GRC Blog
GRC Blog
- Details
- Written by: Robin Basham
- Category: GRC Blog
Questions from the NIST 800-53 r5 updates
Several Control Families are substantially enhanced in SP 800-53 r5. Two families that require particular note and planning are what used to be managed as PMO packages and Appendixes during the ATO FedRAMP process. These are Program Management (PM) and the PERSONALLY IDENTIFIABLE INFORMATION PROCESSING AND TRANSPARENCY Families.
The takeaway we'd like to reinforce is that the steps for preparing and "packaging" the overall programs within FedRAMP and other NIST-related compliance assessments are now prescriptive with distinct outcomes and assessment steps. What was once a set of prepared packages provided during the triennial assessment are now continuous and distributed controls within the catalog (800-53r5). Here's what NIST writes about the Program Management control domain.
- Hits: 1285
- Details
- Written by: Robin Basham
- Category: GRC Blog
The entirety of NIST SP 800-53, REV. 5 SECURITY AND PRIVACY CONTROLS FOR INFORMATION SYSTEMS AND ORGANIZATIONS include over one thousand controls and enhancements, more than 400 reference documents, and now an additional assessment methodology with an array of a few dozen assessment step attributes for every single requirement. It's easy to understand why organizations would want to leverage as many high-level processes or COMMON control processes as possible.
Consider that for every element in the control catalog spreadsheet, there are nearly infinite connections and context that influence how that control is selected and implemented. It might be one and done, and it might be a dreaded "per system" or even "per event" level control. Download from NIST - The Control Catalog - but this is not everything!
- Hits: 2909
- Details
- Written by: Robin Basham
- Category: GRC Blog
Challenge - Can you describe a fraud event that would not have been caught by any of these six controls?
- Hits: 635
- Details
- Written by: Robin Basham
- Category: GRC Blog
We Need a Green Plan, so why not a Green GRC Plan. See how NetApp did it and consider how you might exercise your own program. What Is Required Reduction In GHG?
Start locally. Publish your own office Green Plan. Consider publishing a family Green plan. Here's how we did ours.
The first view is for a program manager. The second view is for legal and research. The third plan is for home office and small business managers. Hope at least one of the three models provides you the support to kick off your journey.
- Hits: 2374
- ISO/IEC FDIS 27002 - ISO's big huge upgrade
- NIST 171 DFARS and CMMC
- CSA CCM 4.2 Mapping NIST 800-53 R5
- Approaches to Improve Software Security
- Virtual Reality - It's not a game
- Another Great Example of a Web Cookie Tracking Policy
- Stand Your Conscience - The Ten-Year Anniversary of Trayvon Martin
- When Will It Stop
- Data in the Cloud - Explicit consent, right of portability, right to be forgotten
- Ten Rules of Data

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics