Code Repository that's NIST 800-53 compliant

Posted on 2011-10-17
Last Modified: 2013-11-13
For code repositories, I've been a user of first, CVS, and then SVN for the past 6 years.  Because it's open source, my company needs to replace it with a code repository that is NIST 800-53 compliant.  Does anyone have any suggestions?  I know anything from Microsoft meets NIST standards but I'm not a fan of using Microsoft for everything.


Question by:mjfagan
    LVL 8

    Expert Comment

    You might check Perforce ( or Mercurial (  Neither website mentions NIST compliance, however.
    LVL 6

    Author Comment

    Thanks for the response.  Mecurial isn't considered NIST compliant because of it being open source.  In doing research, I hadn't stumbled across Perforce--do you use it?
    LVL 8

    Accepted Solution

    I have used Perforce, but only a little.  One of my clients used it for their SCM. It appeared to be a good quality package. I've talked with Perforce reps at trade shows and they seem knowledgeable.  It does use a different terminology than I am used to, so there was a bit of a learning curve.

    I'm not familiar with NIST 800-53 (and Wikipedia is not very enlightening).  I would be disappointed to hear that open source programs are, by definition, not compliant.  Proprietary does not equate to better quality or more secure.  
    LVL 6

    Author Comment

    My company is still learning all of the NIST rules.  I probably should have worded my question differently and asked what federal contractors are using.

    I'm disappointed that open source programs aren't compliant either but from what I understand, it's because of going through the code review per NIST, etc.  I'm not 100% that's the reason but that's what I've been able to gather.  I love using Subversion, would prefer to move to GIT, but those aren't options.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Suggested Solutions

    Title # Comments Views Activity
    Problem to adjust sheet 1 78
    scoresClump  challenge 31 85
    wordsWithout 49 64
    java  and programming certification ? 4 27
    Communication between departments might not happen in two different languages, but they do exist in two different worlds. With different targets and performance goals the same phrase often means something completely different to each party. Learn ho…
    "Disruption" is the most feared word for C-level executives these days. They agonize over their industry being disturbed by another player - most likely by startups.
    This tutorial will introduce the viewer to VisualVM for the Java platform application. This video explains an example program and covers the Overview, Monitor, and Heap Dump tabs.
    In this fourth video of the Xpdf series, we discuss and demonstrate the PDFinfo utility, which retrieves the contents of a PDF's Info Dictionary, as well as some other information, including the page count. We show how to isolate the page count in a…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now