{
  "node_id": "assessing-security-privacy-controls",
  "title": "Assessing Security and Privacy Controls in Information Systems and Organizations",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2022-01-01",
  "bluf": "This publication provides a methodology and a set of procedures for conducting assessments of security and privacy controls employed within systems and organizations as part of an effective risk management framework. The assessment procedures are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. Security and privacy control assessments are the principal vehicle used to verify that selected controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting security and privacy requirements. The procedures are customizable and can be tailored to provide organizations with the flexibility to conduct assessments that support their risk management processes and align with their stated risk tolerance. Control assessment results provide organizational officials with evidence of control effectiveness, an indication of the quality of risk management processes, and information about the security and privacy strengths and weaknesses of systems. These findings are used to determine the overall effectiveness of controls and to provide credible inputs to the organization’s risk management process, facilitating a cost-effective approach to managing risk by identifying weaknesses and enabling appropriate risk responses.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "nist-sp-800-53b-control-baselines",
    "nist-sp-800-30-risk-assessment"
  ],
  "primary_citations_count": 7
}