NIST SP 800-53 Rev 5 · FIPS 199 · RMF

The GRC platform built for
small and medium enterprises

RiskCanvas gives growing companies a complete compliance workbench — NIST control tracking, BIA assessments, STRIDE threat modeling, policy management, and continuous authorization. Enterprise-grade GRC without an enterprise-sized team.

Aligned with FFIEC · OCC · NCUA · NIST · PCI DSS · HIPAA · GDPR

1,196

NIST Controls

SP 800-53 Rev 5

20

Control Families

AC · AU · CM · IA · SC…

7

RMF Steps

Full lifecycle

6

STRIDE Categories

AI-augmented

Platform capabilities

Every tool your compliance team needs

Six integrated modules covering the full GRC lifecycle — from initial assessment through continuous authorization.

NIST SP 800-53 Rev 5

Control Canvas

An interactive workspace for all 1,196 controls across 20 families. Track implementation status, assign owners, and upload evidence — all in one place.

Open Control Canvas
  • 20 control families
  • 1,196 controls tracked
  • Bulk status updates
  • Evidence attachments

NIST Risk Management Framework

The full RMF lifecycle, in one platform

Every step from SP 800-37 is supported end-to-end. No more spreadsheet handoffs between teams.

01

Prepare

Define roles, risk tolerance, and system boundaries before categorization begins.

02

Categorize

FIPS 199 CIA impact assessment — Low, Moderate, or High for each information system.

03

Select

Choose the right baseline controls (800-53 Low / Moderate / High) and tailor as needed.

04

Implement

Track control implementation across teams with canvas workspaces and evidence uploads.

05

Assess

Evaluate control effectiveness against documented objectives and test procedures.

06

Authorize

Generate ATO packages from collected evidence and risk-acceptance decisions.

07

Monitor

Continuous monitoring, change management, and ongoing authorization status.

Categorize → Select

BIA Assessments

FIPS 199 CIA ratings automatically determine your 800-53 baseline.

Implement → Assess

Control Canvas

Track every control from selection through evidence-backed implementation.

Assess → Authorize

Policy Management

Policy artifacts linked to controls feed directly into ATO packages.

Monitor (Continuous)

STRIDE Threat Model

Ongoing threat analysis keeps risk posture current between authorization cycles.

Security Architecture

Hard isolation between every organization

RiskCanvas enforces org_id scoping at the database query boundary — not at the application UI level. Every row in every table is tagged and filtered server-side. No configuration mistake can leak one tenant's data to another.

  • Row-level org_id isolation

    Every query adds AND org_id = $n. Cross-tenant reads are structurally impossible.

  • Role-based member access

    org_admin, analyst, and viewer roles enforced at the API layer for every org.

  • Admin audit visibility

    GRC admins see aggregate stats across tenants but cannot access member data.

  • Policy and evidence isolation

    Policies, assessments, and evidence are always scoped to a single organization.

org-isolation.sql

-- Every policy query is org-scoped

SELECT p.id, p.name, p.status

FROM policies p

JOIN org_members om

ON om.org_id = p.org_id

AND om.user_id = $userId

WHERE p.org_id = $orgId;

-- Admin sees stats, not member data

SELECT COUNT(DISTINCT o.id)

FROM organizations o

-- no member-level data exposed

Target market

Built for small and medium enterprises

Whether you're facing your first SOC 2 audit or maturing an established program, RiskCanvas scales to the size of your team — not the other way round.

Lean GRC & Security Teams

Built for the one-person security function. The whole lifecycle — categorize, select, implement, assess, authorize, monitor — in a single workbench instead of a folder of spreadsheets.

Companies Facing First Audit

SOC 2, ISO 27001 and PCI DSS control mapping built in. Start from a tailored baseline rather than a blank document, and produce evidence packages auditors accept.

SaaS & Technology Firms

Threat modeling purpose-built for API-heavy, internet-facing architectures. Controls are tailored to the threats your design actually presents.

Regulated & Financial Services

FFIEC, GLBA and NCUA expectations addressed end-to-end for firms that need them. Customer data is isolated at the database level with no cross-tenant leakage.

Framework coverage

NIST SP 800-53 Rev 5FedRAMP LowFedRAMP ModerateFedRAMP HighPCI DSSHIPAAGDPRSOC 2ISO 27001
Compliance gaps are a regulatory liability

Start building your compliance program today

Get your NIST control canvas, BIA assessments, and STRIDE threat model running in minutes. No professional services required.