Compliance under Pressure
Interconnectedness gave rise to Ransomware attacks targeting the global Supply Chain and a substantial portion of US Critical Infrastructure. Newsworthy ransomware attacks include Kaseya, [xviii] Colonial Pipeline, [xix] beef supplier JBS, and Apple who all garnered attention for their huge payouts. The larger story however could have just as easily been smaller public and private entities reeling from Log4J exploits and no doubt not fully recovered from the monumental SolarWinds attack. [xx] While everyone agrees that we must Stop Hackers, most people lack the proficiency. Even if they do know what needs to happen, companies may choose to forgo the steps necessary to mitigate much of their cyber risk. Technical debt is real. Skilled professionals are expensive. Each day the rate, scale, and impact of data breaches combine with harvested social and stolen private information, enabling even greater catastrophic cyber events. Cyberattacks collectively set the stage for the May 12th, 2021, Executive Order on Improving the Nation's Cybersecurity. [xxi] Software as a Service or 'SaaS' vendors will face increasing difficulty selling cloud services to Federal and Government entities. [xxii]
The relationship between Executive Order 14028, the NIST SP 800-53, and the critical resources necessary to build secure cloud products is highlighted by a few facts.
- The United States Inspector General determines the overall metrics gathered and used to determine FISMA compliance.
- NIST, as the agency, provides through research a catalog of controls and an array of resources we, the public, use to meet those legal requirements.
- While conformity assessments such as FedRAMP and NIST 171 (a.k.a. CMMC 2.0 or SPRS) tailor controls and assign them to baselines, the IG and the President of the United States have now mandated that products as related to any particular Software Bill of Material (SBOM) and any component level vulnerabilities associated to the end-to-end delivery of that service, be remediated prior to and throughout the course of business with the Federal Government.
- Regardless of passing or not passing the audit, the Federal Acquisition Regulation and Defense Federal Acquisition Regulation Supplement (DFARS) will approve or deny contracts based on their determination of its risk or suitability to government purposes.
As of January 2022, there are four months left before mandatory EO 14028 takes effect. Companies can't afford to waste any more time. [xxiii]
The United States, Executive Order 14028, Improving the Nation's Cybersecurity, is an unforgiving directive for Suppliers and Consumers of Cloud-based products. DFARS will require more vendors to attest at higher rates than basic self-scored assessment. By May of 2022, any Vendor selling a technology product can expect Agencies to require evidence of a NIST 171 Assessment and a “Software Bill of Materials” or “SBOM”. The various components used in building software will require evidence to substantiate remediation for all found weaknesses in that product's POA&M. As stated in the EO, “It is analogous to a list of ingredients on food packaging. An SBOM is useful to those who develop or manufacture software, those who select or purchase software, and those who operate the software.” It is important to note that Evidence Collection[xxiv] is already required by law, and since the enactment of the ‘‘Foundations for Evidence-Based Policymaking Act of 2018’’ adherence to the Inspector General FISMA Reporting Measures v1.1 (cisa.gov) [xxv], is no longer a suggestion. When selecting the alignment of NIST SP 800-53 control language towards the validation of a product’s implemented policies, Vendors must prioritize Sec. 4. Enhancing Software Supply Chain Security, stating that “Such guidance shall include standards, procedures, or criteria regarding:
(i) secure software development environments, including such actions as:
(A) using administratively separate build environments.
(B) auditing trust relationships.
(C) establishing multi-factor, risk-based authentication, and conditional access across the enterprise.
(D) documenting and minimizing dependencies on enterprise products that are part of the environments used to develop, build, and edit software.
(E) employing encryption for data; and
(F) monitoring operations and alerts and responding to attempted and actual cyber incidents.
(ii) generating and, when requested by a purchaser, providing artifacts that demonstrate conformance to the processes set forth in subsection (e)(i) of this section.
(iii) employing automated tools, or comparable processes, to maintain trusted source code supply chains, thereby ensuring the integrity of the code.
(iv) employing automated tools, or comparable processes, that check for known and potential vulnerabilities and remediate them, which shall operate regularly, or at a minimum prior to product, version, or update release.
(v) providing, when requested by a purchaser, artifacts of the execution of the tools and processes described in subsection (e)(iii) and (iv) of this section and making publicly available summary information on completion of these actions, to include a summary description of the risks assessed and mitigated.
(vi) maintaining accurate and up-to-date data, provenance (i.e., origin) of software code or components, and controls on internal and third-party software components, tools, and services present in software development processes, and performing audits and enforcement of these controls on a recurring basis.
(vii) providing a purchaser, a Software Bill of Materials (SBOM) for each product directly or by publishing it on a public website.
(viii) participating in a vulnerability disclosure program that includes a reporting and disclosure process.
(ix) attesting to conformity with secure software development practices; and
(x) ensuring and attesting, to the extent practicable, to the integrity”
Companies using Cloud Security management software will have an easier time meeting these requirements. EnterpriseGRC Solutions offers that anyone looking to improve their Cloud Product Development health considers SD Elements, offered by Security Compass. Using this product alleviates the burden of proving the completeness and health of the SBOM and involves using NIST and other software frameworks to shift compliance requirements left so they are handled long before they become a barrier to your company earning business with the United States Government.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics