Ron Ross
Ron Ross is an American computer scientist and cybersecurity specialist who played a central role in the development of federal cybersecurity standards at the National Institute of Standards and Technology (NIST). A retired United States Army lieutenant colonel, Ross was a principal author of numerous NIST Special Publications, including SP 800-53 and SP 800-37, which address information security and risk management frameworks. [1] [2]
Ron Ross | |
---|---|
![]() Dr. Ron Ross | |
Born | United States |
Allegiance | United States |
Service | United States Army |
Years of service | 20 years |
Rank | Lieutenant Colonel (Retired) |
Alma mater | United States Military Academy (B.S.) Naval Postgraduate School (M.S., Ph.D.) Defense Systems Management College |
Other work | Fellow and retired senior computer scientist at the National Institute of Standards and Technology (NIST) |
Early life and education
[edit]Ross graduated from the United States Military Academy at West Point and earned a master’s and doctorate in computer science from the Naval Postgraduate School, with a focus on artificial intelligence and robotics. He also completed studies at the Defense Systems Management College. [2][1]
Military service
[edit]Ross served 20 years in the United States Army, where he was commissioned as a Second Lieutenant and served as a Mechanized Infantry and Army Acquisition Corps officer. He completed Airborne training and held technical and leadership roles in secure computing, information assurance, and risk management, retiring with the rank of lieutenant colonel.[3]
Civilian career
[edit]After retiring from the military, Ross began his civilian service at the Institute for Defense Analyses before joining the National Institute of Standards and Technology (NIST) as a senior computer scientist. He was named a NIST Fellow, the agency’s highest honorary recognition, for his pioneering leadership in cybersecurity and systems security engineering.[2]
Ross was a principal architect of key cybersecurity standards and frameworks used across the federal government and private sector. He served as lead author on foundational NIST publications, including:
- FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems (Feb 2004)
- FIPS 200 – Minimum Security Requirements for Federal Information and Information Systems (Mar 2006)
- NIST SP 800-30 – Guide for Conducting Risk Assessments (Sep 2012)
- NIST SP 800-37 – Risk Management Framework for Information Systems and Organizations (Dec 2018)
- NIST SP 800-39 – Managing Information Security Risk (Mar 2011)
- NIST SP 800-53 – Security and Privacy Controls for Information Systems and Organizations (Dec 2020)
- NIST SP 800-53A – Assessing Security and Privacy Controls in Information Systems and Organizations (Jan 2022)
- NIST SP 800-53B – Control Baselines for Information Systems and Organizations (Dec 2020)
- NIST SP 800-128 – Guide for Security-Focused Configuration Management of Information Systems (Oct 2019)
- NIST SP 800-160 Vol. 1 – Engineering Trustworthy Secure Systems (Nov 2022)
- NIST SP 800-160 Vol. 2 – Developing Cyber Resilient Systems (Dec 2021)
- NIST SP 800-171 – Protecting Controlled Unclassified Information (May 2024)
- NIST SP 800-171A – Assessing Security Requirements for CUI (May 2024)
- NIST SP 800-172 – Enhanced Security Requirements for CUI (Feb 2021)
- NIST SP 800-172A – Assessing Enhanced Security Requirements for CUI (Mar 2022)
Ross was a founding member of the Joint Task Force Transformation Initiative, a collaboration among NIST, the Department of Defense, the Office of the Director of National Intelligence, and the Committee on National Security Systems to unify federal cybersecurity frameworks. He also directed the National Information Assurance Partnership (NIAP), a joint NIST and National Security Agency program focused on systems evaluation.
Ross received the Defense Superior Service Medal (awarded in a civilian capacity) for his contributions to national cybersecurity.[1]
In 2025, Ross was appointed a Fellow at Dartmouth College’s Institute for Security, Technology, and Society (ISTS), where he contributes to research and curriculum development in cybersecurity and systems engineering.[4]
Congressional testimony and media
[edit]Ross has testified before Congress on several occasions regarding cybersecurity risk frameworks, supply chain security, and federal preparedness following major breaches, including the SolarWinds incident.[5]
He has also appeared in national media discussing cybersecurity threats and federal response strategies. His insights have been featured in:
Media outlet | Context | Citation |
---|---|---|
The Washington Post | Helping federal agencies thwart cyberattacks | [6] |
Federal News Network | Insights on SolarWinds breach and federal response | [7] |
Business Wire | Discussing NIST 800-171 Revision 3 at CMMC CON 2023 | [8] |
GovInfoSecurity | Interview on NIST's revolutionary guidance and risk management framework | [9] |
Healthcare IT News | Revealing how leadership, governance, and accountability can solve 90% of cyberbreaches | [10] |
InfoRiskToday | Protecting critical infrastructure through secure system design and NIST initiatives | [11] |
ActiveCyber.net | Discussing the NIST Risk Management Framework and active cyber defense strategies | [12] |
CyberSheath | Explaining NIST 800-171's history and future at CMMC CON 2023 | [13] |
BankInfoSecurity | Emphasizing the need for improved systems security engineering post‑SolarWinds breach | [14] |
Forbes | In‑depth conversation on cybersecurity leadership and NIST's role in federal security standards | [15] |
Selected publications
[edit]- Ross, Ron, et al. Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication 800-53 Revision 5, September 2020. DOI: 10.6028/NIST.SP.800-53r5
- Ross, Ron Planning Minimum-Energy Paths in an Off-Road Environment with Anisotropic Traversal Costs and Motion Constraints. Ph.D. dissertation, Naval Postgraduate School, June 1989. PDF (DTIC)
Presentations
[edit]Title | Description | Citation |
---|---|---|
Engineering Trustworthy Secure Systems | Describes an experiment applying security design principles to a NASA satellite system. | By Ron Ross and Dr. Kymie Tan, "Engineering Trustworthy Secure Systems" (September 2024), [1]. |
Next Generation Mission-Based Security for Systems Engineers | Explains how to protect cyber-physical systems from adversarial and non-adversarial threats. | By Ron Ross, "Next Generation Mission-Based Security for Systems Engineers" (September 2024), [2]. |
Transitioning to Engineering-Based Cybersecurity | Outlines why current cybersecurity approaches are insufficient for modern threats. | By Ron Ross, "Transitioning to Engineering-Based Cybersecurity" (2022), [3]. |
Lectures and academic engagements
[edit]Dr. Ron Ross has delivered invited lectures and participated in academic events at numerous universities and colleges across the United States. His speaking engagements have included prestigious institutions such as:
- Stanford University[1]
- MIT[1]
- Dartmouth College[1]
- Naval Postgraduate School[1]
- George Washington University[1]
In these settings, Dr. Ross has shared insights on topics including cybersecurity risk management, federal information security policy, systems engineering, and emerging threats in national defense and critical infrastructure protection. His lectures frequently draw upon his leadership at the National Institute of Standards and Technology (NIST), where he helped develop the Risk Management Framework (RMF) and the NIST Cybersecurity Framework.
Civilian awards and honors
[edit]- National Cyber Security Hall of Fame, Class of 2015[16]
- Federal 100 Award (multiple years)[17][18]
- Department of Commerce Gold Medal for Distinguished Achievement[19]
- National Security Agency Scientific Achievement Award[1]
- Presidential Rank Award for public service[1]
- Information Systems Security Association Hall of Fame Inductee and Distinguished Service Award recipient[1]
- (ISC)² Lynn F. McNulty Tribute Award (2013, inaugural recipient)[20]
- 2021 Retired Gen. Michael V. Hayden Lifetime Leadership Award[21]
- 1105 Media Gov30 Award[2]
- ISACA Joseph J. Wasserman Award[3]
- 2015 Homeland Security and Law Enforcement Medal[22]
- 2019 Pioneer Award, Institute for Critical Infrastructure Technology (ICIT), for contributions to cybersecurity and public sector innovation[23]
Service and recognition
[edit] Lt. Col., U.S. Army (Ret.)
Awards and decorations
[edit]Award | |
---|---|
![]() |
Defense Superior Service Medal (awarded in civilian capacity) |
![]() |
Meritorious Service Medal |
Badges
[edit]Retirement and legacy
[edit]Ross formally retired from full-time government service in 2025. During his tenure, he contributed to the development of foundational cybersecurity frameworks, including the Risk Management Framework (RMF), and authored key NIST Special Publications such as SP 800-37, SP 800-53, and SP 800-160. These resources continue to guide cybersecurity practices across federal agencies and the private sector. [24]
Following his retirement, Ross founded his own cybersecurity consulting firm, RONROSSECURE, LLC, which offers advisory services on secure system development, cyber resiliency, and risk management strategies. [25]
See also
[edit]- National Institute of Standards and Technology
- NIST Special Publication 800-53
- NIST Special Publication 800-171
- Federal Information Security Modernization Act of 2014
- Risk Management Framework
- Cybersecurity and Infrastructure Security Agency
- Information assurance
- United States Army
External links
[edit]References
[edit]- ^ a b c d e f g h i j k "Dr. Ronald S. Ross". EU Cyber Act. European Cybersecurity Organization. Archived from the original on June 1, 2024. Retrieved June 7, 2025.
- ^ a b c d "Ron Ross Biography" (PDF). National Institute of Standards and Technology. Archived (PDF) from the original on June 1, 2024. Retrieved June 9, 2025.
- ^ a b "Advisory Board – Billington CyberSecurity". Billington CyberSecurity. Archived from the original on June 1, 2024. Retrieved June 2, 2025.
- ^ "Joining Dartmouth as a Fellow in ISTS – Dr. Ron Ross". LinkedIn. Archived from the original on June 1, 2024. Retrieved June 9, 2025.
- ^ "Federal Cybersecurity Post-SolarWinds". House Committee on Science, Space, and Technology. March 2021.
- ^ "Ron Ross: Helping federal agencies thwart cyberattacks". The Washington Post. December 22, 2015. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "One of government's leading cybersecurity experts weighs in on SolarWinds breach". Federal News Network. December 17, 2020. Archived from the original on March 1, 2024. Retrieved June 2, 2025.
- ^ "NIST 800-171 Co-Author Dr. Ron Ross to Discuss New Revision at CMMC CON 2023" (Press release). Business Wire. August 15, 2023. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "Infosec Guru Ron Ross on NIST's Revolutionary Guidance". GovInfoSecurity. March 5, 2010. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "NIST fellow Ron Ross reveals how to solve 90 percent of cyberbreaches". Healthcare IT News. May 11, 2016. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "Ron Ross of NIST on Protecting Critical Infrastructure". InfoRiskToday. December 27, 2018. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "Interview with NIST's Ron Ross". ActiveCyber.net. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "Dr. Ron Ross to Explain NIST 800-171's History and Future". CyberSheath. August 11, 2023. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "NIST's Ron Ross: 'The Adversary Lives in the Cracks'". BankInfoSecurity. December 23, 2020. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "A Conversation With The Most Influential Cybersecurity Guru To The U.S. Government". Forbes. December 7, 2015. Archived from the original on February 1, 2024. Retrieved June 2, 2025.
- ^ "Ron Ross – Biography" (PDF). Government Executive. Archived (PDF) from the original on January 1, 2025. Retrieved June 15, 2025.
- ^ "Ron Ross Receives Federal 100 Award". NIST. February 4, 2019. Retrieved June 2, 2025.
- ^ "The 2019 Federal 100". FCW. March 2019. Retrieved June 2, 2025.
- ^ "Commerce Gold and Silver Medals". NIST. December 2010. Retrieved June 2, 2025.
- ^ "NIST Fellow Ron Ross Honored with Inaugural McNulty Information Security Award". NIST. November 21, 2013. Retrieved June 2, 2025.
- ^ "Ron Ross to Receive 2021 Hayden Lifetime Leadership Award". NIST. October 6, 2021. Retrieved June 2, 2025.
- ^ "Ron Ross". Service to America Medals. Partnership for Public Service. Retrieved June 5, 2025.
- ^ "ICIT Honors Dr. Ron Ross (NIST) and Suzette Kent (OMB) at 2019 ICIT Gala & Benefit". GlobeNewswire. Institute for Critical Infrastructure Technology. November 27, 2019. Retrieved June 7, 2025.
- ^ "Tech Stalwart Ron Ross Leaving NIST". Meritalk. February 20, 2025. Archived from the original on June 1, 2024. Retrieved June 3, 2025.
- ^ "Ron Ross Secure". Ron Ross Secure. Archived from the original on June 1, 2024. Retrieved June 9, 2025.