Get it now, hot off the press, Assessing Security and Privacy Controls in Information Systems and Organizations

Are your security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome? Find out using the newly released control assessment methodology and assessment procedures in the National Institute of Standards and Technology (NIST) SP 800-53A Revision 5. 
The assessment procedures are available in multiple data formats, including plain text, CSV, and OSCAL.

#cybersecurity #privacy #controls #assessment #RMF #riskmanagement #automation #OSCAL

This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk 
management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization. Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results.

NIST 800-53A R5 Assessing Security and Privacy Controls in Information Systems and Organizations800-53A R5 Privacy Assessment

I'll be reporting on the journey of downloading and implementing the new OSCAL. We're moving far down the inheritance model and it will be interesting to see how Cloud Security providers bend or redesign their implementation of the improved methodology replacing the SP 800-53B.

Notice we have a big update in control identifier notation, swapping out leading zeros and potentially doing away with the parenthesis entirely. Unlike the NIST-800-171, where the entire of Chapter Three, the consistent location for all NIST standard and framework control sets, uses the notation 3.# as the Control, and all requirements are 3.#.#. In the 800-53 the Controls order alphanumerically and then the enhancements organize numerically. I'll try to dig into the OSCAL this coming weekend. It's all about the schema and keeping enormous control data sets distinct and complete.

This newly released assessment model is the same type used in the NIST 171 Assessment methodology which is currently used in scoring DFARS alignment via the SPRS. It's wonderful to have this same level of detail for the entirety of the Catalog.

NIST SP 800-53A R5 detailed assessment steps for each requirement

Main Menu