
ISACA Podcast: Why You Should Use the F Word More
Source: YouTube · ISACA HQ · published Jun 30, 2026 · 23:47
FedRAMP 20X represents a fundamental shift from broken, point-in-time compliance to a continuous, data-driven model that builds real trust 5:30-5:53.
Key Takeaways:
• Traditional compliance is broken because it relies on static screenshots, limited samples, and curated narratives that fail to reflect actual security postures 2:29-3:18.
• FedRAMP 20X, championed by Pete Waterman, treats compliance as an engineering problem by automating 80% of controls and requiring continuous, API-driven JSON data ingestion instead of documents 8:48-9:14.
• The new framework eliminates the traditional Catch-22 by removing the government sponsor requirement and reducing costs from $2-5 million to roughly $100-200K 7:01-7:58.
• Key Security Indicators (KSIs) provide automated, real-time validation of controls—like secure dev environments—offering far more assurance than signed policy documents 12:58-14:04.
• The future of all compliance (SOC 2, ISO, HIPAA) lies in full data transparency via API-connected trust centers, moving beyond boolean pass/fail checks to complete dataset analysis 20:42-21:27.
FedRAMP 20X's data-first approach is poised to revolutionize how organizations build trust, and security leaders should begin gap analyses now before the anticipated flood of public applications.
Sources:
- 2:29-3:18 Why traditional compliance relies on fake reality and samples
- 5:30-5:53 FedRAMP 20X's goal of continuous real-time data assessment
- 7:01-7:58 Traditional FedRAMP's cost and catch-22 barriers
- 8:48-9:14 Pete Waterman's view of compliance as an engineering problem
- 12:58-14:04 KSIs and automated validation vs. traditional documentation
- 20:42-21:27 The future of compliance: full data sets and API trust centers
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Anecdotes is the leading enterprise agentic GRC platform built for organizations that refuse to compromise. With comprehensive solutions across governance, [music] risk, and compliance, deep customization capabilities, and AI agents that run on an audit-grade data infrastructure, >> [music] >> Anecdotes enables the world's top enterprises to manage GRC programs as unique as their businesses. You can learn more about our efforts at www.anecdotes.ai. [music] >> [music] [music] >> You're listening to the ISACA podcast. This episode is sponsored by Anecdotes. I'm excited today to be joined by Jake Bernardis, who's CISO at Anecdotes. So, a few weeks ago, you presented a session titled "You Should Use the F Word More" at the ISACA North America Conference. You were talking about FedRAMP 20X. One…