<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NIST CSF and SDLC in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/NIST-CSF-and-SDLC/m-p/49978#M633</link>
    <description>&lt;P&gt;Here's another framework if you didn't have enough already:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218.pdf" target="_blank"&gt;Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities (nist.gov)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Section: Protect Software (PS) (PS.1) (Example 3: Use commit signing for code repositories) (&lt;STRONG&gt;NISTCSF: PR.AC-4, PR.DS-6, PR.IP-3)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2022 16:59:30 GMT</pubDate>
    <dc:creator>tmekelburg1</dc:creator>
    <dc:date>2022-03-07T16:59:30Z</dc:date>
    <item>
      <title>NIST CSF and SDLC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/NIST-CSF-and-SDLC/m-p/49975#M632</link>
      <description>&lt;P&gt;&lt;SPAN&gt;So here is a security control framework question. I am going through an exercise of mapping our control set to various frameworks to track compliance, with NIST CSF as the "main" framework, linking others to it. The very first one in the list is enforcing signed commits to software repos. Trying to map that to the NIST CSF isn't working. It feels like the NIST CSF items are about Enterprise operations, not software development. Does anyone disagree, or should I add a section to my own derivative framework for Protect.SDLC?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 14:37:20 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/NIST-CSF-and-SDLC/m-p/49975#M632</guid>
      <dc:creator>mgorman</dc:creator>
      <dc:date>2022-03-07T14:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: NIST CSF and SDLC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/NIST-CSF-and-SDLC/m-p/49978#M633</link>
      <description>&lt;P&gt;Here's another framework if you didn't have enough already:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218.pdf" target="_blank"&gt;Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities (nist.gov)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Section: Protect Software (PS) (PS.1) (Example 3: Use commit signing for code repositories) (&lt;STRONG&gt;NISTCSF: PR.AC-4, PR.DS-6, PR.IP-3)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 16:59:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/NIST-CSF-and-SDLC/m-p/49978#M633</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2022-03-07T16:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: NIST CSF and SDLC</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/NIST-CSF-and-SDLC/m-p/50024#M635</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/604773865"&gt;@mgorman&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;SPAN&gt;So here is a security control framework question. I am going through an exercise of mapping our control set to various frameworks to track compliance, with NIST CSF as the "main" framework, linking others to it. The very first one in the list is enforcing signed commits to software repos. Trying to map that to the NIST CSF isn't working. It feels like the NIST CSF items are about Enterprise operations, not software development. Does anyone disagree, or should I add a section to my own derivative&lt;FONT color="#999999"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;A href="https://www.jcpenneykiosk.bid/" target="_blank" rel="noopener"&gt;&lt;FONT color="#999999"&gt;jcpassociates&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt; framework for Protect.SDLC?&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;A general SDLC&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;includes five phases: initiation, acquisition/development, implementation/assessment, operations/maintenance, and sunset (disposition)&lt;/STRONG&gt;. Each of the five phases includes a minimum set of security tasks needed to effectively incorporate security in the system development process.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 10 Mar 2022 05:10:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/NIST-CSF-and-SDLC/m-p/50024#M635</guid>
      <dc:creator>Montero6299</dc:creator>
      <dc:date>2022-03-10T05:10:00Z</dc:date>
    </item>
  </channel>
</rss>

