed April 13, 2024)
Created October 9, 2003, Updated February 19, 2017