16% of NIST SP 800-171 you already have
API 1164 already covers about 16% of NIST SP 800-171, leaving
78 of 93 controls as genuinely new work.
Already covered 1
Likely covered 14
New work 78
What is genuinely new work
Nothing in API 1164 reaches these. This is the list to scope.
171-AC-2Least Privilege and Separation of Duties
171-AC-3Remote Access and Mobile Devices
171-AT-1Security Awareness and Role-Based Training
171-AU-1Audit Event Capture
171-AU-2Audit Review and Analysis
171-CM-1Baseline Configuration and Inventory
171-IA-1Identification and Authentication
171-IA-2Multi-Factor Authentication
171-IR-1Incident Handling Capability
171-IR-2Incident Reporting
171-MA-1Maintenance Authorisation and Control
171-PE-1Physical Access Authorisations
171-RA-2Vulnerability Scanning and Remediation
171-SC-1Boundary Protection
171-SC-2Encryption of Controlled Unclassified Information
171-SI-2Malicious Code Protection
3.1.1Authorized Access Control
3.1.2Transaction and Function Control
3.1.20External Connections Control
3.10.6Alternate Work Site Safeguards
3.11.2Vulnerability Scanning
3.12.1Security Control Assessment
3.13.11Cryptographic Protection
3.13.5Network Segmentation
3.13.8Transmission Confidentiality
3.14.6Monitoring for Attacks
3.4.1Baseline Configuration Maintenance
3.5.3Multi Factor Authentication
3.9.2Personnel Transfer and Termination
A.03.01.01Account Management Assessment
A.03.01.05Least Privilege Assessment
A.03.01.12Remote Access Assessment
A.03.03.01Event Logging Assessment
A.03.04.01Baseline Configuration Assessment
A.03.04.02Configuration Settings Assessment
A.03.05.03Multi Factor Authentication Assessment
A.03.06.01Incident Handling Assessment
A.03.07.04Maintenance Tools Assessment
A.03.08.03Media Sanitization Assessment
A.03.09.02Personnel Termination Assessment
A.03.10.01Physical Access Authorization Assessment
A.03.11.01Risk Assessment Process
A.03.11.02Vulnerability Monitoring Assessment
A.03.12.01Security Control Assessments
A.03.13.11Cryptographic Protection of CUI at Rest
A.03.14.01Flaw Remediation Assessment
A.03.14.06System Monitoring Assessment
A.03.15.01System Security Plan Assessment
SP800-171-3.10.6Safeguard CUI at alternate work sites
SP800-171-3.12.1Periodically assess security controls
SP800-171-3.12.2Plans of action for deficiencies
SP800-171-3.13.11Employ FIPS-validated cryptography
SP800-171-3.13.16Protect confidentiality of CUI at rest
SP800-171-3.13.8Encrypt CUI in transmission
SP800-171-3.14.1Identify, report, and correct flaws
SP800-171-3.14.3Monitor security alerts and advisories
SP800-171-3.14.6Monitor systems and traffic for attacks
SP800-171-3.5.1Identify system users, processes, and devices
SP800-171-3.5.10Store and transmit only encrypted passwords
SP800-171-3.5.2Authenticate identities before access
SP800-171-3.5.3Multifactor authentication for privileged/network access
SP800-171-3.5.4Replay-resistant authentication
SP800-171-3.6.2Track, document, and report incidents
SP800-171-3.6.3Test incident response capability
SP800-171-3.7.1Perform system maintenance
SP800-171-3.7.2Control maintenance tools and personnel
SP800-171-3.7.5MFA for nonlocal maintenance
SP800-171-3.8.1Protect system media containing CUI
SP800-171-3.8.3Sanitize or destroy media before disposal
SP800-171-3.8.6Encrypt CUI on digital media during transport
SP800-171-3.8.7Control removable media
SP800-171-3.9.2Protect CUI during personnel actions
Show the 15 you already have
3.6.1Incident Response Capability
171-AC-1Access Control Policy and Procedures
3.3.1Audit Record Creation
SP800-171-3.10.1Limit physical access
SP800-171-3.10.3Escort and monitor visitors
SP800-171-3.11.1Periodically assess risk
SP800-171-3.11.2Scan for vulnerabilities
SP800-171-3.11.3Remediate vulnerabilities
SP800-171-3.12.3Continuously monitor controls
SP800-171-3.13.1Monitor and protect communications at boundaries
SP800-171-3.13.6Deny network traffic by default
SP800-171-3.14.2Malicious code protection
SP800-171-3.6.1Operational incident-handling capability
SP800-171-3.9.1Screen individuals before CUI access
How this is calculated
Already covered means a mapping runs from a control in API 1164 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition