<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommendation for NIST auditor in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Recommendation-for-NIST-auditor/m-p/55108#M761</link>
    <description>&lt;P&gt;I trust you will post more like that later on. Appreciative for sharing such mind blowing information.&lt;/P&gt;</description>
    <pubDate>Sat, 12 Nov 2022 10:30:53 GMT</pubDate>
    <dc:creator>Kingsdajo</dc:creator>
    <dc:date>2022-11-12T10:30:53Z</dc:date>
    <item>
      <title>Recommendation for NIST auditor</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Recommendation-for-NIST-auditor/m-p/53302#M740</link>
      <description>&lt;P&gt;We have a software product that is subject to a 'hybrid' NIST audit, and the quotes we are getting do not seem to fit the scope of work. Our responsibility is only 63 controls, but (in some cases) the quotes we are getting would appear to include hundreds of hours. They are truly all over the place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking for a recommendation for a reasonable audit group that might give this better consideration. Perhaps, the groups we are contacting just have more work than they need...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:18:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Recommendation-for-NIST-auditor/m-p/53302#M740</guid>
      <dc:creator>Pedro</dc:creator>
      <dc:date>2023-10-09T10:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendation for NIST auditor</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Recommendation-for-NIST-auditor/m-p/53305#M741</link>
      <description>&lt;P&gt;Are we talking about NIST 800-53? Are there any requirements regarding the auditor from the customer?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Feel free to DM me. I can put you in touch with my US-based colleagues who regularly work on this type of projects.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2022 15:21:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Recommendation-for-NIST-auditor/m-p/53305#M741</guid>
      <dc:creator>wimremes</dc:creator>
      <dc:date>2022-09-13T15:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Recommendation for NIST auditor</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/Recommendation-for-NIST-auditor/m-p/55108#M761</link>
      <description>&lt;P&gt;I trust you will post more like that later on. Appreciative for sharing such mind blowing information.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Nov 2022 10:30:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/Recommendation-for-NIST-auditor/m-p/55108#M761</guid>
      <dc:creator>Kingsdajo</dc:creator>
      <dc:date>2022-11-12T10:30:53Z</dc:date>
    </item>
  </channel>
</rss>

