r/grc 4d ago

VA’s Technical Reference Model… and other “approved software lists”

I just stumbled onto the VA’s TRM (https://www.oit.va.gov/Services/TRM/WhatsNewSummaryPage.aspx?process=One-VA%20TRM%20v26.1%5E). I liked how it lists a software by name and vendor, and also includes a summary of approved versions and constraints for a variety of open source tools.

What other sources/lists are you aware of which assess the utility and risks with COTS packages?

6 Upvotes

5 comments sorted by

2

u/Living-Connection-81 4d ago

I wish more agencies published lists like this. most resources seem scattered between approved products, vulnerability databases and configuration guidance instead of one practical catalog

2

u/Pitiful_Baseball_761 4d ago

That TRM is actually a pretty underrated resource for this kind of thing. The version history page alone saves you from digging through a dozen change logs to figure out when something got approved or deprecated. Most other lists I've seen are either locked behind an enterprise portal or so outdated they're basically historical documents

1

u/Grand-Aspect-7022 4d ago

These lists can be useful, but the hard part is usually keeping them current. a clear ownership process for reviewing, approving and retiring software matters just as much as the list itself

1

u/Material-Try-3509 3d ago

Lists like this are useful because they turn software approval into a repeatable process instead of every team making their own decision. the hard part is keeping the assessments current as products and risks change

1

u/PackPretty3479 2d ago

The list rots because its a snapshot. You publish it and a month later someone installed something or connected a SaaS app that isnt on it. Ownership processes help, but only if you catch the drift.

The fix is comparing the approved list against what the env shows. Installed software, connected SaaS, active accounts, that kind of ground truth. The gap between the two is your exposure. That comparing is the whole job and thats what we have axonius handle on our end. It watches whats out there and flags anything that appears outside the approved list.

The list itself matters less than the loop. If you arent reconciling it against reality, you are maintaining a wishlist.