10% of CMMC 2.0 you already have
APRA CPS 234 already covers about 10% of CMMC 2.0, leaving
99 of 110 controls as genuinely new work.
Already covered 0
Likely covered 11
New work 99
No control in APRA CPS 234
maps directly to one in CMMC 2.0. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in APRA CPS 234 reaches these. This is the list to scope.
AC.L2-3.1.11Session Termination
AC.L2-3.1.12Control Remote Access
AC.L2-3.1.13Remote Access Confidentiality
AC.L2-3.1.14Remote Access Routing
AC.L2-3.1.15Privileged Remote Access
AC.L2-3.1.16Wireless Access Authorization
AC.L2-3.1.17Wireless Access Protection
AC.L2-3.1.18Mobile Device Connection
AC.L2-3.1.19Encrypt CUI on Mobile
AC.L2-3.1.2Transaction & Function Control
AC.L2-3.1.20External Connections
AC.L2-3.1.21Portable Storage Use
AC.L2-3.1.22Control Public Information
AC.L2-3.1.3Control CUI Flow
AC.L2-3.1.4Separation of Duties
AC.L2-3.1.5Least Privilege
AC.L2-3.1.6Non-Privileged Account Use
AC.L2-3.1.7Privileged Functions
AC.L2-3.1.8Unsuccessful Logon Attempts
AC.L2-3.1.9Privacy & Security Notices
AT.L2-3.2.2Role-Based Training
AT.L2-3.2.3Insider Threat Awareness
AU.L2-3.3.1System Auditing
AU.L2-3.3.2User Accountability
AU.L2-3.3.4Audit Failure Alerting
AU.L2-3.3.5Audit Correlation
AU.L2-3.3.6Reduction & Reporting
AU.L2-3.3.7Time Stamps & Synchronization
AU.L2-3.3.8Audit Protection
AU.L2-3.3.9Audit Management
CA.L2-3.12.3Security Control Monitoring
CA.L2-3.12.4System Security Plan
CM.L2-3.4.1System Baselining
CM.L2-3.4.3System Change Management
CM.L2-3.4.4Security Impact Analysis
CM.L2-3.4.5Access Restrictions for Change
CM.L2-3.4.6Least Functionality
CM.L2-3.4.7Nonessential Functionality
CM.L2-3.4.8Application Execution Policy
CM.L2-3.4.9User-Installed Software
IA.L2-3.5.1Identification
IA.L2-3.5.10Cryptographically-Protected Passwords
IA.L2-3.5.11Obscure Feedback
IA.L2-3.5.2Authentication
IA.L2-3.5.3Multifactor Authentication
IA.L2-3.5.4Replay-Resistant Authentication
IA.L2-3.5.5Identifier Reuse
IA.L2-3.5.6Identifier Handling
IA.L2-3.5.7Password Complexity
IA.L2-3.5.8Password Reuse
IA.L2-3.5.9Temporary Passwords
IR.L2-3.6.3Incident Response Testing
MA.L2-3.7.1Perform Maintenance
MA.L2-3.7.2System Maintenance Control
MA.L2-3.7.3Equipment Sanitization
MA.L2-3.7.4Media Inspection
MA.L2-3.7.5Nonlocal Maintenance
MA.L2-3.7.6Maintenance Personnel
MP.L2-3.8.1Media Protection
MP.L2-3.8.3Media Disposal
MP.L2-3.8.4Media Markings
MP.L2-3.8.5Media Accountability
MP.L2-3.8.6Portable Storage Encryption
MP.L2-3.8.7Removable Media
MP.L2-3.8.9Protect Backups
PE.L2-3.10.1Limit Physical Access
PE.L2-3.10.2Monitor Facility
PE.L2-3.10.3Escort Visitors
PE.L2-3.10.4Physical Access Logs
PE.L2-3.10.5Manage Physical Access
PE.L2-3.10.6Alternative Work Sites
PS.L2-3.9.1Screen Individuals
PS.L2-3.9.2Personnel Actions
RA.L2-3.11.1Risk Assessments
RA.L2-3.11.3Vulnerability Remediation
SC.L2-3.13.10Key Management
SC.L2-3.13.12Collaborative Device Control
SC.L2-3.13.14Voice over Internet Protocol
SC.L2-3.13.15Communications Authenticity
SC.L2-3.13.16Data at Rest
SC.L2-3.13.2Security Engineering
SC.L2-3.13.3Role Separation
SC.L2-3.13.4Shared Resource Control
SC.L2-3.13.5Public-Access System Separation
SC.L2-3.13.6Network Communication by Exception
SC.L2-3.13.7Split Tunneling
SC.L2-3.13.8Data in Transit
SC.L2-3.13.9Connections Termination
SI.L2-3.14.1Flaw Remediation
SI.L2-3.14.3Security Alerts & Advisories
SI.L2-3.14.4Update Malicious Code Protection
SI.L2-3.14.5System & File Scanning
SI.L2-3.14.6Monitor Communications for Attacks
SI.L2-3.14.7Identify Unauthorized Use
Show the 11 you already have
AC.L2-3.1.1Authorized Access Control
AT.L2-3.2.1Role-Based Risk Awareness
CA.L2-3.12.1Security Control Assessment
CA.L2-3.12.2Plan of Action
CM.L2-3.4.2Security Configuration Enforcement
IR.L2-3.6.1Incident Handling
IR.L2-3.6.2Incident Reporting
RA.L2-3.11.2Vulnerability Scan
SC.L2-3.13.1Boundary Protection
SC.L2-3.13.11CUI Encryption
SI.L2-3.14.2Malicious Code Protection
How this is calculated
Already covered means a mapping runs from a control in APRA CPS 234 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition