EnterpriseGRC Home
Starting Over
- Details
- Written by: Robin Basham
- Category: Company
Current toolbox
- Cloud Controls Matrixv4 as CCM WG leader for the mapping to NIST SP 800-53 and new ISO/IEC FDIS 27002
- 21 CFR Part 11
- 21 CFR Part 820
- HIPAA-HITECH CFR 45
- Eudralex V4 Annex 11
- GAMP® 5*
- HITRUST 9.3* (you must have a valid client license with HITRUST)
- ISO 13485:2016
- ISO/IEC 30111:2019
- ISO/IEC 27001:2013 €
- ISO/IEC 27017:2015 € 27002 for cloud services
- ISO/IEC 27799:2016 €
- ISO/IEC 27002:2013 € New ISO/IEC FDIS 27002 and mapping to CCM V4 and NIST 171 Assessment
- ISO/IEC 27018:2019 €
- ISO/IEC 27701:2019 €
- ISO/IEC TR 3445:2022 € Information technology — Cloud computing — Audit of cloud services
- NIST SP 800-171r2, NIST SP 800-171A, NIST SP 800-172, NIST.HB.162
- NIST SP 800-53 r5 / NIST SP 800-53B rev 5 / NIST SP 800-53A rev 5
- NIST SP 800-37 RMF v2
- NIST Cybersecurity Framework CSF- we have V1.1 mapped to SOC2, NIST 800-53, CIS-CSC 8.1, ISO/IEC 27001 and 27017, NIST 800-171&172 for CMMC 2.0
- GDPR
- CCPA 1798
- SOC 2 AICPA
- CIS Benchmarks - OSCAL & SCAP integration, mapping to custom cybersecurity products
- CIS CSC v7.1-> 8.1 - the top 18 - mapped to CCM v4.5
- PCI DSS V3.2.1
- COSO 2013 as mapped to IT and Cybersecurity standards and ISMS
- FFIEC (with insights from the CRI, Cyber Risk Institute)
- National Cyber Security Center NCSC UK Announces Major Updates to Cyber Essentials
- UK Cyber Essential in Brief
- Criminal Justice Information Services (CJIS) Security Policy
- Compliance Controls Catalogue (C5)
- Cloudification and building to Zero Trust
- More upon request.
- Hits: 1669
Cloudification and building to Zero Trust
- Details
- Written by: Robin Basham
- Parent Category: Services
- Category: Cybersecurity RoadMap
EnterpriseGRC Solutions has invested substantial time in readdressing our Cloud Security Assessment methodology. A lot of our resources were released as far back as 2011 to 2015, which means they are not sufficiently aligned with Zero Trust. Even the work contributed to mapping NIST SP 800-53 rev 5 and CMMC 2.0 during 2021 and 2022 lack specificity in ZTA. The CCM 4.5 clearly points to the use of ZTA, but we're leaning forward in the saddle to define new processes and procedures and then, in turn, to work with our community to suggest new control languages, and to encourage everyone to immediately implement the best and most critical new resources.
It's a journey, not a destination.
- Hits: 791
- Demystifying Zero Trust - Abhishek Singh, CEO, Araali Networks
- Not Smart Home
- CISA Compiles Free Cybersecurity Services and Tools for Network Defenders
- ERM, Cybersecurity and Incident Response
- Just Tell Me What to Do: Building Cloud Products consumed by Government Agencies, Current State
- Building Cloud Products for Federal Agencies
- NIST Cybersecurity Framework CSF
- Tonight We Write and other routine inspirations from Dr. Carlotta Berry
- Self-Protecting Data - Can Keyavi Change the Game? July 14 2022 ISC2 East Bay Member Event
- Zero Trust Architecture (Networking) - The search for truth and observability
- Did you hear what happened to Appendix J?
- Common - Hybrid - or System Specific
- NIST 171 DFARS and CMMC
- Stand Your Conscience - The Ten-Year Anniversary of Trayvon Martin
- Mr. Christopher Bouzy Shares the Story of Bot Sentinel and the AI behind Detecting Hate Accounts
- NIST SP 800-53A R5 is here
- FedRAMP releases draft Revision 5 Baselines for public comment
Page 1 of 10
