2% of FedRAMP High you already have
APRA CPS 234 already covers about 2% of FedRAMP High, leaving
410 of 417 controls as genuinely new work.
Already covered 1
Likely covered 6
New work 410
What is genuinely new work
Nothing in APRA CPS 234 reaches these. This is the list to scope.
AC-1Policy and Procedures
AC-10Concurrent Session Control
AC-14Permitted Actions Without Identification or Authentication
AC-17(1)Monitoring and Control
AC-17(2)Protection of Confidentiality and Integrity Using Encryption
AC-17(3)Managed Access Control Points
AC-17(4)Privileged Commands and Access
AC-17(9)Disconnect or Disable Access
AC-18(1)Authentication and Encryption
AC-18(3)Disable Wireless Networking
AC-18(4)Restrict Configurations by Users
AC-18(5)Antennas and Transmission Power Levels
AC-19Access Control for Mobile Devices
AC-19(5)Full Device or Container-Based Encryption
AC-2(1)Automated System Account Management
AC-2(12)Account Monitoring for Atypical Usage
AC-2(13)Disable Accounts for High-Risk Individuals
AC-2(2)Automated Temporary and Emergency Account Management
AC-2(4)Automated Audit Actions
AC-2(7)Privileged User Accounts
AC-2(9)Restrictions on Use of Shared and Group Accounts
AC-20Use of External Systems
AC-20(1)Limits on Authorized Use
AC-20(2)Portable Storage Devices Restricted Use
AC-22Publicly Accessible Content
AC-4Information Flow Enforcement
AC-4(21)Physical or Logical Separation of Information Flows
AC-4(4)Flow Control of Encrypted Information
AC-4(8)Security and Privacy Policy Filters
AC-6(1)Authorize Access to Security Functions
AC-6(10)Prohibit Non-Privileged Users from Executing Privileged Functions
AC-6(2)Non-Privileged Access for Nonsecurity Functions
AC-6(3)Network Access to Privileged Commands
AC-6(5)Privileged Accounts
AC-6(7)Review of User Privileges
AC-6(8)Privilege Levels for Code Execution
AC-6(9)Log Use of Privileged Functions
AC-7Unsuccessful Logon Attempts
AC-8System Use Notification
AT-1Policy and Procedures
AT-2Literacy Training and Awareness
AT-2(3)Social Engineering and Mining
AU-1Policy and Procedures
AU-11Audit Record Retention
AU-12Audit Record Generation
AU-12(1)System-wide and Time-correlated Audit Trail
AU-12(3)Changes by Authorized Individuals
AU-3Content of Audit Records
AU-3(1)Additional Audit Information
AU-4Audit Log Storage Capacity
AU-5Response to Audit Logging Process Failures
AU-5(1)Storage Capacity Warning
AU-6Audit Record Review, Analysis, and Reporting
AU-6(1)Automated Process Integration
AU-6(3)Correlate Audit Record Repositories
AU-6(4)Central Review and Analysis
AU-6(5)Integrated Analysis of Audit Records
AU-6(6)Correlation with Physical Monitoring
AU-7Audit Record Reduction and Report Generation
AU-7(1)Automatic Processing
AU-9Protection of Audit Information
AU-9(2)Store on Separate Physical Systems or Components
AU-9(3)Cryptographic Protection
AU-9(4)Access by Subset of Privileged Users
CA-1Policy and Procedures
CA-2(1)Independent Assessors
CA-2(2)Specialized Assessments
CA-2(3)Leveraging Results from External Organizations
CA-5Plan of Action and Milestones
CA-7Continuous Monitoring
CA-7(1)Independent Assessment
CA-8(1)Independent Penetration Agent or Team
CA-8(2)Red Team Exercises
CM-1Policy and Procedures
CM-10Software Usage Restrictions
CM-11User-Installed Software
CM-12Information Location
CM-12(1)Automated Tools to Support Information Location
CM-2Baseline Configuration
CM-2(2)Automation Support for Accuracy and Currency
CM-2(3)Retention of Previous Configurations
CM-2(7)Configure Systems and Components for High-Risk Areas
CM-3Configuration Change Control
CM-3(1)Automated Documentation, Notification, and Prohibition
CM-3(2)Testing, Validation, and Documentation of Changes
CM-3(4)Security and Privacy Representatives
CM-3(6)Cryptography Management
CM-4(1)Separate Test Environments
CM-5Access Restrictions for Change
CM-5(1)Automated Access Enforcement and Audit Records
CM-5(2)Review System Changes
CM-6Configuration Settings
CM-6(1)Automated Management, Application, and Verification
CM-6(2)Respond to Unauthorized Changes
CM-7(2)Prevent Program Execution
CM-7(3)Registration Compliance
CM-7(5)Authorized Software Allow-by-Exception
CM-8System Component Inventory
CM-8(1)Updates During Installation and Removal
CM-8(2)Automated Maintenance
CM-8(3)Automated Unauthorized Component Detection
CM-8(4)Accountability Information
CM-9Configuration Management Plan
CP-1Policy and Procedures
CP-10System Recovery and Reconstitution
CP-10(2)Transaction Recovery
CP-10(4)Restore Within Time Period
CP-2(1)Coordinate with Related Plans
CP-2(3)Resume Mission and Business Functions
CP-2(5)Continue Mission and Business Functions
CP-2(8)Identify Critical Assets
CP-4Contingency Plan Testing
CP-4(1)Coordinate with Related Plans
CP-4(2)Alternate Processing Site
CP-6Alternate Storage Site
CP-6(1)Separation from Primary Site
CP-6(2)Recovery Time and Recovery Point Objectives
CP-7Alternate Processing Site
CP-7(1)Separation from Primary Site
CP-7(3)Priority of Service
CP-7(4)Preparation for Use
CP-8Telecommunications Services
CP-8(1)Priority of Service Provisions
CP-8(2)Single Points of Failure
CP-8(3)Separation of Primary and Alternate Providers
CP-8(4)Provider Contingency Plan
CP-9(1)Testing for Reliability and Integrity
CP-9(2)Test Restoration Using Sampling
CP-9(3)Separate Storage for Critical Information
CP-9(5)Transfer to Alternate Storage Site
CP-9(8)Cryptographic Protection
IA-1Policy and Procedures
IA-12(2)Identity Evidence
IA-12(3)Identity Evidence Validation and Verification
IA-12(4)In-Person Validation and Verification
IA-12(5)Address Confirmation
IA-2Identification and Authentication (Organizational Users)
IA-2(1)MFA to Privileged Accounts
IA-2(12)Acceptance of PIV Credentials
IA-2(2)MFA to Non-Privileged Accounts
IA-2(5)Individual Authentication with Group Authentication
IA-2(6)Access to Accounts via Separate Device
IA-2(8)Access to Accounts Replay Resistant
IA-3Device Identification and Authentication
IA-4Identifier Management
IA-4(4)Identify User Status
IA-5Authenticator Management
IA-5(1)Password-Based Authentication
IA-5(2)Public Key-Based Authentication
IA-5(6)Protection of Authenticators
IA-5(7)No Embedded Unencrypted Static Authenticators
IA-5(8)Multiple System Accounts
IA-6Authentication Feedback
IA-7Cryptographic Module Authentication
IA-8Identification and Authentication (Non-Organizational Users)
IA-8(1)Acceptance of PIV Credentials from Other Agencies
IA-8(2)Acceptance of External Authenticators
IA-8(4)Use of Defined Profiles
IR-1Event Detection and Triage
IR-2(2)Automated Training Environments
IR-3Continuity of Operations
IR-3(2)Coordination with Related Plans
IR-4(1)Automated Incident Handling Processes
IR-4(3)Continuity of Operations
IR-4(4)Information Correlation
IR-4(8)Correlation with External Organizations
IR-5(1)Automated Tracking, Data Collection, and Analysis
IR-6(1)Automated Reporting
IR-6(3)Supply Chain Coordination
IR-7Incident Response Assistance
IR-7(1)Automation Support for Availability of Information and Support
IR-8Incident Response Plan
IR-9Information Spillage Response
IR-9(3)Post-Spill Operations
IR-9(4)Exposure to Unauthorized Personnel
MA-1Policy and Procedures
MA-2Controlled Maintenance
MA-2(2)Automated Maintenance Activities
MA-3(3)Prevent Unauthorized Removal
MA-4(3)Comparable Security and Sanitization
MA-5Maintenance Personnel
MA-5(1)Individuals Without Appropriate Access
MP-1Policy and Procedures
MP-6(1)Review, Approve, Track, Document, Verify
MP-6(3)Nondestructive Techniques
PE-1Policy and Procedures
PE-11(1)Alternate Power Supply Minimal Operational Capability
PE-13(1)Detection Systems Automatic Activation and Notification
PE-13(2)Suppression Systems Automatic Activation and Notification
PE-14Environmental Controls
PE-15Water Damage Protection
PE-15(1)Automation Support
PE-16Delivery and Removal
PE-18Location of System Components
PE-2Physical Access Authorizations
PE-3Physical Access Control
PE-4Access Control for Transmission
PE-5Access Control for Output Devices
PE-6Monitoring Physical Access
PE-6(1)Intrusion Alarms and Surveillance Equipment
PE-6(4)Monitoring Physical Access to Systems
PE-8Visitor Access Records
PE-8(1)Automated Records Maintenance and Review
PE-9Power Equipment and Cabling
PL-1Policy and Procedures
PL-2System Security and Privacy Plans
PL-4(1)Social Media and External Site/Application Usage Restrictions
PL-8Security and Privacy Architectures
PS-1Policy and Procedures
PS-2Position Risk Designation
PS-3(3)Information Requiring Special Protective Measures
PS-4Personnel Termination
PS-7External Personnel Security
PS-9Position Descriptions
RA-3(1)Supply Chain Risk Assessment
RA-5Vulnerability Monitoring and Scanning
RA-5(11)Public Disclosure Program
RA-5(2)Update Vulnerabilities to be Scanned
RA-5(4)Discoverable Information
RA-7Identifies and Analyzes Risk
RA-9Identifies and Analyzes Significant Change
SA-1Logging and Monitoring
SA-10Developer Configuration Management
SA-10(1)Software and Firmware Integrity Verification
SA-11Developer Testing and Evaluation
SA-11(1)Static Code Analysis
SA-11(2)Threat Modeling and Vulnerability Analyses
SA-11(8)Dynamic Code Analysis
SA-15Development Process, Standards, and Tools
SA-16Developer-Provided Training
SA-17Developer Security and Privacy Architecture and Design
SA-2Common Operating Picture
SA-22Unsupported System Components
SA-3System Development Life Cycle
SA-4(1)Functional Properties of Controls
SA-4(10)Use of Approved PIV Products
SA-4(2)Design and Implementation Information for Controls
SA-4(5)System, Component, and Service Configurations
SA-4(8)Continuous Monitoring Plan for Controls
SA-4(9)Functions, Ports, Protocols, and Services in Use
SA-8Security and Privacy Engineering Principles
SA-9External System Services
SA-9(1)Risk Assessments and Organizational Approvals
SA-9(2)Identification of Functions, Ports, Protocols, and Services
SA-9(4)Consistent Interests of Consumers and Providers
SA-9(5)Processing, Storage, and Service Location
SC-1Policy and Procedures
SC-12Cryptographic Key Establishment and Management
SC-13Cryptographic Protection
SC-15Collaborative Computing Devices and Applications
SC-17Public Key Infrastructure Certificates
SC-2Separation of System and User Functionality
SC-20Secure Name/Address Resolution Service (Authoritative)
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22Architecture and Provisioning for Name/Address Resolution Service
SC-23Session Authenticity
SC-23(1)Invalidate Session Identifiers at Logout
SC-28Protection of Information at Rest
SC-28(1)Cryptographic Protection
SC-3Security Function Isolation
SC-4Information in Shared System Resources
SC-45System Time Synchronization
SC-45(1)Synchronization with Authoritative Time Source
SC-5Denial-of-Service Protection
SC-5(1)Restrict Ability to Attack Other Systems
SC-5(2)Capacity, Bandwidth, and Redundancy
SC-5(3)Detection and Monitoring
SC-6Resource Availability
SC-7(10)Prevent Exfiltration
SC-7(12)Host-Based Protection
SC-7(13)Isolation of Security Tools, Mechanisms, and Support Components
SC-7(20)Dynamic Isolation and Segregation
SC-7(21)Isolation of System Components
SC-7(4)External Telecommunications Services
SC-7(5)Deny by Default Allow by Exception
SC-7(7)Split Tunneling for Remote Devices
SC-7(8)Route Traffic to Authenticated Proxy Servers
SC-8Transmission Confidentiality and Integrity
SC-8(1)Cryptographic Protection
SI-1Policy and Procedures
SI-10Information Input Validation
SI-12Information Management and Retention
SI-17Fail-Safe Procedures
SI-2(1)Central Management
SI-2(2)Automated Flaw Remediation Status
SI-2(3)Time to Remediate Flaws and Benchmarks for Corrective Actions
SI-3Malicious Code Protection
SI-4(1)System-Wide Intrusion Detection System
SI-4(10)Visibility of Encrypted Communications
SI-4(11)Analyze Communications Traffic Anomalies
SI-4(12)Automated Organization-Generated Alerts
SI-4(14)Wireless Intrusion Detection
SI-4(16)Correlate Monitoring Information
SI-4(18)Analyze Traffic and Covert Exfiltration
SI-4(19)Risk for Individuals
SI-4(2)Automated Tools and Mechanisms for Real-Time Analysis
SI-4(22)Unauthorized Network Services
SI-4(23)Host-Based Devices
SI-4(4)Inbound and Outbound Communications Traffic
SI-4(5)System-Generated Alerts
SI-5Security Alerts, Advisories, and Directives
SI-5(1)Automated Alerts and Advisories
SI-6Security and Privacy Function Verification
SI-7Software, Firmware, and Information Integrity
SI-7(14)Binary or Machine-Executable Code
SI-7(2)Automated Notifications of Integrity Violations
SI-7(5)Automated Response to Integrity Violations
SI-7(7)Integration of Detection and Response
SR-1Policy and Procedures (SR-1)
SR-10Inspection of Systems or Components (SR-10)
SR-11Component Authenticity (SR-11)
SR-11(1)Anti-counterfeit Training (SR-11(1))
SR-11(2)Configuration Control for Component Service and Repair (SR-11(2))
SR-12Component Disposal (SR-12)
SR-2Supply Chain Risk Management Plan (SR-2)
SR-3Supply Chain Controls and Processes (SR-3)
SR-5Acquisition Strategies, Tools, and Methods (SR-5)
SR-6Supplier Assessments and Reviews (SR-6)
SR-8Notification Agreements (SR-8)
Show the 7 you already have
CA-9Internal System Connections
IR-2Incident Response and Recovery
RA-1Policy and Procedures
RA-2Security Categorization
How this is calculated
Already covered means a mapping runs from a control in APRA CPS 234 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition