Excuse me. Can you please shift to the left?

Compliance with NIST is complicated. Compliance requires strategy, training, project management, assessment events, and continuous program monitoring. Borrowing from the Software Industry’s “Shift Left”, compliance must occur prior to and as part of any development project. Compliance must exist in every CI/CD [xxvi] and refresh with each Authorization to Operate, or ATO [xxvii].

The way we deal with constantly evolving sets of regulatory requirements, therefore, is to “Shift Compliance Left”. Different from the initial Shift Left, a practice intended to find and prevent defects early in the software delivery process[xxviii], to Shift the responsibilities for Compliance Left requires a dynamic facility to select only the necessary regulatory and compliance outcomes. Using the actual SBOM, risks associated with the boundaries of a system would include an actual set of configurations and methodologies required by the system’s architecture. Driving off requirements adjusted to the SBOM, the system would generate tasks. With clear and properly scoped requirements, compliance would no longer be or would become less of a barrier to an Agile Software as a Service (SaaS) lifecycle.

To do this effectively, responsibility for implementing control tasks, for just-in-time compliance training, and for continuous monitoring or maintaining of evidence for corresponding controls would happen through a well-organized and OSCAL [xxix] facilitated system. Based on the risks unique to the subject or collective components, the mechanism would apply correct Open Vulnerability and Assessment Language OVAL [xxx] (or JOVAL) in accordance with the Security Content Automation Protocol Validation Program (SCAP)[xxxi] compliance checks. The system would rate, register, and assign a set of required remediations. Programs that are purpose-built to facilitate compliance would assign specific evidence-based tasks and responsibilities. The system would maintain a capability to coordinate the necessary Supply Chain and extend the most current regulatory considerations throughout the lifetime of that product or service. (Ideally.)

Governance Risk and Compliance (GRC) solutions generally meet the needs of most organization-based policy lifecycles. Where these programs routinely fail is in the engineering realm and the rapid continuous deployment of Cloud Products. GRC Systems are notoriously weak where weakness is most often introduced, namely through the Supply Chain and through associated technology-based components that shipped but never had their vulnerabilities addressed.

Consider the massive size and complexity of NIST content and the challenge of applying the correct standards, practices, and regulations by component, data type, and target. Where Shift Left had merely aimed to improve quality by moving associated software vulnerability tasks earlier in the process, what we need today combines Just-in-Time training across the entire Privacy Information Management Systems (PIMS)[xxxii] and captures evidence at every phase of the Product and Service. To Shift Compliance Left involves a means to both forecast what will be required and to capture evidence of applying the right industry guidance to every component as it is served.

Apply a Massive Number of controls in a Myriad of Contexts

We tackle complexity and context through industry verified and uniformly tagged evidence-based tasks that organically tie to each regulatory requirement. We use NIST SP 800-53 Controls as a mediating framework because SP 800-53 offers a risk-based context to tag and map to everything else.

Let’s begin to understand the components of NIST SP 800-53, visiting them in their home at NIST Risk Management Framework | CSRC. NIST (The Agency) maintains Federal Information Security Modernization Act (FISMA) information regarding E-Government Act (Public Law 107-347) and the Office of Management and Budget (OMB) Circular A-130“Managing Federal Information as a Strategic Resource.” 

When evaluating a product, we take initial steps to explore and available guidance for Security Configuration Settings. [xxxiii] “As part of a holistic risk management strategy and applying the information security concept of defense-in-depth, organizations should employ appropriate configuration settings on commercial information technology products. These products include, for example, mainframe computers, workstations, portable and mobile devices, and network components. Requirements to establish mandatory configuration settings derive from the Federal Information Security Management Act as implemented by FIPS 200 and NIST Special Publication 800-53 (Control CM-6, Configuration Settings), and OMB Policy.”

The following publicly available links provide critical information for organizations implementing authorized configuration settings for all scoped system components:

In addition to the control catalog, users should explore the Control Overlay Repository. The control overlays address unique risks and requirements of specialized industries and their systems. NIST Security and Privacy Control Overlay Repository (SCOR) provides stakeholders a “platform for voluntarily sharing control overlays created by subject matter experts to help reduce the duplication of effort and share best practices for the information security and privacy community.” Review the Government-wide Overlay Submissions and NIST-developed Overlay Submissions.

Finally, visit the section titled Downloads. NIST content exists in XML, PDF, CSV, MS Excel, XSLT, and OSCAL.

Main Menu