• EnterpriseGRC Home
  • Company
    • About Us
    • Partners and Projects
    • Jobs
  • Services
    • Enterprise Governance Risk & Compliance
      • LAYERING NETWORK SECURITY THROUGH SEGMENTATION
      • Cloud Security Technical Reference Architecture - CISA and USDS, Federal Risk Authorization Management Rev 2.0
    • Facilitated Compliance Management (TM)
    • Business Continuity
      • Business Continuity Management from standards to Cobit 5 - Michael Sim, O Leonard, C Mauny
    • Cybersecurity RoadMap
      • The Cybersecurity and Information Systems Information Analysis Center (CSIAC) DoD Policy Chart
      • The Road to Zero Trust - Abhishek Singh Araali Networks
    • Content Development & Research
      • Pitfalls in Mapping Cloud Controls Matrix V4 Presented to ISACA April 28 2021
      • This Associates to That - The Pitfalls in mapping CCM NIST 800-53r5 NIST 171 Assessment, ISO IEC 27001 plus Cloud, Processing, and Privacy
      • NIST SP-800-53 r5 – The Control Reference Layer CSA CCM v4 EO 14028 ISC2 SV 6-8-2021
      • CCM v4 as Master Control List - Mapping NIST FedRAMP & DFARS PCI SOC ISO ISACA SF August 25th 2021
      • CSA CCM Mapping WG NIST-800-53r5 Final Product Coming Soon at CSA
      • Unified Compliance Program - Presented to ISC2 East Bay
      • Just Tell Me What To Do - Building Cloud for Federal - ISC2 SV March 8th 2022
    • Information systems Audit & Assurance (Cloud & Cyber)
    • ISMS PIMS ISO/IEC Certification Programs
    • Privacy
      • Privacy Preserving Analytics and Secure Multiparty Computation - Ulf Mattson - Protegrity-The Webinar
      • Privacy - Preserving Analytics and Secure Multiparty Computation by Ulf Mattsson-The slides
    • Process Transformation
    • Training & Professional Development
  • Resources
    • Regulatory Compliance Standards and Frameworks
    • Fun Stuff - Puzzles Reinforcers Inspiration
      • Family Tree December 2022
    • Products & Service Providers
    • NIST SP 800 Publications (Takes you to NIST)
    • CSRC Glossary (Takes You to NIST)
    • NIST Privacy Framework (Takes You to NIST)
  • GRC Blog
    • Climate Science & Green Tech
    • Disinformation - Risk Management
      • Code of Ethics - Journalism Resources (Takes You to SOCIETY OF PROFESSIONAL JOURNALISTS)
      • How To Be an Ambassador of Trust - Sherri Douville Medigram
      • Who is Accountable Anyways? Presented by Sarah Clarke - InfoSpectives
    • Enterprise Architecture & Compliance News
      • CISA Alerts
      • Cybersecurity Insights
      • Privacy Newsfeed
      • National Cyber Awareness System (NCAS)
    • Bay Area News & Events
  • Privacy Policy
  • Contacts
EnterpriseGRC Solutions

Advanced Search

Login Form

For new registrations please allow 24 hours for administrator approval.

  • Forgot your password?
  • Forgot your username?
  • Create an account

Some Reading Ideas

  • Starting Over
  • Process Diagrams
  • Artificial Intelligence Machine Learning NLP and Ethics
  • Cloud Security with Reblaze followed by The Secure Enterprise Mandate with YouAttest at (ISC)2 East Bay 9-8-2022
  • Self-Protecting Data - Can Keyavi Change the Game? July 14 2022 ISC2 East Bay Member Event
  • Custom Content Development and Market Research
  • 7 Experts on Attaining ATO Faster in US Government Agencies
  • Zero Trust Architecture (Networking) - The search for truth and observability
  • EQUILIBRIUM CONFERENCE 2022
  • Helene Silver - The Artist
  • Tweets
  • The Road To Zero Trust
  • Justice Kentaji Brown Jackson
  • Cloudification and building to Zero Trust
  • Demystifying Zero Trust - Abhishek Singh, CEO, Araali Networks
  • Extract - The Security Hippie
  • Professional Organizations
  • Global Temperatures Spiral Out of Control in New Climate Change from NASA's Scientific Visualization Studio
  • How health-care field can optimize mobile technology - Celebrating Success
  • CSA CCM 4.2 Mapping NIST 800-53 R5
  1. You are here:  
  2. Home
  3. Services
  4. Enterprise Governance Risk & Compliance
  5. Cloud Security Technical Reference Architecture - CISA and USDS, Federal Risk Authorization Management Rev 2.0

Critical Reading - Cloud Security Technical Reference Architecture - CISA and USDS, Federal Risk Authorization Management

FIPS PUB 200 Minimum Security Requirements

FIPS PUB 200 Minimum Security Requirements - Visit FIPS 200, Minimum Security Requirements for Federal Info and Info Systems | CSRC (nist.gov)
  • Access Control (AC)
  • Awareness and Training (AT)
  • Audit and Accountability (AU)
  • Certification, Accreditation, and Security Assessments (CA)
  • Configuration Management (CM)
  • Contingency Planning (CP)
  • Identification and Authentication (IA)
  • Incident Response (IR)

Read FIPS PUB 200 Minimum Security Requirements

  • Maintenance (MA)
  • Media Protection (MP)
  • Physical and Environmental Protection (PE)
  • Planning (PL)
  • Personnel Security (PS)
  • Risk Assessment (RA)
  • System and Services Acquisition (SA)
  • System and Communications Protection (SC)
  • System and Information Integrity (SI)

NIST Reading

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics you need to know. (The Perils of Mount Must Read™ Confessions of a Cliff Note Junky) These resources go onto the "Mountain of Must Read". If you don't recognize the standard reference, you've missed critical understanding. As of 2022, this is the minimum NIST alphabet. All of these documents are found at https://csrc.nist.gov/publications/ Be very careful about static content. Look at links before you launch them. Never use alternate sites for the Computer Security Resource Center. Get the full list here <NIST Reading Extended>

FIPS Publication 140-2 Security Requirements for Cryptographic Modules [FIPS 140-2]
FIPS Publication 199 Standards for Security Categorization of Federal Information and Information Systems [FIPS 199]
FIPS Publication 200 Minimum Security Requirements for Federal Information and Information Systems [FIPS 200]
FIPS Publication 201-1 Personal Identity Verification (PIV) of Federal Employees and Contractors [FIPS 201-1]
NISTIR 8212 ISCMA: An Information Security Continuous Monitoring Program Assessment
NIST SP 800-18 Guide for Developing Security Plans for Federal Information Systems [SP 800-18]
NIST SP 800-30 Risk Management Guide for Information Technology Systems [NIST SP 800-30]
NIST SP 800-34 Contingency Planning Guide for Federal Information Systems [SP 800-34]

Copyright October 2011 - 2025 ©EnterpriseGRC Solutions, Inc. | Privacy Policy| Terms of Service | Contact | EnterpriseGRC Solutions on LinkedIn | Follow EnterpriseGRC on Bluesky