Further Understanding NIST SP 800-53 Rev. 5, Security and Privacy Controls for Federal Information Systems and Organizations; Using an RMF, Selecting from other catalogs. Presented by Robin Basham, CEO, EnterpriseGRC Solutions; To ISC2 Silicon Valley, on March 8th, 2022
As of Today, Binding Operational Directive 22-01 | CISA
<View static slides> Just Tell Me What To Do - Building Cloud for Federal - ISC2 SV March 8th 2022
Binding Operational Directive 22-01 | CISA
- Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive 22-01 - Reducing the Significant Risk of Known Exploited Vulnerabilities.
- A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems.
- Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives.
- Federal agencies are required to comply with DHS-developed directives.
- These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community.
- Known Exploited Vulnerabilities Catalog | CISA

Building Cloud Products for Federal Agencies – Using NIST to Shift Compliance Left
Vendors and Consultants working with Federal Agencies are required to establish secure products and services and to do so using a Cybersecurity Framework mapped to address common cybersecurity-related responsibilities.
Common sets of categorized outcomes are:
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Federal Information Systems and Organizations
- NIST Cybersecurity Framework (CSF) and NIST Privacy Framework (PF) as mapped to NIST Special Publication (SP) 800-53, Revision 5, NERC, ISSA, ISO
- Various cybersecurity frameworks, such as CIS-CSC 8.1, CCM v4.5 which are also mapped to the CSF/PF Core and to the SP 800-53 controls that support the achievement of the Subcategories
What it really takes to implement NIST

Here's a 2 CPE Discussion to inspire your ultimate fire breathing best self.

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics