Security - Compliance with Security Controls Equivalent to NIST 800-53 for Low-Impact Systems, v1.0

Credential Service Providers must comply with security controls of NIST 800-53 for low impact systems or equivalent.

Assessment Step

1
Security Low Impact (SecurityLowImpact)
Does the CSP comply with NIST 800-53 or equivalent set of security controls?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample processes) that the CSP complies with required security controls.

Conformance Criteria (1)

C1
The CSP SHALL employ appropriately-tailored security controls from the low baseline of security controls defined in SP 800-53 or equivalent federal (e.g. FEDRAMP) or industry standard. The CSP SHALL ensure that the minimum assurance-related controls for low-impact systems, or equivalent, are satisfied.
Citation
NIST SP 800-63B
Section 4.1.4