GRC Blog
GRC Blog
- Details
- Written by: Robin Basham
- Category: GRC Blog
Remember the two years of waiting for NIST SP 800-53 Rev 4 to adopt Rev 5. For me, it's post-traumatic. Attempting everything I could to have the new data model ready we built an interim Four point Five, only to have NIST nearly scrap and begin again before releasing and adopting what we now use as Rev 5. Remember when AICPA released the SOC 2 2016 standard in 2017 and then quickly turned and released the SOC 2 2017? Did you suffer when CIS CSC 6.1 rolled to 7.1 and moved entire sections under new numbers? So how is that nineteenth nervous breakdown coming along? Did we mention that CMMC 2.0 completely scraped CMMC 1.0 and returned that cost of training to all those who certified to the first model?
It can feel thankless, but at some level, we still love to do it. We love managing and updating all the security standards b/c what they strive to accomplish actually matters.
So, Happy Two Thousand and Twenty Two. It's a new year and a big new ISO Standard.
We begin again.
(This article will post on January 28th, 2022)
- Hits: 942
- Details
- Written by: Robin Basham
- Category: GRC Blog
NIST 171 Compliance: The NIST Special Publication 171 series, (DFARS) 7012, and Cybersecurity Maturity Model Certification – Regulating Protected Controlled Unclassified Information
Suppose you are a nonfederal service provider whose offering might involve handling Controlled Unclassified Information (CUI). Up till now, it might not have been an issue. Still, suddenly either your Government Contract Management Officer or an upstream distributor for one of your products has informed you that your contracts and work orders won’t move forward till your offering is listed in the DoD Supplier Performance Review System as having passed NIST 171. Now what?
- Hits: 9611
- Details
- Written by: Robin Basham
- Category: GRC Blog
Delivering the final product of six months' work is the highlight of the last decade working in GRC.
Cloud Security Alliance Working Group CCM 4.1 to NIST SP 800-53 r5 Mapping Insights and Outcomes
Follow up to “Aligning the Cloud Controls Matrix CCM 4.1 to NIST SP 800-53 r5 – The Control Reference Layer” is the final product of the CCM Working group and reflects efforts with several major companies here in the East Bay.
All Cloud Security Alliance Common Controls Matrix CCM 4.2 resources are available at CSA (cloudsecurityalliance.org).
- Hits: 3241
- Details
- Written by: NIST
- Category: GRC Blog
These are the best NIST Resources resources to use for software security. (To launch in a new window, hold down the ctrl key.)
- Hits: 659
- Virtual Reality - It's not a game
- Another Great Example of a Web Cookie Tracking Policy
- Stand Your Conscience - The Ten-Year Anniversary of Trayvon Martin
- When Will It Stop
- Data in the Cloud - Explicit consent, right of portability, right to be forgotten
- Ten Rules of Data
- How health-care field can optimize mobile technology - Celebrating Success
- They Write a Way Better Privacy Policy than I do - Shall we all use Who Targets Me?
- Disinformation in Medicine and Voting - Speaking with Cybersecurity Sherri Douville CEO Medigram and Jennifer Cohn Election Integrity Advocate
- Mr. Christopher Bouzy Shares the Story of Bot Sentinel and the AI behind Detecting Hate Accounts

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics