On the 6th of April, NIST is releasing Draft NIST Interagency Report (NISTIR) 8011 Volume 3, Automation Support for Security Control Assessments: Software Asset Management. This NISTIR represents a joint effort between NIST and the Department of Homeland Security to provide an operational approach for automating security control assessments in order to facilitate information security continuous monitoring, ongoing assessment, and ongoing security authorizations in a way that is consistent with the NIST Risk Management Framework as described in NIST Special Publication (SP) 800-37 and the guidance in SP 800-53 and SP 800-53A, in particular.
NISTIR 8011 will ultimately consist of 13 volumes. Volumes 1 and 2 were published in 2017. Volume 3 provides details specific to the software asset management security capability. The remaining 10 ISCM security capability volumes will provide details specific to each capability but will be organized in a very similar way to Volumes 2 and 3.
The public comment period is open through May 4th 2018.
Please submit public comments to sec-cert@nist.gov. Comments are accepted in any desired format.
CSRC Update: https://csrc.nist.gov/News/2018/NIST-Releases-Draft-NISTIR-8011-Volume-3
Publication details: https://csrc.nist.gov/publications/detail/nistir/8011/vol-3/draft