Sept. 5, 2022, 12:12 p.m. | /u/iggygatton

cybersecurity www.reddit.com

Stigviewer.com shows impact levels for NIST controls. Is this referring directly to risk? For instance, AC-5 separation of Duties has a Moderate impact level. Is this saying that an organization not implementing this control is assuming a moderate risk impact in doing so?

If this is not the case, how would an organization or accessor determine the risk level for not implementing a certain control?

controls cybersecurity nist risk

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Cybersecurity Triage Analyst

@ Peraton | Linthicum, MD, United States

Associate DevSecOps Engineer

@ LinQuest | Los Angeles, California, United States

DORA Compliance Program Manager

@ Resillion | Brussels, Belgium

Head of Workplace Risk and Compliance

@ Wise | London, United Kingdom