In 2023 IRIS Connect won a contract with the US government agency: HHS (Dept Health and Human Services), Administration for Children and Families (ACF), Office of Head Start (OHS). As part of the federal requirements, IRIS Connect has implemented 300 tailored NIST security controls as required for a FIPS 199 categorization of moderate, based on the US government's classification of data they would be uploading to IRIS Connect.
The security controls are from the NIST Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations. The National Institute of Standards and Technology (NIST) Special Publication 800-53 is a set of recommended security and privacy controls for information systems and organizations to help meet the US government's Federal Information Security Management Act (FISMA) requirements.
NIST controls cover 20 areas as shown in Table 1