27% of NIST SP 800-53 Rev 5 you already have
APPI already covers about 27% of NIST SP 800-53 Rev 5, leaving
141 of 192 controls as genuinely new work.
Already covered 12
Likely covered 39
New work 141
What is genuinely new work
Nothing in APPI reaches these. This is the list to scope.
NIST800-AC-1Access control policy and procedures
NIST800-AC-12Session control
NIST800-AC-14Permitted actions without identification or authentication
NIST800-AC-18Wireless access
NIST800-AC-19Access control for mobile devices
NIST800-AC-22Publicly accessible content
NIST800-AC-4Information flow enforcement
NIST800-AC-5Separation of duties
NIST800-AT-1Policy and procedures for awareness and training
NIST800-AT-2Literacy training and awareness
NIST800-AT-4Training records
NIST800-AT-6Training feedback
NIST800-AU-1Policy and procedures for audit and accountability
NIST800-AU-11Audit record retention
NIST800-AU-4Audit log storage capacity
NIST800-AU-5Response to audit logging process failures
NIST800-AU-6Audit record review, analysis, and reporting
NIST800-AU-7Audit record reduction and report generation
NIST800-AU-9Protection of audit information
NIST800-CA-1Policy and procedures for assessment, authorization, and monitoring
NIST800-CA-3Information exchange
NIST800-CA-5Plan of action and milestones
NIST800-CA-6Authorization
NIST800-CA-9Internal system connections
NIST800-CM-1Policy and procedures for configuration management
NIST800-CM-10Software usage restrictions
NIST800-CM-11User-installed software
NIST800-CM-2Baseline configuration
NIST800-CM-5Access restrictions for change
NIST800-CM-6Configuration settings
NIST800-CM-7Least functionality
NIST800-CM-8System component inventory
NIST800-CP-1Policy and procedures for contingency planning
NIST800-CP-2Contingency plan
NIST800-CP-3Contingency training
NIST800-CP-4Contingency plan testing
NIST800-CP-6Alternate storage site
NIST800-CP-7Alternate processing site
NIST800-IA-1Policy and procedures for identification and authentication
NIST800-IA-11Re-authentication
NIST800-IA-12Identity proofing
NIST800-IA-2Identification and authentication of organizational users
NIST800-IA-3Device identification and authentication
NIST800-IA-5Authenticator management
NIST800-IA-6Authentication feedback
NIST800-IR-1Policy and procedures for incident response
NIST800-IR-3Incident response testing
NIST800-IR-8Incident response plan
NIST800-MA-1Policy and procedures for maintenance
NIST800-MA-2Controlled maintenance
NIST800-MA-3Maintenance tools
NIST800-MA-4Nonlocal maintenance
NIST800-MA-5Maintenance personnel
NIST800-MP-1Policy and procedures for media protection
NIST800-MP-3Media marking
NIST800-MP-4Media storage
NIST800-MP-5Media transport
NIST800-MP-6Media sanitization
NIST800-PE-1Policy and procedures for physical and environmental protection
NIST800-PE-10Emergency shutoff
NIST800-PE-11Emergency power
NIST800-PE-12Emergency lighting
NIST800-PE-13Fire protection
NIST800-PE-15Water damage protection
NIST800-PE-17Alternate work site
NIST800-PE-4Access control for transmission
NIST800-PE-5Access control for output devices
NIST800-PE-6Monitoring physical access
NIST800-PE-8Visitor access records
NIST800-PE-9Power equipment and cabling
NIST800-PL-1Policy and procedures for planning
NIST800-PL-10Baseline selection
NIST800-PL-11Baseline tailoring
NIST800-PL-2System security and privacy plans
NIST800-PL-4Rules of behavior
NIST800-PS-2Position risk designation
NIST800-PS-4Personnel termination
NIST800-PS-5Personnel transfer
NIST800-PS-6Access agreements
NIST800-PS-7External personnel security
NIST800-PS-9Position descriptions
NIST800-RA-10Threat hunting
NIST800-RA-7Risk response
NIST800-RA-9Criticality analysis
NIST800-SA-1Policy and procedures for system and services acquisition
NIST800-SA-15Development process, standards, and tools
NIST800-SA-2Allocation of resources
NIST800-SA-22Developer security and privacy architecture
NIST800-SA-3System development life cycle
NIST800-SA-4Acquisition process
NIST800-SA-5System documentation
NIST800-SA-9External system services
NIST800-SC-1Policy and procedures for system and communications protection
NIST800-SC-10Network disconnect
NIST800-SC-15Collaborative computing devices and applications
NIST800-SC-17Public key infrastructure certificates
NIST800-SC-2Separation of system and user functionality
NIST800-SC-20Secure name/address resolution service
NIST800-SC-21Secure name/address resolution service (recursive)
NIST800-SC-23Session authenticity
NIST800-SC-39Process isolation
NIST800-SC-4Information in shared system resources
NIST800-SC-5Denial-of-service protection
NIST800-SC-7Boundary protection
NIST800-SI-1Policy and procedures for system and information integrity
NIST800-SI-10Information input validation
NIST800-SI-12Information management and retention
NIST800-SI-16Memory protection
NIST800-SI-3Malicious code protection
NIST800-SI-5Security alerts, advisories, and directives
NIST800-SI-7Software, firmware, and information integrity
NIST800-SR-1Policy and procedures for supply chain risk management
NIST800-SR-10Inspection of systems or components
NIST800-SR-12Component disposal
NIST800-SR-2Supply chain risk management plan
NIST800-SR-5Acquisition strategies, tools, and methods
NIST800-SR-6Supplier assessments and reviews
SP800-53-ACAccess Control Family
SP800-53-ATAwareness and Training Family
SP800-53-AUAudit and Accountability Family
SP800-53-CAAssessment, Authorization, and Monitoring Family
SP800-53-CMConfiguration Management Family
SP800-53-CPContingency Planning Family
SP800-53-IAIdentification and Authentication Family
SP800-53-IRIncident Response Family
SP800-53-MAMaintenance Family
SP800-53-MPMedia Protection Family
SP800-53-PEPhysical and Environmental Protection Family
SP800-53-PLPlanning Family
SP800-53-PMProgram Management Family
SP800-53-PSPersonnel Security Family
SP800-53-PTPII Processing and Transparency Family
SP800-53-RARisk Assessment Family
SP800-53-SASystem and Services Acquisition Family
SP800-53-SCSystem and Communications Protection Family
SP800-53-SISystem and Information Integrity Family
SP800-53-SRSupply Chain Risk Management Family
Show the 51 you already have
NIST800-AC-2Account management
NIST800-AC-20Use of external systems
NIST800-AC-7Unsuccessful logon attempts
NIST800-IA-7Cryptographic module authentication
NIST800-IR-2Incident response training
NIST800-IR-5Incident monitoring
NIST800-IR-7Incident response assistance
NIST800-RA-1Policy and procedures for risk assessment
NIST800-RA-2Security categorization
NIST800-RA-5Vulnerability monitoring and scanning
NIST800-SC-12Cryptographic key establishment and management
NIST800-SC-13Cryptographic protection
NIST800-AC-17Remote access
NIST800-AC-3Access enforcement
NIST800-AC-6Least privilege
NIST800-AT-3Role-based training
NIST800-AU-12Audit record generation
NIST800-AU-2Event logging
NIST800-AU-3Content of audit records
NIST800-CA-2Control assessments
NIST800-CA-7Continuous monitoring
NIST800-CA-8Penetration testing
NIST800-CM-3Configuration change control
NIST800-CM-4Impact analyses
NIST800-CM-9Configuration management plan
NIST800-CP-10System recovery and reconstitution
NIST800-CP-8Telecommunications services
NIST800-CP-9System backup
NIST800-IA-4Identifier management
NIST800-IA-8Identification and authentication of non-organizational users
NIST800-IR-4Incident handling
NIST800-IR-6Incident reporting
NIST800-PE-14Environmental controls
NIST800-PE-2Physical access authorizations
NIST800-PE-3Physical access control
NIST800-PL-8Security and privacy architectures
NIST800-PS-1Policy and procedures for personnel security
NIST800-PS-3Personnel screening
NIST800-PS-8Personnel sanctions
NIST800-RA-3Risk assessment
NIST800-SA-10Developer configuration management
NIST800-SA-11Developer testing and evaluation
NIST800-SA-8Security and privacy engineering principles
NIST800-SC-22Architecture and provisioning for name/address resolution service
NIST800-SC-28Protection of information at rest
NIST800-SC-8Transmission confidentiality and integrity
NIST800-SI-2Flaw remediation
NIST800-SI-4System monitoring
NIST800-SR-11Component authenticity
NIST800-SR-3Supply chain controls and processes
NIST800-SR-8Notification agreements
How this is calculated
Already covered means a mapping runs from a control in APPI to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition