<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NIST SP-800 control listing in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18074#M821</link>
    <description>&lt;P&gt;I am not certain that I understand where you are having difficulty, however, based on your question, I believe the issue is that many people tend to look at SP 800-53 as a stand alone document as opposed to one of the component documents support the NIST Risk Management Framework (RMF). To get a better understanding of where 800-53 fits into the RMF I suggest reviewing SP 800-37 "Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The baseline is derived by completing the system categorization (FIPS 199 &amp;amp; NIST SP 800-60) to determine the sensitivity levels for a systems Confidentiality, Integrity,&amp;nbsp; and Availability (CIA). using the appendices of the 800-53 or the "Minimum Security" section on the 800-53 webpage: &lt;A href="https://nvd.nist.gov/800-53/Rev4" target="_blank"&gt;https://nvd.nist.gov/800-53/Rev4&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I am unaware of any books I would recommend to summarize these documents and supporting processes. IF you have the patience to read through them, the NIST documents do a good job, but tend to be very wordy and repetitive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this information is helpful, if not I will be happy to clarify anyplace I can where I misunderstand your concerns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jan 2019 19:04:22 GMT</pubDate>
    <dc:creator>StevenJ6052</dc:creator>
    <dc:date>2019-01-21T19:04:22Z</dc:date>
    <item>
      <title>NIST SP-800 control listing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18068#M820</link>
      <description>&lt;P&gt;Hello Everyone!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I found difficulty to understand how controls are laid out in NIST Special Publication 800-53. I mean, elements of a control listing (e.g. Priority , baseline allocation etc.)&amp;nbsp; Could someone suggest any relevant reference /book /document which explains the documentation for a rookie.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 12:21:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18068#M820</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-01-21T12:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: NIST SP-800 control listing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18074#M821</link>
      <description>&lt;P&gt;I am not certain that I understand where you are having difficulty, however, based on your question, I believe the issue is that many people tend to look at SP 800-53 as a stand alone document as opposed to one of the component documents support the NIST Risk Management Framework (RMF). To get a better understanding of where 800-53 fits into the RMF I suggest reviewing SP 800-37 "Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The baseline is derived by completing the system categorization (FIPS 199 &amp;amp; NIST SP 800-60) to determine the sensitivity levels for a systems Confidentiality, Integrity,&amp;nbsp; and Availability (CIA). using the appendices of the 800-53 or the "Minimum Security" section on the 800-53 webpage: &lt;A href="https://nvd.nist.gov/800-53/Rev4" target="_blank"&gt;https://nvd.nist.gov/800-53/Rev4&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, I am unaware of any books I would recommend to summarize these documents and supporting processes. IF you have the patience to read through them, the NIST documents do a good job, but tend to be very wordy and repetitive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this information is helpful, if not I will be happy to clarify anyplace I can where I misunderstand your concerns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 19:04:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18074#M821</guid>
      <dc:creator>StevenJ6052</dc:creator>
      <dc:date>2019-01-21T19:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: NIST SP-800 control listing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18089#M824</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It helps me for sure, the link provides good info.I Thank you for your time and info. Just in case please give me a clue to understand the&amp;nbsp;&lt;EM&gt; baseline allocation&amp;nbsp;&lt;/EM&gt; element purpose in the snap below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nist.jpg" style="width: 895px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2905i1D27C0DC244D38EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="nist.jpg" alt="nist.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 02:22:30 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18089#M824</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-01-22T02:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: NIST SP-800 control listing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18095#M826</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/637665353"&gt;@iluom&lt;/a&gt;,&amp;nbsp;the baseline implies the minimal recommended settings depending on the level you opt for. You use this as a starting point, and then tailor the control requirements depending on your situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's illustrate this with the &lt;STRONG&gt;A-2&lt;/STRONG&gt;&amp;nbsp;(Account Management) control, shown below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2907iA29D99BA149251CB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;For a Low level, it's the basic set of controls, but higher levels have enhanced controls. Nonetheless, no level has&amp;nbsp;&lt;FONT color="#0000FF"&gt;A6&lt;/FONT&gt;, &lt;FONT color="#0000FF"&gt;A7&lt;/FONT&gt;, &lt;FONT color="#0000FF"&gt;A8&lt;/FONT&gt;, &amp;amp; &lt;FONT color="#0000FF"&gt;A9&lt;/FONT&gt;, given that they may have dependencies, the costs of implementing them may outweigh the benefits, they may not be needed in an environment, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the example that you provided, there are no enhancements, so they've referenced just the main control for all the security levels, since there's nothing more.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For other controls, such as &lt;STRONG&gt;A-6&lt;/STRONG&gt; (Least Privilege), you'll notice that there's nothing provided for the Low level &amp;amp; both the other levels have all the enhanced controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whatever the case here, you start by selecting a particular control and the level you want, and then go on to add or remove controls to meet you own needs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 11:28:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18095#M826</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-01-22T11:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: NIST SP-800 control listing</title>
      <link>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18131#M827</link>
      <description>&lt;P&gt;Awesome!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 06:47:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/NIST-SP-800-control-listing/m-p/18131#M827</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2019-01-23T06:47:53Z</dc:date>
    </item>
  </channel>
</rss>

