ISACA Podcast: Why You Should Use the F Word More

ISACA Podcast: Why You Should Use the F Word More

Source: YouTube · ISACA HQ · published Jun 30, 2026 · 23:47

Compliance & GRC
No ratings yet Log in to rate
Transcript Available
Description

FedRAMP 20X represents a fundamental shift from broken, point-in-time compliance to a continuous, data-driven model that builds real trust 5:30-5:53.

Key Takeaways:
• Traditional compliance is broken because it relies on static screenshots, limited samples, and curated narratives that fail to reflect actual security postures 2:29-3:18.
• FedRAMP 20X, championed by Pete Waterman, treats compliance as an engineering problem by automating 80% of controls and requiring continuous, API-driven JSON data ingestion instead of documents 8:48-9:14.
• The new framework eliminates the traditional Catch-22 by removing the government sponsor requirement and reducing costs from $2-5 million to roughly $100-200K 7:01-7:58.
• Key Security Indicators (KSIs) provide automated, real-time validation of controls—like secure dev environments—offering far more assurance than signed policy documents 12:58-14:04.
• The future of all compliance (SOC 2, ISO, HIPAA) lies in full data transparency via API-connected trust centers, moving beyond boolean pass/fail checks to complete dataset analysis 20:42-21:27.

FedRAMP 20X's data-first approach is poised to revolutionize how organizations build trust, and security leaders should begin gap analyses now before the anticipated flood of public applications.

Sources:

  • 2:29-3:18 Why traditional compliance relies on fake reality and samples
  • 5:30-5:53 FedRAMP 20X's goal of continuous real-time data assessment
  • 7:01-7:58 Traditional FedRAMP's cost and catch-22 barriers
  • 8:48-9:14 Pete Waterman's view of compliance as an engineering problem
  • 12:58-14:04 KSIs and automated validation vs. traditional documentation
  • 20:42-21:27 The future of compliance: full data sets and API trust centers

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Anecdotes is the leading enterprise agentic GRC platform built for organizations that refuse to compromise. With comprehensive solutions across governance, [music] risk, and compliance, deep customization capabilities, and AI agents that run on an audit-grade data infrastructure, >> [music] >> Anecdotes enables the world's top enterprises to manage GRC programs as unique as their businesses. You can learn more about our efforts at www.anecdotes.ai. [music] >> [music] [music] >> You're listening to the ISACA podcast. This episode is sponsored by Anecdotes. I'm excited today to be joined by Jake Bernardis, who's CISO at Anecdotes. So, a few weeks ago, you presented a session titled "You Should Use the F Word More" at the ISACA North America Conference. You were talking about FedRAMP 20X. One…