Get it now, hot off the press, Assessing Security and Privacy Controls in Information Systems and Organizations
Are your security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome? Find out using the newly released control assessment methodology and assessment procedures in the National Institute of Standards and Technology (NIST) SP 800-53A Revision 5.
The assessment procedures are available in multiple data formats, including plain text, CSV, and OSCAL.
#cybersecurity #privacy #controls #assessment #RMF #riskmanagement #automation #OSCAL
This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk
management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results.


I'll be reporting on the journey of downloading and implementing the new OSCAL. We're moving far down the inheritance model and it will be interesting to see how Cloud Security providers bend or redesign their implementation of the improved methodology replacing the SP 800-53B.
Notice we have a big update in control identifier notation, swapping out leading zeros and potentially doing away with the parenthesis entirely. Unlike the NIST-800-171, where the entire of Chapter Three, the consistent location for all NIST standard and framework control sets, uses the notation 3.# as the Control, and all requirements are 3.#.#. In the 800-53 the Controls order alphanumerically and then the enhancements organize numerically. I'll try to dig into the OSCAL this coming weekend. It's all about the schema and keeping enormous control data sets distinct and complete.
This newly released assessment model is the same type used in the NIST 171 Assessment methodology which is currently used in scoring DFARS alignment via the SPRS. It's wonderful to have this same level of detail for the entirety of the Catalog.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics