Federal Agencies Mandated to Protect Information with NIST SP 800-53 Controls
The Federal Information Security Modernization Act of 2014 (FISMA) requires all federal agencies and their contractors to safeguard federal information. This protection must adhere to the NIST SP 800-53 control catalog, which outlines security and privacy controls for information systems and organizations. Companies like XQ are providing solutions to enforce these controls at the data layer, specifically covering access control (AC), audit (AU), identification (IA), communications protection (SC), and integrity (SI) control families. While XQ enforces policies, the responsibility for defining these policies and procedures, such as AC-1, AU-1, and IA-1, remains with the individual agencies. Other controls, like logon-attempt limits (AC-7) and input validation (SI-10), are handled by identity providers and applications, respectively, simplifying control inheritance documentation in system security plans. XQ's approach has been validated for the Data pillar of AWS ZTAG-I, AWS’s reference zero trust architectu...