-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
introductions to security compliance? #57
Comments
@afeld Did you ever get answers to your questions:
That said, this video pretty concise and easy to follow but
|
Everything from 5:00 (The "what" section) to 26:00 (The section where FedRAMP LI SaaS, now FedRAMP Tailored is mentioned) is good information for anyone who wants to know learn about compliance. Some of your questions have pretty long explanations, and with the NIST website down for the shutdown it's hard to cite all the exact laws. Q: What is stopping the AO to say yes to everything? Q: Does FedRAMP have government authority? The chain of command in a nutshell (without going back too far) goes something like:
And now we're here today (basically)! Sorry for the wall of text but I haven't actually ever had to type this out so it was kind of fun. In terms of talks, there really is next to no content out there... There's fedramp.gov/training ... |
@brasky That's helpful context. Coincidentally, Aidan's talk was posted 27 July 2016, and A-130 was updated the next day: https://www.federalregister.gov/documents/2016/07/28/2016-17872/revision-of-omb-circular-no-a-130-managing-information-as-a-strategic-resource. |
This reddit thread just popped up about how to better understand NIST and there was a good comment with a few videos about 800-171 that could be useful.
|
@Jkrzy might have ideas? |
Launched a new site for this - see #70. |
suggest closing this based on the new site existing |
@pburkholder posed a good question:
That video could use an update, but was (as it says) everything I knew at the time. In terms of documentation, I then put what I knew into Before You Ship.
Anyone else know of good introductory materials? Assuming an audience of tech but not government experience, I guess?
cc @brittag @wslack
The text was updated successfully, but these errors were encountered: