Further Understanding NIST SP 800-53 Rev. 5, Security and Privacy Controls for Federal Information Systems and Organizations; Using an RMF, Selecting from other catalogs. Presented by Robin Basham, CEO, EnterpriseGRC Solutions; To ISC2 Silicon Valley, on March 8th, 2022

As of Today, Binding Operational Directive 22-01 | CISA

<View static slides> Just Tell Me What To Do - Building Cloud for Federal - ISC2 SV March 8th 2022

Binding Operational Directive 22-01 | CISA

  • Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive 22-01 - Reducing the Significant Risk of Known Exploited Vulnerabilities.
  • A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems.
  • Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives.
  • Federal agencies are required to comply with DHS-developed directives.
  • These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community.
  • Known Exploited Vulnerabilities Catalog | CISA

Clean Up Your Vulnerabilities

Building Cloud Products for Federal Agencies – Using NIST to Shift Compliance Left

Vendors and Consultants working with Federal Agencies are required to establish secure products and services and to do so using a Cybersecurity Framework mapped to address common cybersecurity-related responsibilities.

Common sets of categorized outcomes are:

  • NIST SP 800-53 Rev. 5, Security and Privacy Controls for Federal Information Systems and Organizations
  • NIST Cybersecurity Framework (CSF) and NIST Privacy Framework (PF) as mapped to NIST Special Publication (SP) 800-53, Revision 5, NERC, ISSA, ISO
  • Various cybersecurity frameworks, such as CIS-CSC 8.1, CCM v4.5 which are also mapped to the CSF/PF Core and to the SP 800-53 controls that support the achievement of the Subcategories

What it really takes to implement NIST

Be a Dragon

Here's a 2 CPE Discussion to inspire your ultimate fire breathing best self.

Main Menu