By Maril Vernon, Field CISO, Anecdotes
I spent years on the offensive side of security performing red and purple team assessments, bypassing controls that GRC teams, and often times even auditors, were convinced were working.
Spoiler: it was rarely as difficult as it should have been. Not because those teams were careless, but because they were measured against a system that rewarded proving a control existed at one moment in time, not whether it would still hold up operationally on some random Tuesday six months after the audit.
FedRAMP Rev5 was built around that model. Organizations described how controls were implemented, mapped those narratives to NIST 800-53, and supported them with carefully curated evidence.
Assessors then sampled that evidence annually to determine whether the implementation matched the documentation. But, if you've ever participated in an audit then you know how much room that leaves to manage scope and narrative. And if you've ever been a pentester, you know that's exactly where to start looking.






