Compliance and Security Frameworks
23 chapters
1. 1 Defense in Depth
[Verse 1]
Picture walls around a castle, moats and guards in every tower
One defense can always crumble when it meets superior power
But layer shields of every nature, stack them deep and stack them wide
Administrative, technical, and physical side by side
[Chorus]
Defense in depth, defense in depth
Never trust a single step
Preventive, detective, corrective too
Layer controls in all you do
When one guard falls, the next stands tall
Defense in depth protects us all
[Verse 2]
Start with policies and training, that's administrative control
Then add firewalls and encryption, technical protections roll
Don't forget the locks and cameras, physical barriers strong
Three control types working together, harmonizing like a song
[Chorus]
Defense in depth, defense in depth
Never trust a single step
Preventive, detective, corrective too
Layer controls in all you do
When one guard falls, the next stands tall
Defense in depth protects us all
[Bridge]
Preventive stops before it starts
Detective finds when trouble parts
Corrective fixes what went wrong
Together they sing security's song
No single point of failure here
Multiple layers make threats disappear
[Verse 3]
Organizations must remember what the policy clearly states
Layer controls so that failure of one control never breaks
The whole security framework down, overlapping shields remain
When attackers breach the first line, other defenses break their chain
[Chorus]
Defense in depth, defense in depth
Never trust a single step
Preventive, detective, corrective too
Layer controls in all you do
When one guard falls, the next stands tall
Defense in depth protects us all
[Outro]
Layer by layer, control by control
Defense in depth is security's goal
Administrative, technical, physical might
Defense in depth keeps data safe and tight
2. 2 Separation of Duties
[Verse 1]
In the world of business process flow
There's a golden rule you need to know
When power concentrates in just one hand
That's when trouble strikes across the land
Sarah runs accounting, does it all
Authorization, execution, then the final call
But when she reviews her own work too
That's a recipe for problems coming through
[Chorus]
Split the duties, break the chain
No one person should maintain
All the power from start to end
Authorize, execute, then review again
Three distinct roles, three different hands
That's how solid control stands
Split the duties, make it right
Keep your processes in sight
[Verse 2]
Take procurement as our case in point
Three key functions at each joint
Someone approves what we should buy
Someone else signs the check goodbye
Then a third person reviews the deal
Makes sure everything was real
When these roles all separate
Fraud and errors can't take the bait
[Chorus]
Split the duties, break the chain
No one person should maintain
All the power from start to end
Authorize, execute, then review again
Three distinct roles, three different hands
That's how solid control stands
Split the duties, make it right
Keep your processes in sight
[Bridge]
Why do we divide and conquer
Makes the system so much stronger
Collusion takes conspiracy
Single actors can't run free
Human error gets detected
When the process is protected
Independence is the key
That's how controls are meant to be
[Verse 3]
From the corner store to corporate tower
Every business needs this power
Separation keeps us clean
Best control you've ever seen
Policy states it crystal clear
No single person engineer
The complete transaction flow
That's the way professionals go
[Chorus]
Split the duties, break the chain
No one person should maintain
All the power from start to end
Authorize, execute, then review again
Three distinct roles, three different hands
That's how solid control stands
Split the duties, make it right
Keep your processes in sight
[Outro]
Remember this when building systems
Good controls prevent the problems
Separation of duties strong
Keeps your organization moving along
3. 3 Least Privilege
[Verse 1]
Sarah starts her Monday morning, logging in to do her job
She's in accounting, needs the numbers, but the system's like a mob
Every folder, every database, wide open to her eyes
She can see the HR records, legal files, and salary ties
[Pre-Chorus]
But just because you can access
Doesn't mean you should possess
[Chorus]
Least privilege, least privilege
Give the minimum to get the job done
Least privilege, least privilege
Lock it down for everyone
Only what you need to succeed
Nothing more, that's the creed
Least privilege keeps us safe and sound
[Verse 2]
Marcus joins the marketing team, fresh-faced and ready to go
Admin gives him full permissions, every system, high and low
He can read the source code secrets, modify the client base
Delete the financial records, leave barely a trace
[Pre-Chorus]
When you open every door
You're just asking for much more
[Chorus]
Least privilege, least privilege
Give the minimum to get the job done
Least privilege, least privilege
Lock it down for everyone
Only what you need to succeed
Nothing more, that's the creed
Least privilege keeps us safe and sound
[Bridge]
Access to information systems
Limited by design
Minimum necessary access
Keeps everything in line
Your assigned duties define
What you get to see
Anything beyond that scope
Creates vulnerability
[Verse 3]
Policy says it crystal clear, no room for interpretation
Limit access to the minimum, across the whole organization
Job performance is the measure, not convenience or request
When you follow least privilege, you're simply at your best
[Final Chorus]
Least privilege, least privilege
Give the minimum to get the job done
Least privilege, least privilege
Lock it down for everyone
Only what you need to succeed
Nothing more, that's the creed
Least privilege keeps us safe and sound
Keeps us safe and sound
[Outro]
Minimum necessary
That's the way to be
Least privilege policy
Sets your data free
4. 4 Fail-Safe Defaults
[Verse 1]
When building systems, here's the golden rule
Start with nothing, that's your security tool
Every door is locked, every gate is closed
Until you say exactly what gets exposed
No assumptions, no shortcuts to take
Every permission is a choice you make
[Chorus]
Deny by default, that's the way to start
Explicit authorization, the beating heart
Four fail-safe defaults keep your system tight
Nothing gets through without permission's light
Deny by default, make them prove their case
Only documented access gets a place
[Verse 2]
Information systems lock it down complete
No back doors open, no access so sweet
Configure the barriers, build them up high
Every user must authenticate and try
When in doubt, the answer's always no
Until the paperwork says let it go
[Chorus]
Deny by default, that's the way to start
Explicit authorization, the beating heart
Four fail-safe defaults keep your system tight
Nothing gets through without permission's light
Deny by default, make them prove their case
Only documented access gets a place
[Bridge]
Document the reasons, write it down clear
Every granted access, keep the records near
When the auditors come knocking at your door
You'll have the proof of what each access is for
Failure modes should always lock it tight
Better safe than sorry in the security fight
[Verse 3]
Four defaults standing like a fortress wall
Fail secure, fail closed, deny them all
Minimal privilege, least access you give
That's how secure systems learn to live
Default deny is your first line defense
Making attackers jump through every fence
[Chorus]
Deny by default, that's the way to start
Explicit authorization, the beating heart
Four fail-safe defaults keep your system tight
Nothing gets through without permission's light
Deny by default, make them prove their case
Only documented access gets a place
[Outro]
When systems fail, they should fail secure
That's the principle that will endure
Deny by default, keep it locked down tight
That's management controls done right
5. 5 Accountability
[Verse 1]
In the digital domain where actions flow
Every click and command needs an owner we know
Sarah logs in with her personal key
No sharing passwords, accountability's free
When the audit trail shows what went wrong
We can trace it back where it belongs
[Chorus]
Every action has a name
Every user bears the blame
No generic, no shared account
Individual is paramount
Track it back, make it clear
Accountability starts here
[Verse 2]
The policy states what we must do
Shared accounts are banned, it's nothing new
But when business needs require exception
Document the case with clear perception
Compensating controls must be in place
To keep individual ownership in the race
[Chorus]
Every action has a name
Every user bears the blame
No generic, no shared account
Individual is paramount
Track it back, make it clear
Accountability starts here
[Bridge]
When the system asks who did what
Point to one person, close the cut
No confusion, no gray zone
Every deed has an owner shown
Responsibility can't hide
When accounts are personalized
[Verse 3]
From the server room to the cloud above
Personal access is what we love
Generic logins blur the line
Individual tracks by design
When compliance comes to call
We'll have answers for them all
[Chorus]
Every action has a name
Every user bears the blame
No generic, no shared account
Individual is paramount
Track it back, make it clear
Accountability starts here
[Outro]
One person, one account, one way to be sure
Accountability keeps our systems secure
Every action, every name
That's how we play the management game
6. 6 Proportionality
[Verse 1]
When data flows through systems every day
We need to guard what matters most they say
But building walls around everything we see
Costs more than what we're trying to keep free
A simple file needs simple protection
While secrets need much more inspection
[Chorus]
Proportionality, match the guard to what you save
Strong controls for treasures, light ones for the everyday
Commensurate with classification and the risk we face
Right-sized protection, everything in its right place
Proportionality, that's the management control way
[Verse 2]
Assess the value, measure what's at stake
Then choose your controls for goodness sake
Don't put a bank vault door on garden shed
But don't leave diamonds under flower bed
The policy states it crystal clear today
Match protection to the risk we weigh
[Chorus]
Proportionality, match the guard to what you save
Strong controls for treasures, light ones for the everyday
Commensurate with classification and the risk we face
Right-sized protection, everything in its right place
Proportionality, that's the management control way
[Bridge]
High value data gets the fortress treatment
Medium risk deserves some good agreement
Low classification needs basic measures
Balance cost with organizational treasures
When threats are severe, controls get stronger
When risks are mild, we don't wait longer
[Chorus]
Proportionality, match the guard to what you save
Strong controls for treasures, light ones for the everyday
Commensurate with classification and the risk we face
Right-sized protection, everything in its right place
Proportionality, that's the management control way
[Outro]
Strength and cost should always match the prize
That's how management controls get wise
7. 1 SOC 2 Trust Services Criteria
[Verse 1]
In the world of enterprise control design
SOC 2 draws the compliance line
Five trust services guide our way
Security, availability every day
Processing integrity keeps data clean
Confidentiality guards what's unseen
[Chorus]
S-A-P-C-P, trust services we need
Security first, availability freed
Processing right, confidentiality tight
Privacy protected, controls burn bright
Common criteria one through nine
Map your controls, align the line
[Verse 2]
Security sits at the foundation
Common criteria cross every station
CC one through nine, the framework core
Access controls and governance more
Risk assessment drives the plan
Logical access for every man
[Chorus]
S-A-P-C-P, trust services we need
Security first, availability freed
Processing right, confidentiality tight
Privacy protected, controls burn bright
Common criteria one through nine
Map your controls, align the line
[Verse 3]
Availability keeps systems running strong
Processing integrity prevents what's wrong
Confidentiality locks sensitive doors
Privacy rights that law requires
Each criterion has its numbered place
Control activities fill the space
[Bridge]
When you write your policy text
Reference the criteria that comes next
"This policy supports SOC 2 goals
Addressing Trust Services Criteria" roles
CC six point two or A one point one
Map your controls till compliance is done
[Chorus]
S-A-P-C-P, trust services we need
Security first, availability freed
Processing right, confidentiality tight
Privacy protected, controls burn bright
Common criteria one through nine
Map your controls, align the line
[Outro]
Five categories, numbered clear
SOC 2 compliance drawing near
Trust services criteria guide the way
To controlled environments every day
8. 2 CMMC (Cybersecurity Maturity Model Certification)
[Verse 1]
Fourteen domains built from NIST eight oh one seventy one
Three levels rising up but Level Two's where most work gets done
One hundred ten practices waiting for your compliance call
From access control to system integrity, gotta implement them all
[Chorus]
CMMC Level Two, that's the target we pursue
AC dot L2 dash three dot one dot one, that's how we reference what we've done
Domain name and practice ID, policy language clear to see
CMMC Level Two, cybersecurity breakthrough
[Verse 2]
Configuration management, identification and authentication
Incident response planning with proper documentation
Media protection, personnel security standing strong
Physical protection, recovery processes when things go wrong
[Chorus]
CMMC Level Two, that's the target we pursue
AC dot L2 dash three dot one dot one, that's how we reference what we've done
Domain name and practice ID, policy language clear to see
CMMC Level Two, cybersecurity breakthrough
[Bridge]
When you're crossing that US-Canada line
CPCSC and CMMC must align
More restrictive requirement wins the day
Independent paths when they diverge away
Dual compliance keeps you safe and sound
Best of both nations' cyber battleground
[Verse 3]
Risk assessment, security assessment running side by side
System and communications protection cannot hide
System and information integrity, awareness and training too
Maintenance domain completes the set, now you know what you must do
[Chorus]
CMMC Level Two, that's the target we pursue
AC dot L2 dash three dot one dot one, that's how we reference what we've done
Domain name and practice ID, policy language clear to see
CMMC Level Two, cybersecurity breakthrough
[Outro]
This policy implements the way
CMMC Level Two leads the day
Maturity model certification
Protecting our digital nation
9. 3 HIPAA Security Rule
[Verse 1]
When patient data needs protection strong
HIPAA Security Rule comes along
Three categories guard the way
Administrative, Physical, Technical today
Some standards are required by the law
Others addressable, but still must draw
A plan to implement or justify
Why alternatives will satisfy
[Chorus]
A-P-T, remember these three
Administrative, Physical, Technical security
Required means you must comply
Addressable means implement or justify
Document your choices in the risk assessment file
Forty-five CFR one-sixty-four style
[Verse 2]
Administrative controls set the tone
Policies and procedures, workforce shown
Who can access what and when they may
Training and sanctions guide the way
Security officer leads the charge
Information access management large
Assigned security responsibility
Workforce training and activity
[Chorus]
A-P-T, remember these three
Administrative, Physical, Technical security
Required means you must comply
Addressable means implement or justify
Document your choices in the risk assessment file
Forty-five CFR one-sixty-four style
[Verse 3]
Physical safeguards guard the space
Workstations, media in their place
Facility access controls the door
Device and media controls and more
Technical safeguards use technology
Access control and activity
Audit controls track every move
Integrity and transmission prove
[Bridge]
One-sixty-four point three-hundred sections tell
Which standards are required, which addressable
Risk assessment documents your reasoning
For every choice that you are seasoning
Implementation specifications guide
How compliance will be verified
[Chorus]
A-P-T, remember these three
Administrative, Physical, Technical security
Required means you must comply
Addressable means implement or justify
Document your choices in the risk assessment file
Forty-five CFR one-sixty-four style
[Outro]
Three pillars standing strong and true
HIPAA Security protecting you
Administrative, Physical, Technical way
Keeping patient data safe each day
10. 5 NIST SP 800-53
[Verse 1]
Twenty families of controls to guide your way
From Access Control to Supply Chain every day
AC, AT, AU - the alphabet begins
CA, CM, CP - where security wins
Each control has a number and a baseline too
Low, Moderate, High - depends on what you do
[Chorus]
Eight hundred fifty-three, the catalog we need
Twenty families strong, security's our creed
Base controls and enhancements, tailor to your site
NIST gives us the framework to get security right
Reference in your policy, implement with care
Eight hundred fifty-three, controls beyond compare
[Verse 2]
Identity and Authentication, that's IA
Incident Response when things go astray
Maintenance and Media Protection keep us sound
Personnel Security, trusted people all around
Privacy controls with PT designation
Risk Assessment guides your organization
[Chorus]
Eight hundred fifty-three, the catalog we need
Twenty families strong, security's our creed
Base controls and enhancements, tailor to your site
NIST gives us the framework to get security right
Reference in your policy, implement with care
Eight hundred fifty-three, controls beyond compare
[Bridge]
Physical and Environmental, Planning too
Program Management, what managers must do
System Acquisition, Communications secure
System Information Integrity for sure
When you write your policy, here's the way to go
"This implements requirements of controls below"
[Verse 3]
State the family and the numbers that apply
XX dash one, XX dash two, reaching for the sky
Choose your baseline level, Low or Moderate
High impact systems need the strongest advocate
Enhancements are optional but they give you more
Layered security from ceiling to the floor
[Final Chorus]
Eight hundred fifty-three, revision number five
Twenty families working to keep your data alive
From Access to Supply Chain, every family's role
NIST eight hundred fifty-three, security's our goal
Reference in your policy, implement with pride
Eight hundred fifty-three, your cybersecurity guide
[Outro]
Twenty families strong
Security belongs
Eight hundred fifty-three
Your guide to being free
From cyber threats today
The NIST SP way
11. 6 PIPEDA and Canadian Privacy Requirements
[Verse 1]
In Canada's digital landscape, there's a law we all must know
PIPEDA guards our privacy as personal data flows
Ten fair principles guide the way for every company
From consent to accountability, protecting you and me
[Chorus]
P-I-P-E-D-A, ten principles light the way
Consent and purpose, minimal use
Accuracy and retention, access for me and you
Security, openness, challenge when things go wrong
Accountability makes us strong
[Verse 2]
First comes consent, meaningful and clear
Tell me what you're collecting and why you need it here
Purpose limitation keeps you on the narrow track
Use my data for what you said, don't go behind my back
[Chorus]
P-I-P-E-D-A, ten principles light the way
Consent and purpose, minimal use
Accuracy and retention, access for me and you
Security, openness, challenge when things go wrong
Accountability makes us strong
[Verse 3]
Data minimization is the golden rule
Only collect what's necessary, that's the privacy tool
Keep it accurate, keep it fresh, update when things have changed
And when the purpose has been served, make sure it's been arranged
[Bridge]
This policy implements the requirements of PIPEDA
Principle by principle, protecting data every day
Individual access rights, let people see what's stored
Security safeguards in place, privacy is our reward
[Verse 4]
Openness means transparency in all your privacy ways
Challenge mechanisms ready for those questioning days
Retention schedules clearly set, don't keep what you don't need
Accountability at the top, that's how we all succeed
[Chorus]
P-I-P-E-D-A, ten principles light the way
Consent and purpose, minimal use
Accuracy and retention, access for me and you
Security, openness, challenge when things go wrong
Accountability makes us strong
[Outro]
From coast to coast across our land
PIPEDA helps us understand
Personal information deserves respect
Ten principles we won't neglect
12. 1 NIST 800-171 and CMMC Level 2
[Verse 1]
One hundred ten controls in revision two
NIST eight oh one seventy one that we pursue
Revision three is coming with some changes new
But level two is where we start our journey through
Self-assessment first or C three PAO way
Choose your path but know the price you'll have to pay
[Chorus]
Access Control, Audit trail
Configuration never fail
ID and Authentication strong
System Protection all along
Information Integrity
Six domains for you and me
CMMC level two compliance
Built on cybersecurity science
[Verse 2]
Scoping boundaries are the choice that matters most
What's inside CUI protection, what can you boast
Draw the lines too wide and costs will make you ghost
Draw them thin and auditors will be your host
Infrastructure mapping to each domain
Shows the controls where security must remain
[Chorus]
Access Control, Audit trail
Configuration never fail
ID and Authentication strong
System Protection all along
Information Integrity
Six domains for you and me
CMMC level two compliance
Built on cybersecurity science
[Bridge]
POA and M management
What assessors will accept
Timelines reasonable
With progress they expect
But wishful thinking plans
Will get your cert reject
Show concrete remediation
That you can architect
[Verse 3]
Self-assessment means you validate your own
But C three PAO brings eyes you've never known
Third party assessment sets a different tone
Higher confidence but seeds that must be sown
From basic safeguarding to enhanced protection
Every control needs proper implementation
[Chorus]
Access Control, Audit trail
Configuration never fail
ID and Authentication strong
System Protection all along
Information Integrity
Six domains for you and me
CMMC level two compliance
Built on cybersecurity science
[Outro]
Defense contractors listen well
Your infrastructure story tell
Map each control to every part
NIST eight oh one seventy one by heart
Level two will pave the way
For defending USA
13. 2 CPCSC (Canadian Program for Cyber Security Certification)
[Verse 1]
Canada's building cyber walls so strong
CPCSC Level Two where we belong
Aligned with CMMC across the border line
Defense contractors need both to shine
ITSG thirty-three controls the Canadian way
Built on NIST foundation but sovereign they say
[Chorus]
Two levels aligned, controls defined
ITSG and NIST combined
CUI stays home, controlled goods too
Cross-border patterns, compliance through and through
CPCSC rising, get ready now
Defense infrastructure, we'll show you how
[Verse 2]
Data sovereignty means knowing where it lives
Canadian controlled goods, location restrictive
CUI cannot cross without proper care
Architecture patterns show us how to share
Hybrid clouds with regional zones
Keep sensitive data in national homes
[Chorus]
Two levels aligned, controls defined
ITSG and NIST combined
CUI stays home, controlled goods too
Cross-border patterns, compliance through and through
CPCSC rising, get ready now
Defense infrastructure, we'll show you how
[Bridge]
Timeline moving fast, implementation near
Twenty twenty-five the target year appears
Start your assessments, map your controls
Both sides of the border, achieve your goals
Reciprocity coming, mutual trust
Dual compliance frameworks, adapt you must
[Verse 3]
Cross-border architecture needs careful design
Canadian regions for sensitive line
US zones handle unclassified flow
Network segmentation, keep data controlled
Zero trust principles, verify each call
Defense in depth protects us all
[Chorus]
Two levels aligned, controls defined
ITSG and NIST combined
CUI stays home, controlled goods too
Cross-border patterns, compliance through and through
CPCSC rising, get ready now
Defense infrastructure, we'll show you how
[Outro]
CPCSC Level Two
Your certification's calling you
Sovereignty and security aligned
Defense infrastructure by design
14. 3 STIG Hardening
[Verse 1]
Security Technical Implementation Guides define the way
Rules and checks with severity grades to keep the threats at bay
Fix text tells you how to solve, check text shows what's wrong
CAT One, Two, and Three findings help you sing security's song
[Chorus]
STIG it up, lock it down, automate the compliance round
CAT One critical must be fixed, CAT Two and Three can wait around
Document every deviation, risk acceptance or control
STIG hardening keeps us safe, security is our goal
[Verse 2]
Kubernetes STIG protects your pods and API server calls
RBAC policies, network rules, and secrets behind the walls
Operating systems need their guides, RHEL Eight and Nine
Ubuntu runs with CIS Benchmarks, keeping systems fine
[Chorus]
STIG it up, lock it down, automate the compliance round
CAT One critical must be fixed, CAT Two and Three can wait around
Document every deviation, risk acceptance or control
STIG hardening keeps us safe, security is our goal
[Bridge]
OSCAP scans your system state
Ansible roles automate
InSpec tests and Cinc Auditor
Make compliance so much greater
[Verse 3]
Application STIGs secure your code and web server stack
Database configs, SSL certs, preventing each attack
When you cannot fix a finding, document the reason why
Compensating controls might work, or accept the risk and try
[Chorus]
STIG it up, lock it down, automate the compliance round
CAT One critical must be fixed, CAT Two and Three can wait around
Document every deviation, risk acceptance or control
STIG hardening keeps us safe, security is our goal
[Outro]
Category One means fix it now
Category Two and Three allow
Some flexibility in timing
Keep your infrastructure climbing
STIG compliance, stay secure
Defense infrastructure stays pure
15. 4 FIPS 140-2/140-3 Cryptography
[Verse 1]
When security demands the highest grade
FIPS validation is the test that must be made
Not just compliance with the written spec
But certified modules that inspectors check
Validation means it passed the rigorous test
Compliance means you follow but haven't been blessed
FIPS mode is when the system locks it down
Only approved algorithms are allowed
[Chorus]
FIPS one-forty-two and three
Cryptographic security
Validated not compliant mode
Check the cert before you load
OpenSSL provider true
BoringCrypto built for you
NSS and Bouncy Castle too
Make sure FIPS follows through
[Verse 2]
In the Java world where JVM runs deep
Bouncy Castle FIPS makes your crypto sleep safe
Red Hat's system-wide policies set the tone
Every process follows rules they've grown
But configuring FIPS isn't always enough
You must test and verify the crypto stuff
Don't assume that setting flags will do
Validate enforcement is working too
[Chorus]
FIPS one-forty-two and three
Cryptographic security
Validated not compliant mode
Check the cert before you load
OpenSSL provider true
BoringCrypto built for you
NSS and Bouncy Castle too
Make sure FIPS follows through
[Verse 3]
When Kafka needs to stream with FIPS in place
TLS handshakes slow down at their pace
Cipher suites get restricted to approved lists
Compatibility problems can't be dismissed
Kubernetes feels the impact everywhere
API server etcd kubelet must declare
Service mesh TLS gets constrained
Performance costs that can't be feigned
[Bridge]
Test don't trust the FIPS mode flag
Run the benchmarks feel the drag
Early testing saves the day
Performance penalty you'll pay
Validation over compliance wins
That's where real security begins
[Chorus]
FIPS one-forty-two and three
Cryptographic security
Validated not compliant mode
Check the cert before you load
OpenSSL provider true
BoringCrypto built for you
NSS and Bouncy Castle too
Make sure FIPS follows through
[Outro]
Defense infrastructure needs it right
FIPS validation burning bright
Test enforce and verify
Cryptographic standards high
16. 5 FedRAMP and Cloud Authorization
[Verse 1]
When you're building systems for the government's defense
FedRAMP authorization makes the compliance sense
Low for public data, Moderate for most
High for national security, that's what matters most
DoD maps their levels two through six in line
With FedRAMP's framework, keeping data fine
[Chorus]
Low Moderate High, know your authorization
Shared responsibility, cloud configuration
You own the data, apps, and access control
CSP handles infrastructure, that's their role
Monitor continuous, scan and update
FedRAMP in the cloud, don't hesitate
[Verse 2]
Shared responsibility splits the compliance load
Cloud provider secures the underlying code
Physical security, network infrastructure too
Hypervisor patching, that's what they do for you
But you still own identity, encryption keys
Operating systems, applications if you please
[Chorus]
Low Moderate High, know your authorization
Shared responsibility, cloud configuration
You own the data, apps, and access control
CSP handles infrastructure, that's their role
Monitor continuous, scan and update
FedRAMP in the cloud, don't hesitate
[Verse 3]
GovCloud regions keep your data state-side
AWS GovCloud, Azure Government pride
Google's Assured Workloads for compliance needs
Isolated environments where security feeds
US persons only with the clearance right
Keeping federal data safe day and night
[Bridge]
Vulnerability scanning monthly at least
POA and M updates, never cease
Inherit those controls from your CSP's pack
Reference their SSP, stay on track
Continuous monitoring never sleeps
Assessment and authorization, the cycle repeats
[Chorus]
Low Moderate High, know your authorization
Shared responsibility, cloud configuration
You own the data, apps, and access control
CSP handles infrastructure, that's their role
Monitor continuous, scan and update
FedRAMP in the cloud, don't hesitate
[Outro]
From IL-two to six, map it right
FedRAMP authorization shining bright
Cloud security shared but never ignored
Defense infrastructure, properly secured
17. 6 Container Supply Chain Security
[Verse 1]
When you need containers that are battle-tested and clean
Iron Bank at repo one D-S-O dot mil is the scene
Hardened images waiting with approval process tight
Every base is vetted through security's keen sight
But when pre-built won't cut it and custom's what you need
Build from hardened foundations, that's the golden creed
[Chorus]
Sign and verify, scan and deny
SBOM tells us what's inside
Gates that guard before deploy
Container security we can't avoid
Iron Bank, custom build, sign the deal
Scan for flaws, gates enforce, keep it real
[Verse 2]
Cosign and Notary version two will mark your way
Digital signatures prove your images are okay
Software Bill of Materials in SPDX we trust
CycloneDX format showing every bit of rust
Generate and consume these lists of every part
Transparency in components is security's art
[Chorus]
Sign and verify, scan and deny
SBOM tells us what's inside
Gates that guard before deploy
Container security we can't avoid
Iron Bank, custom build, sign the deal
Scan for flaws, gates enforce, keep it real
[Bridge]
Trivy scans the layers deep
Grype finds the flaws that creep
Anchore guards the CI-CD way
Catching vulns before they play
O-P-A Gatekeeper stands so tall
Kyverno answers policy's call
[Verse 3]
In your pipeline integration vulnerability scanning flows
Trivy Grype and Anchore catch the threats nobody knows
At deploy time admission controllers take their stand
Gatekeeper and Kyverno with policies so grand
Image policies enforced before the pods can start
Security woven deep into DevOps beating heart
[Chorus]
Sign and verify, scan and deny
SBOM tells us what's inside
Gates that guard before deploy
Container security we can't avoid
Iron Bank, custom build, sign the deal
Scan for flaws, gates enforce, keep it real
[Outro]
From Iron Bank to custom builds
Through scanning tools and policy shields
Container supply chain locked down tight
Security done right
18. 1 System Security Plan (SSP)
[Verse 1]
Start with system description clear and bright
Document the purpose, scope, and operational sight
Draw the boundary diagram, show what's in and out
Authorization limits that you can't live without
[Chorus]
S-S-P, System Security Plan
Structure, Boundary, Controls - that's the master plan
Specific, Measurable, Referenced and true
Living document flowing through and through
S-S-P, keep it up to date
OSCAL makes it machine-readable, don't hesitate
[Verse 2]
Control implementations need specific detail
Not just "we comply" - that story will fail
Reference configurations, procedures you use
Assessors need evidence they can't refuse
[Chorus]
S-S-P, System Security Plan
Structure, Boundary, Controls - that's the master plan
Specific, Measurable, Referenced and true
Living document flowing through and through
S-S-P, keep it up to date
OSCAL makes it machine-readable, don't hesitate
[Verse 3]
Leveraged from common, inherited and shared
Hybrid splits the duty, responsibility paired
System-specific controls you implement alone
Three types of controls in every security zone
[Bridge]
Throughout the lifecycle, keep it alive
Update as you build, maintain, and strive
OSCAL format makes automation sing
Machine-readable plans are the powerful thing
[Chorus]
S-S-P, System Security Plan
Structure, Boundary, Controls - that's the master plan
Specific, Measurable, Referenced and true
Living document flowing through and through
S-S-P, keep it up to date
OSCAL makes it machine-readable, don't hesitate
[Outro]
From system description to control detail
Living SSP will help you prevail
19. 4 Risk Management
[Verse 1]
Every project starts with threats we cannot see
Hidden risks that lurk beneath complexity
Build your register with four columns standing tall
Identify the danger, then assess them all
Likelihood and impact, plot them on your grid
Mitigation strategies for every risk you bid
[Chorus]
Risk register, POA and M
I-L-I-M-A, remember them
Identify, Likelihood, Impact, Mitigate, Accept
Communication flows from tech to exec
When to fix, when to accept, when to redesign
Risk management keeps your project in line
[Verse 2]
POA and M is your action battle plan
Timelines and milestones help you understand
What goes in the document, evidence of progress
Tracking every weakness until you clean the mess
Resources and owners, completion target dates
Monitor the status before it's too late
[Chorus]
Risk register, POA and M
I-L-I-M-A, remember them
Identify, Likelihood, Impact, Mitigate, Accept
Communication flows from tech to exec
When to fix, when to accept, when to redesign
Risk management keeps your project in line
[Bridge]
Talking to the boardroom, leave the jargon at the door
Business impact language is what they're looking for
High medium and low, with dollars on the line
Show them what it costs and give them a timeline
[Verse 3]
Three choices face you when the risk appears
Accept it, fix it, or redesign your gears
Low impact, low chance, acceptance might be right
Critical vulnerabilities need immediate fight
When the foundation's broken, redesign's the way
Architecture changes save another day
[Chorus]
Risk register, POA and M
I-L-I-M-A, remember them
Identify, Likelihood, Impact, Mitigate, Accept
Communication flows from tech to exec
When to fix, when to accept, when to redesign
Risk management keeps your project in line
[Outro]
Defense infrastructure depends on what you choose
Manage every risk or watch your project lose
I-L-I-M-A guides you through the storm
Risk management keeps your systems strong
20. 3 Continuous Monitoring and Continuous ATO
[Verse 1]
Gone are the days of waiting years for clearance
Traditional ATO took forever to appear
Now DevSecOps brings continuous compliance
With automated checks that make security clear
Every code commit triggers validation
Real-time monitoring across the nation
[Chorus]
Continuous ATO, keep the flow alive
Scan, Triage, Remediate, Document to survive
SIEM integration collecting every trace
Ongoing authorization keeps systems in their place
Monitor continuously, never lose the thread
DevSecOps pipeline keeps security fed
[Verse 2]
Configuration drift detection running daily
Access reviews automated through the night
Compliance evidence gathered oh so neatly
Scan results flowing in to keep things right
No more manual paperwork delays
Continuous monitoring lights the way
[Chorus]
Continuous ATO, keep the flow alive
Scan, Triage, Remediate, Document to survive
SIEM integration collecting every trace
Ongoing authorization keeps systems in their place
Monitor continuously, never lose the thread
DevSecOps pipeline keeps security fed
[Bridge]
When vulnerabilities surface in the code
We follow the sacred four-step road
First we scan to find what's wrong
Triage quickly, don't take long
Remediate with patches clean
Document everything you've seen
[Verse 3]
SIEM events must flow with correlation rules
Retention requirements keep the data pools
As systems evolve we maintain our stance
Authorization never left to chance
Every change tracked through the gate
Continuous security our mandate
[Chorus]
Continuous ATO, keep the flow alive
Scan, Triage, Remediate, Document to survive
SIEM integration collecting every trace
Ongoing authorization keeps systems in their place
Monitor continuously, never lose the thread
DevSecOps pipeline keeps security fed
[Outro]
Traditional ATO was slow and static
Continuous monitoring automatic
Defense infrastructure delivery
Secured through our activity
21. Regulatory Context (Common)
[Verse 1]
When you're building software systems that need to stay secure
There's a framework of compliance that will keep your data pure
SOC 2 for the service folks, Type One and Type Two
Audits check your controls are working like they're supposed to do
[Chorus]
Six rules to remember, six frameworks to know
SOC, HIPAA, CMMC - watch your business grow
PIPEDA, PCI, ISO - compliance is the way
Learning regulations keeps the hackers at bay
[Verse 2]
Healthcare data's sensitive, so HIPAA takes the lead
HITECH makes it stronger with the breach rules that you need
If you're touching patient records or you're covered by the law
Privacy and security are worth fighting for
[Chorus]
Six rules to remember, six frameworks to know
SOC, HIPAA, CMMC - watch your business grow
PIPEDA, PCI, ISO - compliance is the way
Learning regulations keeps the hackers at bay
[Verse 3]
Defense contractors listen up, CMMC's your guide
NIST eight hundred seventy-one keeps secrets classified
Maturity levels one through three, controls for every tier
Protecting federal information is the mission crystal clear
[Chorus]
Six rules to remember, six frameworks to know
SOC, HIPAA, CMMC - watch your business grow
PIPEDA, PCI, ISO - compliance is the way
Learning regulations keeps the hackers at bay
[Bridge]
North of the border, PIPEDA reigns
Bill C twenty-seven brings new privacy chains
Credit card processing needs PCI DSS
Payment card industry won't accept a mess
[Verse 4]
ISO twenty-seven oh-oh-one's the global standard bearer
Information security management makes your posture fairer
Risk assessment, treatment plans, and continuous review
International recognition when your audit's finally through
[Final Chorus]
Six rules to remember, six frameworks to know
SOC, HIPAA, CMMC - watch your business grow
PIPEDA, PCI, ISO - compliance is the way
Learning regulations keeps the hackers at bay
Regulatory knowledge makes a CISO's day
[Outro]
From interview questions to your first ninety days
Master these six frameworks and you'll earn your compliance praise
22. Standard-Setting Bodies and Process
[Verse 1]
When companies report their books each year
We need the rules to be crystal clear
Three mighty bodies set the stage
Writing standards page by page
IASB works worldwide you see
While FASB serves the US free
And IOSCO watches securities
[Chorus]
Standard setters, making it right
IASB, FASB, IOSCO's might
Due process keeps it fair and true
Exposure drafts and comment periods too
Standard setters, hear the call
Making financial reporting work for all
[Verse 2]
The IASB sits in London town
With fourteen members of renown
From different countries they all come
To make IFRS standards for everyone
The trustees guide them from above
While staff research with care and love
Public interest is their only judge
[Chorus]
Standard setters, making it right
IASB, FASB, IOSCO's might
Due process keeps it fair and true
Exposure drafts and comment periods too
Standard setters, hear the call
Making financial reporting work for all
[Verse 3]
FASB protects investors' needs
Seven members plant the seeds
Of GAAP standards tried and true
Research first, then they review
Comment letters flood their door
Public hearings give us more
Transparency is what they're fighting for
[Bridge]
First they research and analyze
Then exposure drafts arise
Comments come from far and wide
Final standards are our guide
This process takes some time to grow
But quality is what we know
[Chorus]
Standard setters, making it right
IASB, FASB, IOSCO's might
Due process keeps it fair and true
Exposure drafts and comment periods too
Standard setters, hear the call
Making financial reporting work for all
[Verse 4]
IOSCO brings regulators near
To make securities crystal clear
Principles and standards they create
Help global markets communicate
When standards work across each border
Financial chaos turns to order
[Outro]
Three bodies working hand in hand
Making standards across the land
Due process makes the system strong
Financial reporting right not wrong
23. Policies
[Verse 1]
When people join our team each day
We need a guide to show the way
Code of Conduct sets the tone
No competing interests, make it known
Behavioral expectations clear
Protect what we hold dear
[Chorus]
Five policies to keep us strong
Code and Whistle, Use along
Performance paired with no retaliation
Building trust across the nation
Map your risks, control the flow
These five policies help us grow
[Verse 2]
Whistleblower channels must be clear
Internal first, then external here
To regulators, law enforcement too
Not unauthorized leaking, that won't do
Protected disclosure, credible and true
Accessible reporting channels for you
[Chorus]
Five policies to keep us strong
Code and Whistle, Use along
Performance paired with no retaliation
Building trust across the nation
Map your risks, control the flow
These five policies help us grow
[Verse 3]
Acceptable Use draws the line
Company resources must align
No competing organizations here
No foreign governments, make it clear
No activist causes that conflict inside
Our interests must be our guide
[Bridge]
Performance Management, fair and documented
Process improvement, never tormented
Discipline and termination with care
Reduces grievance when treatment is fair
Anti-Retaliation protects the brave
Good faith concerns, their jobs we save
[Chorus]
Five policies to keep us strong
Code and Whistle, Use along
Performance paired with no retaliation
Building trust across the nation
Map your risks, control the flow
These five policies help us grow
[Outro]
Human leverage risks controlled
Through policies worth their weight in gold
When grievances might escalate
These five policies seal our fate
Back to Home