EnterpriseGRC Home
Did you hear what happened to Appendix J?
- Details
- Written by: Robin Basham
- Category: GRC Blog
Questions from the NIST 800-53 r5 updates
Several Control Families are substantially enhanced in SP 800-53 r5. Two families that require particular note and planning are what used to be managed as PMO packages and Appendixes during the ATO FedRAMP process. These are Program Management (PM) and the PERSONALLY IDENTIFIABLE INFORMATION PROCESSING AND TRANSPARENCY Families.
The takeaway we'd like to reinforce is that the steps for preparing and "packaging" the overall programs within FedRAMP and other NIST-related compliance assessments are now prescriptive with distinct outcomes and assessment steps. What was once a set of prepared packages provided during the triennial assessment are now continuous and distributed controls within the catalog (800-53r5). Here's what NIST writes about the Program Management control domain.
- Hits: 1294
Common - Hybrid - or System Specific
- Details
- Written by: Robin Basham
- Category: GRC Blog
The entirety of NIST SP 800-53, REV. 5 SECURITY AND PRIVACY CONTROLS FOR INFORMATION SYSTEMS AND ORGANIZATIONS include over one thousand controls and enhancements, more than 400 reference documents, and now an additional assessment methodology with an array of a few dozen assessment step attributes for every single requirement. It's easy to understand why organizations would want to leverage as many high-level processes or COMMON control processes as possible.
Consider that for every element in the control catalog spreadsheet, there are nearly infinite connections and context that influence how that control is selected and implemented. It might be one and done, and it might be a dreaded "per system" or even "per event" level control. Download from NIST - The Control Catalog - but this is not everything!
- Hits: 2913
Page 7 of 10