5% of NIST SP 800-53 Rev 5 LOW you already have
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 5% of NIST SP 800-53 Rev 5 LOW, leaving
164 of 173 controls as genuinely new work.
Already covered 3
Likely covered 6
New work 164
What is genuinely new work
Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.
AC-1Policy and Procedures
AC-14Permitted Actions Without Identification or Authentication
AC-20Use of External Systems
AC-22Publicly Accessible Content
AC-7Unsuccessful Logon Attempts
AC-8System Use Notification
AT-1Policy and Procedures
AT-2Literacy Training and Awareness
AU-1Policy and Procedures
AU-11Audit Record Retention
AU-12Audit Record Generation
AU-3Content of Audit Records
AU-4Audit Log Storage Capacity
AU-5Response to Audit Logging Process Failures
AU-6Audit Record Review, Analysis, and Reporting
AU-9Protection of Audit Information
CA-1Policy and Procedures
CA-5Plan of Action and Milestones
CA-7Continuous Monitoring
CM-1Policy and Procedures
CM-10Software Usage Restrictions
CM-11User-Installed Software
CM-2Baseline Configuration
CM-5Access Restrictions for Change
CM-6Configuration Settings
CM-8System Component Inventory
CP-1Policy and Procedures
CP-10System Recovery and Reconstitution
CP-4Contingency Plan Testing
IA-1Policy and Procedures
IA-2Identification and Authentication (Organizational Users)
IA-4Identifier Management
IA-5Authenticator Management
IA-6Authentication Feedback
IA-7Cryptographic Module Authentication
IA-8Identification and Authentication (Non-Organizational Users)
IR-1Event Detection and Triage
IR-7Incident Response Assistance
IR-8Incident Response Plan
MA-1Policy and Procedures
MA-2Controlled Maintenance
MA-5Maintenance Personnel
MP-1Policy and Procedures
PE-1Policy and Procedures
PE-14Environmental Controls
PE-15Water Damage Protection
PE-16Delivery and Removal
PE-2Physical Access Authorizations
PE-3Physical Access Control
PE-6Monitoring Physical Access
PE-8Visitor Access Records
PL-1Policy and Procedures
PL-2System Security and Privacy Plans
PM-1Information Security Program Plan
PM-10Authorization Process
PM-11Mission and Business Process Definition
PM-12Insider Threat Program
PM-13Security and Privacy Workforce
PM-14Testing, Training, and Monitoring
PM-15Security and Privacy Groups and Associations
PM-16Threat Awareness Program
PM-17Protecting CUI on External Systems
PM-18Privacy Program Plan
PM-19Privacy Program Leadership Role
PM-2Information Security Program Leadership Role
PM-20Dissemination of Privacy Program Information
PM-21Accounting of Disclosures
PM-22Personally Identifiable Information Quality Management
PM-23Data Governance Body
PM-24Data Integrity Board
PM-25Minimization of PII Used in Testing, Training, and Research
PM-26Complaint Management
PM-29Risk Management Program Leadership Roles
PM-3Information Security and Privacy Resources
PM-30Supply Chain Risk Management Strategy
PM-31Continuous Monitoring Strategy
PM-4Plan of Action and Milestones Process
PM-6Measures of Performance
PM-7Enterprise Architecture
PM-8Critical Infrastructure Plan
PM-9Risk Management Strategy
PS-1Policy and Procedures
PS-2Position Risk Designation
PS-4Personnel Termination
PS-7External Personnel Security
PS-9Position Descriptions
PT-1Policy and Procedures
PT-2Authority to Process PII
PT-3PII Processing Purposes
PT-6System of Records Notice
PT-7Specific Categories of PII
PT-8Computer Matching Requirements
RA-5Vulnerability Monitoring and Scanning
RA-7Identifies and Analyzes Risk
SA-1Logging and Monitoring
SA-2Common Operating Picture
SA-22Unsupported System Components
SA-3System Development Life Cycle
SA-8Security and Privacy Engineering Principles
SA-9External System Services
SC-1Policy and Procedures
SC-12Cryptographic Key Establishment and Management
SC-13Cryptographic Protection
SC-15Collaborative Computing Devices and Applications
SC-20Secure Name/Address Resolution Service (Authoritative)
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22Architecture and Provisioning for Name/Address Resolution Service
SC-5Denial-of-Service Protection
SI-1Policy and Procedures
SI-12Information Management and Retention
SI-3Malicious Code Protection
SI-5Security Alerts, Advisories, and Directives
SR-1Policy and Procedures (SR-1)
SR-10Inspection of Systems or Components (SR-10)
SR-11Component Authenticity (SR-11)
SR-12Component Disposal (SR-12)
SR-2Supply Chain Risk Management Plan (SR-2)
SR-3Supply Chain Controls and Processes (SR-3)
SR-5Acquisition Strategies, Tools, and Methods (SR-5)
SR-8Notification Agreements (SR-8)
Show the 9 you already have
CA-9Internal System Connections
IR-2Incident Response and Recovery
RA-1Policy and Procedures
AC-19Access Control for Mobile Devices
RA-2Security Categorization
How this is calculated
Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition