In response to questions about the standard, Information Security and Policy has published multiple clarifying updates to the standard as well as guidelines that include several important exceptions.
Topics addressed include:
Encryption in Transit
Definition of Privileged Access Devices
Inventory and Registration
Because the updates clarify the original intent of the requirements and do not impose additional requirements (in some cases the changes are more lenient than the original) the changes are effective immediately.
Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet. This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.