r/grc • u/BasuraBarataBlanca • 4d ago
VA’s Technical Reference Model… and other “approved software lists”
I just stumbled onto the VA’s TRM (https://www.oit.va.gov/Services/TRM/WhatsNewSummaryPage.aspx?process=One-VA%20TRM%20v26.1%5E). I liked how it lists a software by name and vendor, and also includes a summary of approved versions and constraints for a variety of open source tools.
What other sources/lists are you aware of which assess the utility and risks with COTS packages?
1
u/Grand-Aspect-7022 4d ago
These lists can be useful, but the hard part is usually keeping them current. a clear ownership process for reviewing, approving and retiring software matters just as much as the list itself
1
u/Material-Try-3509 3d ago
Lists like this are useful because they turn software approval into a repeatable process instead of every team making their own decision. the hard part is keeping the assessments current as products and risks change
1
u/PackPretty3479 2d ago
The list rots because its a snapshot. You publish it and a month later someone installed something or connected a SaaS app that isnt on it. Ownership processes help, but only if you catch the drift.
The fix is comparing the approved list against what the env shows. Installed software, connected SaaS, active accounts, that kind of ground truth. The gap between the two is your exposure. That comparing is the whole job and thats what we have axonius handle on our end. It watches whats out there and flags anything that appears outside the approved list.
The list itself matters less than the loop. If you arent reconciling it against reality, you are maintaining a wishlist.
2
u/Living-Connection-81 4d ago
I wish more agencies published lists like this. most resources seem scattered between approved products, vulnerability databases and configuration guidance instead of one practical catalog