BlogCybersecurity
Security questionnaire overload? Know your options.
5 Minute Read
Read Security questionnaire overload? Know your options.Cybersecurity
By CORL Technologies | November 23, 2021
CORL is continually innovating and updating our capabilities to provide the healthcare industry’s leading Vendor Risk Management (VRM) solution set. We are pleased to announce that the following innovations have been released:
Product Name: CORL Vendor Portal v1.0
Component: NIST 800-53 Rev 5 Vendor Security Questionnaire (VSQ) Overview: The CORL Vendor Portal now includes a new NIST SP 800-53 Rev 5 Vendor Security Questionnaire (VSQ). The new vendor questionnaire is 351 questions and includes the following features:
|
The National Institute of Standards and Technology (NIST) has announced an updated version of their flagship security controls framework NIST Special Publication (SP) 800-53. The new version, Revision 5 or “Rev 5”, update is the first overhaul of the NIST SP 800-53 framework in over seven years and represents critical updates that reflect the modern cyber threat landscape. A major addition in this revision includes an entire security controls “family” dedicated to Supply Chain Risk Management (SR).
A complete rundown of the new NIST SP 800-53 Rev 5 controls and a comparison to NIST SP 800-53 Rev 4 can be found in our related blog post: NIST SP 800-53 Rev 5: New Supply Chain Control Requirements.
The new NIST SP 800-53 Rev 5 vendor questionnaire is 351 questions and includes the following features:
The vendor questionnaire has been updated from NIST SP 800-53 Rev 4 controls to new Rev 5 control set
The vendor questionnaire now includes a new domain for privacy controls that NIST indicates has the following benefits:
The vendor questionnaire now includes a new domain for Supply Chain Risk that NIST indicates has the following benefits:
These new control areas in the vendor questionnaire are designed to modernize security control requirements for application security and related application security testing processes.
The consolidation of controls and logical restructuring of the framework is a necessary form of “hygiene” for any control framework that strives to keep up with complex and evolving business and threat landscapes. NIST describes the control consolidation updates as follows:
The movement to outcomes-based controls represents a fundamental mindset shift that will help organizations to move away from a focus on tactical “busy work” and towards strategic outcomes that can measurably reduce risk. NIST describes the outcomes-based model as follows:
More details about the NIST SP 800-53 Rev 5 vendor questionnaire and control set can be found in the following resources:
[1] https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
[2] https://www.nist.gov/blogs/cybersecurity-insights/next-generation-security-and-privacy-controls-protecting-nations
CORL Technologies
CORL transforms TPRM chaos into clarity
CORL is a leading provider of vendor risk management solutions for the healthcare industry. CORL gets results by scaling organizational and vendor risk programs through our healthcare vendor risk clearinghouse solution, dashboard reporting that business owners can understand, and proven workflows that drive measurable risk reduction. CORL accelerates the speed of vendor risk assessments and holds vendors accountable for remediating risk exposures.
Related Posts
BlogCybersecurity
By CORL Technologies | August 9, 2024
5 Minute Read
Read Security questionnaire overload? Know your options.BlogTPRM
By CORL Technologies | June 19, 2024
5 Minute Read
Read Essential Guide for Vendors: Key Features to Look for in a Cyber Security Assessment Tool for Healthcare TPRMBlogCybersecurity
By CORL Technologies | February 12, 2024
3 Minute Read
Read Do You Understand Your Vendors’ SOC 2 Reports?Webinars
WEBINAR A High-Velocity Approach to TPRM When healthcare organizations think of TPRM, the last thing they think of is ‘fast.’ Instead, today’s approaches to TPRM are exceedingly resource-intensive, expensive, ineffective, and slow. The laggard pace of TPRM is a stark contrast to the rapid pace of innovation in healthcare, which is essential to powering new […]