NIST RFID Security Guidelines and Recommendations
NIST provides guidelines for security of RFID technology. ... A sample of their recommendations are organized by phase of RFID implementation - initiation (prior to design), acquisition and development, implementation, operations and maintenance, and, finally, disposition. In the initiation phase, NIST recommends performing risk assessment to understand threats posed by RFID to the organizations assets. A usage policy should be created that defines assets that should be tagged with RFID and who has the authority to determine what assets get tagged. A transparent privacy policy for RFID should be establised. The organization's information security policy should be updated with regard to the introduction of RFID technology. A training program should be established for the users of the RFID solution that emphasizes security and privacy. Document the RFID standards that you comply with. Disable or destroy RFID tags upon disosal. Other recommendations are in the reference report (PDF). ...

... "RFID devices send and/or receive radio signals to transmit identifying information such as product model or serial numbers. They come in a wide variety of types and sizes, from the size of a grain of rice or printed on paper to much larger devices with built in batteries. Unlike bar coding systems, RFID devices can communicate without requiring a line of sight and over longer distances for faster batch processing of inventory and can be outfitted with sensors to collect data on temperature changes, sudden shocks, humidity or other factors affecting products. As RFID devices are deployed in more sophisticated applications from matching hospital patients with laboratory test results to tracking systems for dangerous materials, concerns have been raised about protecting such systems against eavesdropping and unauthorized uses. " ...
NIST Issues Guidelines for Ensuring RFID Security
Labels: assessment, devices, guidelines, national-institute-standards-technology, nist, phased-implementation, radio-tags, recommendations, rfid, security, solution, understanding