Is there a way to get "official answer/clarification" about some of the nist controls ?
I seems to have a bit of disagreement with fedramp pmo/advisors and look for "ultimate authority" for interpretation of controls
(control in question was discussed in this subreddit, and based on the discussion my interpretation is correct. but as I am unable to point to here as to official source of wisdom, i look for other possibilities)
[link] [comments]