Framework overlap

Does AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) cover NIST SP 800-53 Rev 5 LOW?

You hold AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) and have been told to do NIST SP 800-53 Rev 5 LOW. Here is how much overlaps, control by control.

5% of NIST SP 800-53 Rev 5 LOW you already have

AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 5% of NIST SP 800-53 Rev 5 LOW, leaving 164 of 173 controls as genuinely new work.

Already covered 3 Likely covered 6 New work 164

What is genuinely new work

Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.

AC-1
Policy and Procedures
AC-14
Permitted Actions Without Identification or Authentication
AC-17
Remote Access
AC-18
Wireless Access
AC-20
Use of External Systems
AC-22
Publicly Accessible Content
AC-7
Unsuccessful Logon Attempts
AC-8
System Use Notification
AT-1
Policy and Procedures
AT-2
Literacy Training and Awareness
AT-2(2)
Insider Threat
AT-3
Role-Based Training
AT-4
Training Records
AU-1
Policy and Procedures
AU-11
Audit Record Retention
AU-12
Audit Record Generation
AU-2
Event Logging
AU-3
Content of Audit Records
AU-4
Audit Log Storage Capacity
AU-5
Response to Audit Logging Process Failures
AU-6
Audit Record Review, Analysis, and Reporting
AU-8
Time Stamps
AU-9
Protection of Audit Information
CA-1
Policy and Procedures
CA-2
Control Assessments
CA-3
Information Exchange
CA-5
Plan of Action and Milestones
CA-6
Authorization
CA-7
Continuous Monitoring
CA-7(4)
Risk Monitoring
CM-1
Policy and Procedures
CM-10
Software Usage Restrictions
CM-11
User-Installed Software
CM-2
Baseline Configuration
CM-4
Impact Analyses
CM-5
Access Restrictions for Change
CM-6
Configuration Settings
CM-7
Least Functionality
CM-8
System Component Inventory
CP-1
Policy and Procedures
CP-10
System Recovery and Reconstitution
CP-2
Contingency Plan
CP-3
Contingency Training
CP-4
Contingency Plan Testing
CP-9
System Backup
IA-1
Policy and Procedures
IA-11
Re-Authentication
IA-2
Identification and Authentication (Organizational Users)
IA-4
Identifier Management
IA-5
Authenticator Management
IA-6
Authentication Feedback
IA-7
Cryptographic Module Authentication
IA-8
Identification and Authentication (Non-Organizational Users)
IR-1
Event Detection and Triage
IR-5
Incident Monitoring
IR-6
Incident Reporting
IR-7
Incident Response Assistance
IR-8
Incident Response Plan
MA-1
Policy and Procedures
MA-2
Controlled Maintenance
MA-4
Nonlocal Maintenance
MA-5
Maintenance Personnel
MP-1
Policy and Procedures
MP-2
Media Access
MP-6
Media Sanitization
MP-7
Media Use
PE-1
Policy and Procedures
PE-12
Emergency Lighting
PE-13
Fire Protection
PE-14
Environmental Controls
PE-15
Water Damage Protection
PE-16
Delivery and Removal
PE-2
Physical Access Authorizations
PE-3
Physical Access Control
PE-6
Monitoring Physical Access
PE-8
Visitor Access Records
PL-1
Policy and Procedures
PL-10
Baseline Selection
PL-11
Baseline Tailoring
PL-2
System Security and Privacy Plans
PL-4
Rules of Behavior
PM-1
Information Security Program Plan
PM-10
Authorization Process
PM-11
Mission and Business Process Definition
PM-12
Insider Threat Program
PM-13
Security and Privacy Workforce
PM-14
Testing, Training, and Monitoring
PM-15
Security and Privacy Groups and Associations
PM-16
Threat Awareness Program
PM-17
Protecting CUI on External Systems
PM-18
Privacy Program Plan
PM-19
Privacy Program Leadership Role
PM-2
Information Security Program Leadership Role
PM-20
Dissemination of Privacy Program Information
PM-21
Accounting of Disclosures
PM-22
Personally Identifiable Information Quality Management
PM-23
Data Governance Body
PM-24
Data Integrity Board
PM-25
Minimization of PII Used in Testing, Training, and Research
PM-26
Complaint Management
PM-27
Privacy Reporting
PM-28
Risk Framing
PM-29
Risk Management Program Leadership Roles
PM-3
Information Security and Privacy Resources
PM-30
Supply Chain Risk Management Strategy
PM-31
Continuous Monitoring Strategy
PM-32
Purposing
PM-4
Plan of Action and Milestones Process
PM-5
System Inventory
PM-6
Measures of Performance
PM-7
Enterprise Architecture
PM-8
Critical Infrastructure Plan
PM-9
Risk Management Strategy
PS-1
Policy and Procedures
PS-2
Position Risk Designation
PS-3
Personnel Screening
PS-4
Personnel Termination
PS-5
Personnel Transfer
PS-6
Access Agreements
PS-7
External Personnel Security
PS-8
Personnel Sanctions
PS-9
Position Descriptions
PT-1
Policy and Procedures
PT-2
Authority to Process PII
PT-3
PII Processing Purposes
PT-4
Consent
PT-5
Privacy Notice
PT-6
System of Records Notice
PT-7
Specific Categories of PII
PT-8
Computer Matching Requirements
RA-5
Vulnerability Monitoring and Scanning
RA-7
Identifies and Analyzes Risk
SA-1
Logging and Monitoring
SA-2
Common Operating Picture
SA-22
Unsupported System Components
SA-3
System Development Life Cycle
SA-4
Acquisition Process
SA-5
System Documentation
SA-8
Security and Privacy Engineering Principles
SA-9
External System Services
SC-1
Policy and Procedures
SC-12
Cryptographic Key Establishment and Management
SC-13
Cryptographic Protection
SC-15
Collaborative Computing Devices and Applications
SC-20
Secure Name/Address Resolution Service (Authoritative)
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22
Architecture and Provisioning for Name/Address Resolution Service
SC-39
Process Isolation
SC-5
Denial-of-Service Protection
SC-7
Boundary Protection
SI-1
Policy and Procedures
SI-12
Information Management and Retention
SI-2
Flaw Remediation
SI-3
Malicious Code Protection
SI-4
System Monitoring
SI-5
Security Alerts, Advisories, and Directives
SR-1
Policy and Procedures (SR-1)
SR-10
Inspection of Systems or Components (SR-10)
SR-11
Component Authenticity (SR-11)
SR-12
Component Disposal (SR-12)
SR-2
Supply Chain Risk Management Plan (SR-2)
SR-3
Supply Chain Controls and Processes (SR-3)
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)
SR-8
Notification Agreements (SR-8)
Show the 9 you already have
CA-9
Internal System Connections
IR-2
Incident Response and Recovery
RA-1
Policy and Procedures
AC-19
Access Control for Mobile Devices
AC-2
Account Management
AC-3
Access Enforcement
IR-4
Incident Handling
RA-2
Security Categorization
RA-3
Risk Assessment

How this is calculated

Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition