Methodology
Third-party CyberGRX report provides a standardized vendor assessment survey, analysis and reporting based on the National Institute of Standards and Technology (NIST) SP 800-53 and International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 27001 frameworks.
The assessment features five control groups:
- Strategic
- Operations
- Core
- Management
- Privacy
The aforementioned groups include controls and sub-controls based on the following frameworks: SOC, ISO 27001, NIST 800-53, NIST 800- 171, NY-DFS, PCI DSS, FFIEC, SIG, and more
Remote and On-Site Validation
Remote and On-Site validation requires a third party to provide CyberGRX Analysts with evidence artifacts that support their assessment answers.
This validation process proceeds as follows:
- Selection of Controls
- Evidence Request and Collection
- Evidence Submission
- Evidence Evaluation
Framework Mapping
Upon registration to CyberGRX platform our customers will be able to request the latest completed Risk Assessment report and map the assessment results to industry frameworks as well as custom frameworks to gain granular visibility into controls coverage.
The mapped frameworks are including but not limited to the following:
- Cybersecurity Maturity Model Certification (CMMC) Level 5
- National Institute of Standards and Technology (800.53 Revision 5 & CSF)
- Cloud Security Alliance (CSA-CCM & CAIQ)
- MITRE ATT&CK Framework
- California Consumer Privacy Act (CCPA)
- General Data Protection Regulation (GDPR)
- NYDFS Cybersecurity Regulation (23 NYCRR 500)
- Threat Profile: Accellion File Transfer Application Breach
- LogJam (CVE-2021-44228)