NIST SP 800-53 Compliance Lifecycle
The NIST SP 800-53 compliance lifecycle includes the following steps, all automatically enacted by the ProcessGene™ GRC Software Suite:
Lifecycle step |
NIST SP 800-53 activity |
|
NIST SP 800-53 context establishment |
- Definition of NIST SP 800-53 compliance related business processes
- Delineation of process diagrams (optional)
- Definition of assets within the NIST SP 800-53 scope
- Standardization and documentation of NIST SP 800-53 regulations, policies and procedures
|
|
Risk identification |
- Risk description, identification of risk stakeholders
- Risk classification and determination of heat-maps
- Risk assessment and measurement
- Determination of Key Risk Indicators (KRIs)
- Risk tolerance determination
|
|
Control determination |
- Definition of controls to mitigate identified NIST SP 800-53 risks
- Assignment of NIST SP 800-53 control owners
- Scheduling and monitoring NIST SP 800-53 control execution
- Assessment of residual risk levels
|
|
Requirement management |
- Requirement definition
- Automated requirement workflow management
- Requirement fulfillment monitoring
|
|
NIST SP 800-53 audit and remediation |
- Definition and scheduling of NIST SP 800-53 audit plans
- Definition of mechanisms for testing ongoing NIST SP 800-53 compliance
- Collection, analysis and storage of NIST SP 800-53 audit results
- Remediation plan definition, execution and follow-up
|
|
NIST SP 800-53 related incident management |
- Incident recording
- NIST SP 800-53 related incident handling (using scheduled workflows)
- NIST SP 800-53 related incident analysis and reporting
- Incident monitoring and follow-up
|
|
NIST SP 800-53 certification |
- Hierarchal NIST SP 800-53 certification process determination
- Establishment of an automated NIST SP 800-53 certification process
- Monitoring and reporting NIST SP 800-53 certification status
- Archiving NIST SP 800-53 certification history
|
|
Multi-Org management |
- Determination of a global NIST SP 800-53 compliance baseline with mandatory components
- Establishing a workflow for examining local (subsidiary) variants
- Enforcement of enterprise guidelines, regulations and frameworks within subsidiaries
- Control NIST SP 800-53 compliance level both locally (per subsidiary) and globally from a central HQ cockpit
|
|
|
|
The ProcessGene™ NIST SP 800-53 Software UsersThe ProcessGene™ NIST SP 800-53 compliance software provides value to the following users:
- C-level management (CEO, CFO, CIO, CRO, COO)
- Board of directors
- Compliance officers
- Internal auditors
- NIST SP 800-53 compliance managers
Continue to: Related Regulations >
|