DSP version 2022.3 release

DSP version 2022.3 release

ComplianceForge Support ComplianceForge Support
1 minute read

Listen to article
Audio generated by DropInBlog's Blog Voice AI™ may have slight pronunciation nuances. Learn more

ComplianceForge is pleased to announce the release of version 2022.3 of the Digital Security Program (DSP). There is some new content and minor refinement of the risk catalog to standardize wording improve readability and it also includes a new Evidence Request List (ERL) to help standardize naming for evidence artifacts. The DSP contains 1-1 mapping to the Secure Controls Framework (SCF) so you can have policies, control objectives, standards and more to support your implementation of the SCF!

New mapping in this version includes: 

  • Australian Government Information Security Manual (ISM) September 2022
  • BSI Standard 200-1
  • California Privacy Rights Act (CPRA) - November 2022 version
  • Cybersecurity Capability Maturity Model (C2M2) v2.1
  • Illinois Biometric Information Privacy Act (PIPA)
  • Illinois Identity Protection Act (IPA)
  • ISO 27017:2015
  • ISO 27001:2022
  • Japan Information System Security Management and Assessment Program (ISMAP)
  • New Zealand NZISM 3.6
  • Shared Assessments SIG 2023
  • US Centers for Medicare & Medicaid Services MARS-E Document Suite, Version 2.0.

Learn more about this premium GRC content at https://complianceforge.com/secure-controls-framework-scf-compliance-bundles/

« Back to Blog

NIST SP 800‑53 R5 Control Families

This release includes a total of 1,189 controls, organized into 20 families:

  1. Access Control
  2. Awareness & Training
  3. Audit & Accountability
  4. Assessment, Authorization & Monitoring
  5. Configuration Management
  6. Contingency Planning
  7. Identification & Authentication
  8. Incident Response
  9. Maintenance
  10. Media Protection
  11. Physical & Environmental Protection
  12. Planning
  13. Program Management
  14. Personnel Security
  15. Personally Identifiable Information (PII) Processing & Transparency
  16. Risk Assessment
  17. System & Services Acquisition
  18. System & Communications Protection
  19. System & Information Integrity
  20. Supply Chain Risk Management

This count includes deprecated controls that have been removed or folded into others. Some controls are not categorized under baselines—low, moderate, high, or privacy—per NIST SP 800‑53B.

ComplianceForge provides full 1:1 mapping of all 20 families and their controls in its CDPP documentation.