NIST Special Publication 800-223 is titled High-Performance Computing Security: Architecture, Threat Analysis, and Security Posture. It went out as a public draft on 6 February 2023 and was published as final on 9 February 2024.
It answers a question supercomputing had been answering site by site for decades: what, exactly, is the thing being secured? A cluster is a login plane, a management plane, compute nodes on a high-speed fabric, and parallel storage measured in petabytes, each with its own exposure and its own tolerance for the controls you would otherwise apply everywhere.
SP 800-223 supplies the picture. It divides an HPC system into four function zones, walks the components inside each one, works through the threats zone by zone, and closes on security posture recommendations. What it deliberately does not supply is a control list. Its introduction says so in plain words: the publication “is intended to be a conceptual guide, not a checklist of requirements.”
Who it binds is easy to get wrong in both directions. SP 800-223 was developed under NIST’s FISMA authority, which covers minimum requirements for federal information systems, and the same front matter states that it “may be used by nongovernmental organizations on a voluntary basis.” Federal statutory basis, explicit voluntary path for everyone else.
The author list says where it came from: NIST staff alongside contributors from Los Alamos, Sandia, Oak Ridge, MIT Lincoln Laboratory, the Laboratory for Physical Sciences, the DoD HPCMP, Amazon, and the universities of Alabama, Florida and South Carolina. People who operate these machines put their names on it.