Information Assurance (IA) verifies the implementation and effectiveness of security controls before a system enters production. IAPs help operationalize IA through:
- Certification & Accreditation (C&A) frameworks (also known as ST&E under FISMA);
- Formal control testing, vulnerability scans and risk assessments; and
- Documentation such as Test Plans, System Security Plans and Findings Reports.
The IAP's proactive assurance process ensures that systems meet prescribed security baselines (e.g., NIST 800-53) prior to operational deployment. ComplianceForge offers templated documentation to simplify adoption, making IAPs a structured, repeatable way to enforce security compliance from Day 1.
The following are common statutory, regulatory and contractual requirements that expect "pre-production testing" or "information assurance" activities to be performed:
- ISO 27002 - 14.2.8
- European Union General Data Protection Regulation (EU GDPR) - Article 25
- NIST 800-171 - 3.12.1, 3.12.3 & Non-Federal Organization (NFO)
- NIST Cybersecurity Framework - PR.IP-2, PR.IP-5 & DE.DP-3
- Federal Risk and Authorization Management Program (FedRAMP) - Security Assessment & Authorization (CA) controls
- AICPA Trust Services Principles (TSP) SOC2 - CC7.4
- Center for Internet Security Critical Security Controls (CIS CSC) - 18.2, 18.4 & 18.8
- Cloud Security Alliance Cloud Controls Matrix (CSA CCM) - CCC-03
- Cloud Computing Compliance Controls Catalogue (C5) - BEI-02
- Monetary Authority of Singapore Technology Risk Management (MAS TRM) Guidelines - 6.0.1, 6.2.2, 6.2.3, 6.2.4, 6.3.4, 6.4.2, 6.4.3, 6.4.4, A.1.1 & A.1.2
- European Union Agency for Network and Information Security (ENISA) Technical Guideline of Security Measures - SO23
- National Industry Security Program Operating Manual (NISPOM) - 8-610 & 8-302
- Criminal Justice Information Services (CJIS) Security Policy - 5.10.4.1, 5.11.1.1, 5.11.1.2, 5.11.2 & 5.13.4.1
- Massachusetts MA 201 CMR 17.00 - 17.03(2)(d)(B)(i) & 17.03(2)(h)
- New York Department of Financial Services (23 NYCRR 500) - 500.02
- Oregon Consumer Identity Theft Protection Act (OCITPA) - 622(2)(B)(i)-(iv)
- Underwriters Laboratories (UL) 2900-1 - Section 12
- Payment Card Industry Data Security Standard (PCI DSS) - Requirement 6
- Motion Picture Association of America (MPAA) Content Security Program - MS-2.0