![]() |
Secure Talk PodcastSecure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Author: Justin Beals
Secure Talk reviews the latest threats, tips, and trends on security, innovation, and compliance. Host Justin Beals interviews leading privacy, security and technology executives to discuss best practices related to IT security, data protection and compliance. Based in Seattle, he previously served as the CTO of NextStep and Koru, which won the 2018 Most Impactful Startup award from Wharton People Analytics. He is the creator of the patented Training, Tracking & Placement System and the author of Aligning curriculum and evidencing learning effectiveness using semantic mapping of learning assets, published in the International Journal of Emerging Technologies in Learning (iJet). Justin earned a BA from Fort Lewis College. Language: en Genres: News, Tech News, Technology Contact email: Get it Feed URL: Get it iTunes ID: Get it |
Listen Now...
NIST's Victoria Yan Pillitteri: "Compliance Won't Save You" — Inside NIST 800-171
Episode 261
Tuesday, 22 September, 2026
She helps write the rules the entire U.S. defense industrial base gets assessed against — and she's telling you compliance is the floor, not the finish line.Victoria Yan Pillitteri leads the Risk Management Framework/FISMA team at NIST and co-chairs the Joint Task Force uniting DoD, the Intelligence Community, and civilian agencies on one cybersecurity framework. In this episode, she and Justin Beals go inside how NIST actually builds SP 800-53 and 800-171 — what gets cut, what stays, and why "just copy the control language" is a losing strategy for anyone trying to pass an assessment.In this episode:Why 853 is "the Cheesecake Factory menu" of cybersecurity controls — and why that's a feature, not a bugThe real difference between NIST 800-171 Rev 2 and Rev 3, and why "organization-defined parameters" changed everythingWhy writing your own control (not just quoting NIST's language) is the only way to actually pass an assessmentHow FedRAMP 20x, OSCAL, and continuous monitoring are quietly replacing the point-in-time ATONIST's upcoming AI control overlays for predictive, generative, and agentic AI systemsChapters00:00 Introduction00:34 The purpose of NIST standards and measurement science02:24 Cybersecurity outcomes as a Rosetta Stone03:14 The challenge of measuring risk in cybersecurity04:55 Frameworks as operating systems for risk management06:58 The iterative process of developing cybersecurity standards08:11 Interpreting control statements for organizations09:36 The importance of tailoring controls to risk profiles12:30 The relationship between compliance and good risk management14:37 The development process of cybersecurity standards17:27 Differences between Rev2 and Rev3 of NIST 800-17120:01 Broad versus specific requirements in cybersecurity controls22:36 Supporting small businesses with guidance and tools27:23 The balance between prescriptive and flexible standards30:24 Cybersecurity in public-private partnerships34:53 Moving from point-in-time to continuous authorization40:23 AI risks and the development of tailored controls44:53 The future of cybersecurity standards and AI securityResources referenced:NIST SP 800-53 (Security and Privacy Controls) — [link]NIST SP 800-171 Rev 2 & Rev 3 (Protecting CUI) — [link]NIST Risk Management Framework — [link]NIST Cybersecurity Framework — [link]NIST AI Risk Management Framework — [link]FedRAMP 20x Program — [link]OSCAL (Open Security Controls Assessment Language) — [link]#NIST80053 #NIST800171 #CMMC #FedRAMP #CyberCompliance #RiskManagement #CUI #SecureTalk












