References


[i] Approaches for Federal Agencies to Use the Cybersecurity Framework (nist.gov), page 11
[ii] Cybersecurity Enhancement Act of 2014 signed into law (Public Law No: 113-274) provides for an ongoing, voluntary public-private partnership to improve cybersecurity, and to strengthen cybersecurity research and development, workforce development, and education, and public awareness and preparedness.
[iii] NIST Risk Management Framework | CSRC
[iv] Subpart 39.1 – General FAR (acquisition.gov)
[v] Cybersecurity Framework | NIST
[vi] National Institute of Standards and Technology (2006) Minimum Security Requirements for Federal Information and Information Systems. (U.S. Department of Commerce, Washington, DC), Federal Information Processing Standards Publication (FIPS) 200. https://doi.org/10.6028/NIST.FIPS.200
[vii] SP 800-53B, Control Baselines for Information Systems and Organizations | CSRC (nist.gov)
[viii] Approaches for Federal Agencies to Use the Cybersecurity Framework (nist.gov), page 16
[ix] List of federal agencies in the United States - Wikipedia
[x] Conformity Assessment Resources for Federal Agencies | NIST
[xi] Get Authorized: JAB Authorization | FedRAMP.gov
[xii] CFR-2017-title32-vol6-part2002.pdf (govinfo.gov)
[xiii] SP 800-53 Rev. 5, Security and Privacy Controls for Info Systems and Organizations | CSRC (nist.gov)
[xiv] CSP Authorization Playbook (fedramp.gov)
[xv] Defense Federal Acquisition Regulation Supplement Microsoft Word - 252204.doc (osd.mil), Rev. Jan. 15, 2009)
[xvi] Compliance with Cybersecurity and Privacy Laws and Regulations | NIST
[xvii] Supply Chain Risk Management Practices for Federal Information Systems and Organizations | NIST
[xviii] Kaseya Ransomware Attack: Guidance for Affected MSPs and their Customers | CISA
[xix] Colonial Pipeline: The DarkSide Strikes (congress.gov)
[xx] US Treasury "Significantly Affected" By SolarWinds Cyberattack - Reactionary Times
[xxi] Executive Order on Improving the Nation's Cybersecurity | The White House
[xxii] NIST SP 800-145, The NIST Definition of Cloud Computing, Software as a Service (SaaS), page two
[xxiii] Approaches for Federal Agencies to Use the Cybersecurity Framework | NIST
[xxiv] PUBL435.PS (congress.gov) ‘‘Foundations for Evidence-Based Policymaking Act of 2018’’
[xxv] FY 2021 Inspector General FISMA Reporting Measures v1.1 (cisa.gov)
[xxvi] CI/CD - Wikipedia In software engineering, CI/CD is the combined practices of continuous integration (CI) and either continuous delivery or continuous deployment (CD)
[xxvii] An Authorization to Operate (ATO) is a formal declaration by a Designated Approving Authority (DAA) that authorizes operation of a Business Product and explicitly accepts the risk to agency operations.
[xxviii] Donald Firesmith (23 March 2015). "Four Types of Shift Left Testing". Archived from the original on 2015-09-05. Retrieved 27 March 2015. (As found on https://en.wikipedia.org/wiki/Shift-left_testing)
[xxix] oscal-content/nist.gov/SP800-53/rev5 at master · usnistgov/oscal-content · GitHub
[xxx] Home / Oval Repository (cisecurity.org)
[xxxi] Security Content Automation Protocol Validation Program | CSRC (nist.gov)
[xxxii] ISO - ISO/IEC 27701:2019 - Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines
[xxxiii] NIST Risk Management Framework | CSRC Security Configuration Settings Security Content Automation Protocol | CSRC (nist.gov) and United States Government Configuration Baseline | CSRC (nist.gov)
[xxxiv] OWASP Foundation | Open Source Foundation for Application Security
[xxxv] CIS Benchmarks (cisecurity.org)
[xxxvi] MITRE ATT&CK®
[xxxvii] An Introduction to Information Security (nist.gov)
[xxxviii] Executive Order on Improving the Nation's Cybersecurity | The White House
[xxxix] FY 2021 Inspector General FISMA Reporting Measures v1.1 (cisa.gov)
[xl] Approaches for Federal Agencies to Use the Cybersecurity Framework (nist.gov), page 11
[xli] Cybersecurity Supply Chain Risk Management | CSRC (nist.gov)

Main Menu