Back to: Understanding Implementation Status
The following image of an Implementation Status field within the Continuum GRC ITAM modules common to all NIST-based frameworks such as FedRAMP, StateRAMP, NIST 800-53, DFARS NIST 800-171, CJIS, HIPAA NIST 800-66, and many more.

The purpose of this field is to document the current implementation of the specific control requirement. In this case, it is specifically FedRAMP AC-2. The standard choices are the same throughout the families of NIST system security plan (SSP) templates.
Options include:
- Implemented: The boundary in scope system control requirement is fully implemented and operational.
- Partially Implemented: The boundary in scope system control requirement is only partially implemented or operational.
- Planned: The boundary in scope system control requirement is not yet implemented or operational because it is still in the planning phase of system development.
- Alternative Implementation: This is sometimes also referred to as a Compensating Control, meaning that the boundary in scope system control implementation is satisfied using an alternative solution, such as a reliance on an external solution.
- Not Applicable: In rare instances, the boundary in scope system control requirement cannot be fulfilled due to a technical limitation (ONLY) that cannot be tested.
You may have already noticed that the instructions require you to select (check all that apply) which may seem nonsensical. How can a system be both Implemented and Not Applicable? Is this Schrödinger’s SaaS?
You must look at a control implementation as a collection of parts assembled to create a system. Parts of that system may be fully implemented, but other parts are still in various stages of implementation.




Related Posts