Source: https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A6714729572786585600
National Institute of Standards and Technology (NIST) #Security and #Privacy #Controls for #Information #Systems and #Organizations: SP 800-53, Revision 5: https://lnkd.in/eEgecGw :
PDF: https://lnkd.in/eNadncU :
“…The Task Force notes that the #cyber #threat to U.S. #critical #infrastructure is outpacing efforts to reduce pervasive #vulnerabilities, so that for the next decade at least the United States must lean significantly on #deterrence to address the cyber threat posed by the most capable U.S. #adversaries. It is clear that a more proactive and systematic approach to U.S. #cyber #deterrence is urgently needed…”
The Next Generation Security and Privacy Controls—Protecting the Nation’s Critical Assets
https://lnkd.in/e3QnK3i
The most significant changes to SP 800-53, Revision 5 include:
• Making controls outcome-based
• Consolidating the control catalog
• Integrating supply chain risk management
• Separating the control selection process from the controls
• Transferring control baselines and tailoring guidance to a separate publication:
NIST SP 800-53B, Control Baselines for Information Systems and Organizations: https://lnkd.in/eFMH6sf
• Improving descriptions of content relationships
• Adding new state-of-the-practice controls