Understanding Implementation Status

GRC compliance image - Continuum GRC solutions for cyber security and audit AI-powered cybersecurity 2025 zero trust ransomware protection supply chain security regulatory compliance operational resilience
0

The following image of an Implementation Status field within the Continuum GRC ITAM modules common to all NIST-based frameworks such as FedRAMP, StateRAMP, NIST 800-53, DFARS NIST 800-171, CJIS, HIPAA NIST 800-66, and many more.

The purpose of this field is to document the current implementation of the specific control requirement. In this case, it is specifically FedRAMP AC-2. The standard choices are the same throughout the families of NIST system security plan (SSP) templates.

Options include:

  • Implemented: The boundary in scope system control requirement is fully implemented and operational.
  • Partially Implemented: The boundary in scope system control requirement is only partially implemented or operational.
  • Planned: The boundary in scope system control requirement is not yet implemented or operational because it is still in the planning phase of system development.
  • Alternative Implementation: This is sometimes also referred to as a Compensating Control, meaning that the boundary in scope system control implementation is satisfied using an alternative solution, such as a reliance on an external solution.
  • Not Applicable: In rare instances, the boundary in scope system control requirement cannot be fulfilled due to a technical limitation (ONLY) that cannot be tested.

You may have already noticed that the instructions require you to select (check all that apply) which may seem nonsensical. How can a system be both Implemented and Not Applicable? Is this Schrödinger’s SaaS?

You must look at a control implementation as a collection of parts assembled to create a system. Parts of that system may be fully implemented, but other parts are still in various stages of implementation. 

Michael Peters

Website:

Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015. A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA. Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.