Framework overlap

Does AICPA Privacy Management Framework (PMF) cover NIST SP 800-53 Rev 5?

You hold AICPA Privacy Management Framework (PMF) and have been told to do NIST SP 800-53 Rev 5. Here is how much overlaps, control by control.

26% of NIST SP 800-53 Rev 5 you already have

AICPA Privacy Management Framework (PMF) already covers about 26% of NIST SP 800-53 Rev 5, leaving 143 of 192 controls as genuinely new work.

Already covered 8 Likely covered 41 New work 143

What is genuinely new work

Nothing in AICPA Privacy Management Framework (PMF) reaches these. This is the list to scope.

NIST800-AC-1
Access control policy and procedures
NIST800-AC-11
Device lock
NIST800-AC-12
Session control
NIST800-AC-14
Permitted actions without identification or authentication
NIST800-AC-18
Wireless access
NIST800-AC-19
Access control for mobile devices
NIST800-AC-22
Publicly accessible content
NIST800-AC-4
Information flow enforcement
NIST800-AC-5
Separation of duties
NIST800-AT-1
Policy and procedures for awareness and training
NIST800-AT-2
Literacy training and awareness
NIST800-AT-4
Training records
NIST800-AT-6
Training feedback
NIST800-AU-1
Policy and procedures for audit and accountability
NIST800-AU-11
Audit record retention
NIST800-AU-4
Audit log storage capacity
NIST800-AU-5
Response to audit logging process failures
NIST800-AU-6
Audit record review, analysis, and reporting
NIST800-AU-7
Audit record reduction and report generation
NIST800-AU-8
Time stamps
NIST800-AU-9
Protection of audit information
NIST800-CA-1
Policy and procedures for assessment, authorization, and monitoring
NIST800-CA-3
Information exchange
NIST800-CA-5
Plan of action and milestones
NIST800-CA-6
Authorization
NIST800-CA-9
Internal system connections
NIST800-CM-1
Policy and procedures for configuration management
NIST800-CM-10
Software usage restrictions
NIST800-CM-11
User-installed software
NIST800-CM-2
Baseline configuration
NIST800-CM-5
Access restrictions for change
NIST800-CM-6
Configuration settings
NIST800-CM-7
Least functionality
NIST800-CM-8
System component inventory
NIST800-CP-1
Policy and procedures for contingency planning
NIST800-CP-2
Contingency plan
NIST800-CP-3
Contingency training
NIST800-CP-4
Contingency plan testing
NIST800-CP-6
Alternate storage site
NIST800-CP-7
Alternate processing site
NIST800-IA-1
Policy and procedures for identification and authentication
NIST800-IA-11
Re-authentication
NIST800-IA-12
Identity proofing
NIST800-IA-2
Identification and authentication of organizational users
NIST800-IA-3
Device identification and authentication
NIST800-IA-5
Authenticator management
NIST800-IA-6
Authentication feedback
NIST800-IR-1
Policy and procedures for incident response
NIST800-IR-3
Incident response testing
NIST800-IR-8
Incident response plan
NIST800-MA-1
Policy and procedures for maintenance
NIST800-MA-2
Controlled maintenance
NIST800-MA-3
Maintenance tools
NIST800-MA-4
Nonlocal maintenance
NIST800-MA-5
Maintenance personnel
NIST800-MP-1
Policy and procedures for media protection
NIST800-MP-2
Media access
NIST800-MP-3
Media marking
NIST800-MP-4
Media storage
NIST800-MP-5
Media transport
NIST800-MP-6
Media sanitization
NIST800-MP-7
Media use
NIST800-PE-1
Policy and procedures for physical and environmental protection
NIST800-PE-10
Emergency shutoff
NIST800-PE-11
Emergency power
NIST800-PE-12
Emergency lighting
NIST800-PE-13
Fire protection
NIST800-PE-15
Water damage protection
NIST800-PE-17
Alternate work site
NIST800-PE-4
Access control for transmission
NIST800-PE-5
Access control for output devices
NIST800-PE-6
Monitoring physical access
NIST800-PE-8
Visitor access records
NIST800-PE-9
Power equipment and cabling
NIST800-PL-1
Policy and procedures for planning
NIST800-PL-10
Baseline selection
NIST800-PL-11
Baseline tailoring
NIST800-PL-2
System security and privacy plans
NIST800-PL-4
Rules of behavior
NIST800-PS-2
Position risk designation
NIST800-PS-4
Personnel termination
NIST800-PS-5
Personnel transfer
NIST800-PS-6
Access agreements
NIST800-PS-7
External personnel security
NIST800-PS-9
Position descriptions
NIST800-RA-10
Threat hunting
NIST800-RA-7
Risk response
NIST800-RA-9
Criticality analysis
NIST800-SA-1
Policy and procedures for system and services acquisition
NIST800-SA-15
Development process, standards, and tools
NIST800-SA-2
Allocation of resources
NIST800-SA-22
Developer security and privacy architecture
NIST800-SA-3
System development life cycle
NIST800-SA-4
Acquisition process
NIST800-SA-5
System documentation
NIST800-SA-9
External system services
NIST800-SC-1
Policy and procedures for system and communications protection
NIST800-SC-10
Network disconnect
NIST800-SC-15
Collaborative computing devices and applications
NIST800-SC-17
Public key infrastructure certificates
NIST800-SC-2
Separation of system and user functionality
NIST800-SC-20
Secure name/address resolution service
NIST800-SC-21
Secure name/address resolution service (recursive)
NIST800-SC-23
Session authenticity
NIST800-SC-39
Process isolation
NIST800-SC-4
Information in shared system resources
NIST800-SC-5
Denial-of-service protection
NIST800-SC-7
Boundary protection
NIST800-SC-8
Transmission confidentiality and integrity
NIST800-SI-1
Policy and procedures for system and information integrity
NIST800-SI-10
Information input validation
NIST800-SI-12
Information management and retention
NIST800-SI-16
Memory protection
NIST800-SI-3
Malicious code protection
NIST800-SI-4
System monitoring
NIST800-SI-5
Security alerts, advisories, and directives
NIST800-SI-7
Software, firmware, and information integrity
NIST800-SR-1
Policy and procedures for supply chain risk management
NIST800-SR-10
Inspection of systems or components
NIST800-SR-12
Component disposal
NIST800-SR-2
Supply chain risk management plan
NIST800-SR-5
Acquisition strategies, tools, and methods
NIST800-SR-6
Supplier assessments and reviews
SP800-53-AC
Access Control Family
SP800-53-AT
Awareness and Training Family
SP800-53-AU
Audit and Accountability Family
SP800-53-CA
Assessment, Authorization, and Monitoring Family
SP800-53-CM
Configuration Management Family
SP800-53-CP
Contingency Planning Family
SP800-53-IA
Identification and Authentication Family
SP800-53-IR
Incident Response Family
SP800-53-MA
Maintenance Family
SP800-53-MP
Media Protection Family
SP800-53-PE
Physical and Environmental Protection Family
SP800-53-PL
Planning Family
SP800-53-PM
Program Management Family
SP800-53-PS
Personnel Security Family
SP800-53-PT
PII Processing and Transparency Family
SP800-53-RA
Risk Assessment Family
SP800-53-SA
System and Services Acquisition Family
SP800-53-SC
System and Communications Protection Family
SP800-53-SI
System and Information Integrity Family
SP800-53-SR
Supply Chain Risk Management Family
Show the 49 you already have
NIST800-CA-8
Penetration testing
NIST800-IR-2
Incident response training
NIST800-IR-5
Incident monitoring
NIST800-IR-7
Incident response assistance
NIST800-RA-1
Policy and procedures for risk assessment
NIST800-RA-2
Security categorization
NIST800-RA-5
Vulnerability monitoring and scanning
NIST800-SI-2
Flaw remediation
NIST800-AC-17
Remote access
NIST800-AC-2
Account management
NIST800-AC-20
Use of external systems
NIST800-AC-3
Access enforcement
NIST800-AC-6
Least privilege
NIST800-AC-7
Unsuccessful logon attempts
NIST800-AT-3
Role-based training
NIST800-AU-12
Audit record generation
NIST800-AU-2
Event logging
NIST800-AU-3
Content of audit records
NIST800-CA-2
Control assessments
NIST800-CA-7
Continuous monitoring
NIST800-CM-3
Configuration change control
NIST800-CM-4
Impact analyses
NIST800-CM-9
Configuration management plan
NIST800-CP-10
System recovery and reconstitution
NIST800-CP-8
Telecommunications services
NIST800-CP-9
System backup
NIST800-IA-4
Identifier management
NIST800-IA-7
Cryptographic module authentication
NIST800-IA-8
Identification and authentication of non-organizational users
NIST800-IR-4
Incident handling
NIST800-IR-6
Incident reporting
NIST800-PE-14
Environmental controls
NIST800-PE-2
Physical access authorizations
NIST800-PE-3
Physical access control
NIST800-PL-8
Security and privacy architectures
NIST800-PS-1
Policy and procedures for personnel security
NIST800-PS-3
Personnel screening
NIST800-PS-8
Personnel sanctions
NIST800-RA-3
Risk assessment
NIST800-SA-10
Developer configuration management
NIST800-SA-11
Developer testing and evaluation
NIST800-SA-8
Security and privacy engineering principles
NIST800-SC-12
Cryptographic key establishment and management
NIST800-SC-13
Cryptographic protection
NIST800-SC-22
Architecture and provisioning for name/address resolution service
NIST800-SC-28
Protection of information at rest
NIST800-SR-11
Component authenticity
NIST800-SR-3
Supply chain controls and processes
NIST800-SR-8
Notification agreements

How this is calculated

Already covered means a mapping runs from a control in AICPA Privacy Management Framework (PMF) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition