Risk Posture Insights

Practitioner-focused articles on NIST GRC. Clear explanations of the frameworks behind the tools, and how to apply them to real assessments.

CMMCSP 800-171Rev 3DoD

NIST SP 800-171 Rev 2 vs Rev 3: What Changed, and What It Means for CMMC

NIST finalized SP 800-171 Rev 3 in 2024: 17 families, 97 requirements, and organization-defined parameters. But CMMC still runs on Rev 2. Here's what actually changed and how to prepare.

· 9 min readRead →
NIST AI RMFAI GovernanceGenerative AIAI 100-1

NIST AI RMF Explained: A Practical Guide to the AI Risk Management Framework

The Govern, Map, Measure, and Manage functions, all 72 subcategories, the maturity tiers, the Generative AI Profile, and how to run your first AI RMF assessment.

· 11 min readRead →
NIST CSF 2.0Self-AssessmentGap AnalysisFree Tools

How to Run a Free NIST CSF 2.0 Self-Assessment

A step-by-step walkthrough for running a NIST CSF 2.0 self-assessment: scoping, the six functions (including the new GOVERN), a tier-based scoring rubric, reading the gap analysis, and turning gaps into a plan, all in a free browser-based tool.

· 9 min readRead →
CMMCSP 800-171SPRSDoD

CMMC Level 2: What It Demands and How to Know Where You Stand

Every DoD contractor handling CUI needs a SPRS score on file. Here's what the 110-requirement CMMC Level 2 assessment entails and how to calculate your score before the assessor arrives.

· 10 min readRead →
POA&MFedRAMPFISMARemediation

POA&M Template: The Fields That Matter (and a Free Tracker)

A field-by-field POA&M template mapped to FISMA and FedRAMP expectations (weakness, source, severity, completion dates, milestones, status), plus the severity-based remediation deadlines and a free, browser-based tracker that flags overdue items.

· 9 min readRead →
POA&MFISMAFedRAMPRemediation

The POA&M: Why Tracking Remediation Is What Keeps Your ATO Alive

An ATO isn't a certificate, it's a risk acceptance with conditions. The POA&M is the document that proves you're honoring those conditions. Let it go stale and your authorization follows.

· 9 min readRead →
SSPSP 800-18SP 800-53FIPS 199

System Security Plan (SSP) Template: Structure, Sections, and a Free Builder

A practitioner's SSP template mapped to NIST SP 800-18 Rev 1: system identification, FIPS 199 categorization that drives the SP 800-53 Rev 5 baseline, boundary, roles, control narratives, and CM-8 inventory, with a free in-browser builder.

· 9 min readRead →
NIST CSF 2.0MaturityGap Analysis

Tracking NIST CSF Maturity Over Time: The Benefits of a Trend, Not a Single Score

A one-time NIST CSF assessment tells you where you are. Tracking maturity across assessments tells you whether your security program is actually improving, and where investments aren't moving the needle.

· 9 min readRead →
SP 800-30Risk AssessmentNISTTemplate

NIST SP 800-30 Risk Assessment: A Template and Worked Example

A working NIST SP 800-30 Rev. 1 risk assessment template: walk the threat-source-to-risk model, score three risks end to end with the likelihood and impact scales, and read the risk determination matrix. Includes the semi-quantitative scoring bins and qualitative vs. semi-quantitative tradeoffs.

· 11 min readRead →
SP 800-53 Rev 5SP 800-53BTailoringSSP

SP 800-53 Control Tailoring: A Daunting Task Made Systematic

SP 800-53 Rev 5 has 20 control families and over 1,000 controls. Tailoring, adjusting the baseline to fit your system, is where most authorization teams stall. Here's the decision framework that makes it tractable.

· 11 min readRead →
Risk AssessmentSP 800-30

Why Your Heat Map Doesn't Match Your Risk Score

The NIST SP 800-30 qualitative heat map and your calculated risk score tell two different stories. Here's why that happens, and how RPT's semi-quantitative approach makes them consistent.

· 10 min readRead →
RMFSP 800-37Authorization

RMF Simplified: How the Seven Steps Bring Clarity to System Authorization

The NIST Risk Management Framework's seven steps aren't bureaucracy, they're a decision sequence. Breaking each one down reveals exactly what the framework is trying to accomplish.

· 12 min readRead →
FoundationsSP 800-30SP 800-39

What Is Risk? The NIST Definition and Why It Changes How You Assess

Risk has a precise meaning in the NIST framework, and it's not simply "the chance something bad happens." Understanding the real definition transforms how you write and defend assessment findings.

· 10 min readRead →

Put the frameworks to work

All tools are free to use. Open any assessment and start immediately, no account required.