Also, note the count of controls in the baselines, including the incremental jumps from LOW to MOD and MOD to HIGH. Note that these totals include controls and enhancements.
Practical governance. This blog is about understanding and addressing risk. Systems and architectures continue to rapidly converge, hiding complexity with additional layers of abstraction. Simplicity is great for operations - as long as risks are understood and appropriately mitigated.
Tuesday, March 16, 2021
Summary Statistics for NIST SP 800-53r5
Very interesting statistics, particularly around the related and cross-referenced controls. These counts are related to the Top Level controls. While certainly not an absolute flag, these counts are an interesting indicator of the importance of each of the controls.
Subscribe to:
Posts (Atom)