Framework overlap

Does APRA CPS 234 cover NIST SP 800-53A Rev. 5?

You hold APRA CPS 234 and have been told to do NIST SP 800-53A Rev. 5. Here is how much overlaps, control by control.

63% of NIST SP 800-53A Rev. 5 you already have

APRA CPS 234 already covers about 63% of NIST SP 800-53A Rev. 5, leaving 18 of 48 controls as genuinely new work.

Already covered 0 Likely covered 30 New work 18

No control in APRA CPS 234 maps directly to one in NIST SP 800-53A Rev. 5. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in APRA CPS 234 reaches these. This is the list to scope.

53A-ASMT-PLAN
Develop a Security and Privacy Assessment Plan
53A-ASSESSOR-INDEP
Establish Assessor Independence
53A-AUTOMATED-EVID
Use Automated Evidence Collection
53A-CONTINUOUS
Support Continuous Control Monitoring
53A-CONTROL-INHERIT
Assess Inherited and Hybrid Controls
53A-DEPTH-COVERAGE
Determine Assessment Depth and Coverage
53A-EVIDENCE-CHAIN
Maintain Evidence Chain of Custody
53A-FINDINGS
Document Assessment Findings and Recommendations
53A-METHOD-EXAMINE
Apply the Examine Assessment Method
53A-METHOD-INTERVIEW
Apply the Interview Assessment Method
53A-METHOD-TEST
Apply the Test Assessment Method
53A-OBJECT-INVENTORY
Identify Assessment Objects
53A-OBJECTIVE
Define Assessment Objectives and Determination Statements
53A-PRIVACY-ASMT
Assess Privacy Controls
53A-RETEST
Retest After Remediation
53A-SAMPLING
Apply Sampling for Population Assessments
53A-SAR
Produce Security and Privacy Assessment Report
53A-SUPPLY-CHAIN
Assess Supply Chain Risk Management Controls
Show the 30 you already have
SP800-53A-FAM-AC
Assessment Procedures: Access Control (AC)
SP800-53A-FAM-AT
Assessment Procedures: Awareness and Training (AT)
SP800-53A-FAM-AU
Assessment Procedures: Audit and Accountability (AU)
SP800-53A-FAM-CA
Assessment Procedures: Assessment, Authorization, and Monitoring (CA)
SP800-53A-FAM-CM
Assessment Procedures: Configuration Management (CM)
SP800-53A-FAM-CP
Assessment Procedures: Contingency Planning (CP)
SP800-53A-FAM-IA
Assessment Procedures: Identification and Authentication (IA)
SP800-53A-FAM-IR
Assessment Procedures: Incident Response (IR)
SP800-53A-FAM-MA
Assessment Procedures: Maintenance (MA)
SP800-53A-FAM-MP
Assessment Procedures: Media Protection (MP)
SP800-53A-FAM-PE
Assessment Procedures: Physical and Environmental Protection (PE)
SP800-53A-FAM-PL
Assessment Procedures: Planning (PL)
SP800-53A-FAM-PM
Assessment Procedures: Program Management (PM)
SP800-53A-FAM-PS
Assessment Procedures: Personnel Security (PS)
SP800-53A-FAM-PT
Assessment Procedures: PII Processing and Transparency (PT)
SP800-53A-FAM-RA
Assessment Procedures: Risk Assessment (RA)
SP800-53A-FAM-SA
Assessment Procedures: System and Services Acquisition (SA)
SP800-53A-FAM-SC
Assessment Procedures: System and Communications Protection (SC)
SP800-53A-FAM-SI
Assessment Procedures: System and Information Integrity (SI)
SP800-53A-FAM-SR
Assessment Procedures: Supply Chain Risk Management (SR)
SP800-53A-METHOD-EXAMINE
Assessment Method: Examine
SP800-53A-METHOD-INTERVIEW
Assessment Method: Interview
SP800-53A-METHOD-TEST
Assessment Method: Test
SP800-53A-OBJECTS
Assessment Objects
SP800-53A-STEP-ANALYZE
Analyze Assessment Report Results
SP800-53A-STEP-CAPABILITY
Assess Security and Privacy Capabilities
SP800-53A-STEP-CONDUCT
Conduct Control Assessments
SP800-53A-STEP-PLAN
Develop Security and Privacy Assessment Plans
SP800-53A-STEP-PREPARE
Prepare for Control Assessments
SP800-53A-STEP-SELECT
Select and Tailor Assessment Procedures

How this is calculated

Already covered means a mapping runs from a control in APRA CPS 234 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition