Simplifying NIST 800-53 for people who have real work to do instead of arguing with assessors :-)
How many of you are truly, fully NIST 800-53 compliant?
NIST sp 800-53rev5 control questions
NIST SP 800 - 53 - PL 02 System Security Plan
Factsheet
EDIT- The goal is where to start a NIST 800-53 for Dummies Wiki that's crowd sourced
I always tend to think about how overcomplicated the vagueness of NIST 800-53 controls can be and cause unnecessary back and forth between system admins and assessors. I came across this thread for SC-39 ( "Evidence" for SC-39 (Process Isolation) on Windows 2019 : NISTControls (reddit.com) ) where recommendations were made for an example artifact for both Windows and Linux and the control was explained in a real world scenario.
My question is there anything within this channel or github/etc. that provides a dummy downed explanation of each control in actual real world terms and common sense. Think of the old Cliff Notes books that got straight to the point without all the fluff. The forum would also have folks collaborate with example commands/artifacts that are suggested or have been used in the past. Stuff like "Hey for VMWare you can run this command to show SI-16 Memory Protection" or "This is the actual difference between RA-5d and SI-2"
Another control that I struggle with is SI-7 and whenever I go to any of the popular vendors I never get a clear cut example of how to implement it using their product and even more of a challenge of how to prove it other than "I enabled this because it says it implements SI-7"
Example Red Hat ATO Pathways should have the info but it says "Not Available" Product Document (redhatgov.io)
If anyone agrees this provides value to the IT community any ideas of where to host something like this?
We run a reasonably secure shop. We've spent years refining and trying to make it better and more secure. A part of that has been starting on a journey to comply with the NIST security recommendations. And man, I've got to say it is HARD to not get overwhelmed with just how much more we have to do. I feel like I would need ten more employees to follow every single policy and recommendation, and that would just be to meet the minimum standards! I think we meet or exceed the important stuff, buy we are certainly not completely there.
How many of you admins out there can claim to be 100% fully compliant with the entire framework (at least all of the items that apply to you're organizations)?
Wondering if anyone has NIST sp 800-53rev5 controls with general/specific questions that need to be asked? For example, SA-1 - Type of question(s) that need to be asked to meet the control.