Secure Talk podcast | by Strike Graph

NIST's Victoria Yan Pillitteri: "Compliance Won't Save You". Inside NIST 800-171

Written by Strike Graph Team | Sep 22, 2026, 3:23:35 PM

She helps write the rules the entire U.S. defense industrial base gets assessed against — and she's telling you compliance is the floor, not the finish line.
Victoria Yan Pillitteri leads the Risk Management Framework/FISMA team at NIST and co-chairs the Joint Task Force uniting DoD, the Intelligence Community, and civilian agencies on one cybersecurity framework. In this episode, she and Justin Beals go inside how NIST actually builds SP 800-53 and 800-171 — what gets cut, what stays, and why "just copy the control language" is a losing strategy for anyone trying to pass an assessment.

In this episode:
Why 853 is "the Cheesecake Factory menu" of cybersecurity controls — and why that's a feature, not a bug
The real difference between NIST 800-171 Rev 2 and Rev 3, and why "organization-defined parameters" changed everything
Why writing your own control (not just quoting NIST's language) is the only way to actually pass an assessment
How FedRAMP 20x, OSCAL, and continuous monitoring are quietly replacing the point-in-time ATO
NIST's upcoming AI control overlays for predictive, generative, and agentic AI systems

Chapters:
00:00 Introduction
00:34 The purpose of NIST standards and measurement science
02:24 Cybersecurity outcomes as a Rosetta Stone
03:14 The challenge of measuring risk in cybersecurity
04:55 Frameworks as operating systems for risk management
06:58 The iterative process of developing cybersecurity standards
08:11 Interpreting control statements for organizations
09:36 The importance of tailoring controls to risk profiles
12:30 The relationship between compliance and good risk management
14:37 The development process of cybersecurity standards
17:27 Differences between Rev2 and Rev3 of NIST 800-171
20:01 Broad versus specific requirements in cybersecurity controls
22:36 Supporting small businesses with guidance and tools
27:23 The balance between prescriptive and flexible standards
30:24 Cybersecurity in public-private partnerships
34:53 Moving from point-in-time to continuous authorization
40:23 AI risks and the development of tailored controls
44:53 The future of cybersecurity standards and AI security

Resources referenced:
NIST SP 800-53 (Security and Privacy Controls) 
NIST SP 800-171 Rev 2 & Rev. 3 (Protecting CUI) 
NIST Risk Management Framework 
NIST Cybersecurity Framework
NIST AI Risk Management Framework 
FedRAMP 20x Program 
OSCAL (Open Security Controls Assessment Language)