GovReady/security-stories-nist800-53

AT

Closed this issue · 1 comments

jlyon commented
  • Combined AT-1 AT-2 AT-3 into one story

Question:

  • Does it make sense to combine these into one story?

Let's try keeping AT-1 distinct and combining AT-2 and AT-3.

Each control family starts with XX-1 which is "polices and procedures." Symmetry would make sense. Also, the organization should have policies in place for each family already and the evidence for most projects should be pointing the org's existing policy.