{
  "node_id": "nist-cswp-30-automation-support",
  "title": "Automation Support for Control Assessments: Project Update and Vision",
  "domain": "AI Governance & Law",
  "version": "1.0.0",
  "last_updated": "2023-12-06",
  "bluf": "NIST Interagency Report (IR) 8011 is a multi-volume series that provides a blueprint for supporting automated control assessments. It proposes an approach for creating specific tests, denominated as 'defect checks,' that can be executed using automation to verify that controls are in place and operating as expected. The methodology supports the NIST Risk Management Framework (RMF) and expands on guidance from SP 800-53A for assessing SP 800-53 controls, ultimately to support information security continuous monitoring (ISCM) activities.\n\nThis cybersecurity white paper, NIST CSWP 30, summarizes the findings from an internal review of the IR 8011 project. It outlines opportunities for improving the methodology, including restructuring the workflow for readability, expanding keyword search functions, and abstracting the security framework to support any control-based framework. The paper provides a glimpse of what is coming next and updates the IR 8011 development roadmap, with a stated goal of operationalizing the framework into solutions that can benefit agencies and organizations.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "nist-sp-800-30-risk-assessment"
  ],
  "primary_citations_count": 8
}