DSP 2024.2
A moderate update that introduced PPTDF control tagging and added the MSP/MSSP Secure Practices Baseline as the SCF-M sub-control set.
What changed in this release
- Controls are now tagged for People, Processes, Technology, Data & Facilities (PPTDF) applicability: People (primarily applied to humans, such as employees, contractors and third parties); Process (a manual or automated process); Technology (a system, application and/or service); Data (data such as CUI, CHD or PII); and Facility (a physical building such as an office, data center, warehouse or home office).
- Added the “MSP/MSSP Secure Practices Baseline” as the SCF-M sub-control set. This is intended to help organizations perform Cybersecurity Supply Chain Risk Management (C-SCRM) assessments of their Managed Service Providers (MSP) and Managed Security Service Providers (MSSP), and is tailored to identifying reasonable controls across a set of common compliance expectations.
- Standards and guidelines were updated.
Releases older than 2024 (2023 and beyond) are not covered by this errata archive and are significantly out of date. Existing customers are encouraged to repurchase the current version at 50% of the original product price.