4% of NIST SP 800-53 Rev 5 MODERATE you already have
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 4% of NIST SP 800-53 Rev 5 MODERATE, leaving
263 of 275 controls as genuinely new work.
Already covered 3
Likely covered 9
New work 263
What is genuinely new work
Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.
AC-1Policy and Procedures
AC-11(1)Pattern-hiding Displays
AC-14Permitted Actions Without Identification or Authentication
AC-17(1)Monitoring and Control
AC-17(2)Protection of Confidentiality and Integrity Using Encryption
AC-17(3)Managed Access Control Points
AC-17(4)Privileged Commands and Access
AC-18(1)Authentication and Encryption
AC-18(3)Disable Wireless Networking
AC-19(5)Full Device or Container-Based Encryption
AC-2(1)Automated System Account Management
AC-2(13)Disable Accounts for High-Risk Individuals
AC-2(2)Automated Temporary and Emergency Account Management
AC-2(4)Automated Audit Actions
AC-20Use of External Systems
AC-20(1)Limits on Authorized Use
AC-20(2)Portable Storage Devices Restricted Use
AC-22Publicly Accessible Content
AC-4Information Flow Enforcement
AC-6(1)Authorize Access to Security Functions
AC-6(10)Prohibit Non-Privileged Users from Executing Privileged Functions
AC-6(2)Non-Privileged Access for Nonsecurity Functions
AC-6(5)Privileged Accounts
AC-6(7)Review of User Privileges
AC-6(9)Log Use of Privileged Functions
AC-7Unsuccessful Logon Attempts
AC-8System Use Notification
AT-1Policy and Procedures
AT-2Literacy Training and Awareness
AT-2(3)Social Engineering and Mining
AU-1Policy and Procedures
AU-11Audit Record Retention
AU-12Audit Record Generation
AU-3Content of Audit Records
AU-3(1)Additional Audit Information
AU-4Audit Log Storage Capacity
AU-5Response to Audit Logging Process Failures
AU-6Audit Record Review, Analysis, and Reporting
AU-6(1)Automated Process Integration
AU-6(3)Correlate Audit Record Repositories
AU-7Audit Record Reduction and Report Generation
AU-7(1)Automatic Processing
AU-9Protection of Audit Information
AU-9(4)Access by Subset of Privileged Users
CA-1Policy and Procedures
CA-2(1)Independent Assessors
CA-5Plan of Action and Milestones
CA-7Continuous Monitoring
CA-7(1)Independent Assessment
CM-1Policy and Procedures
CM-10Software Usage Restrictions
CM-11User-Installed Software
CM-12Information Location
CM-12(1)Automated Tools to Support Information Location
CM-2Baseline Configuration
CM-2(2)Automation Support for Accuracy and Currency
CM-2(3)Retention of Previous Configurations
CM-2(7)Configure Systems and Components for High-Risk Areas
CM-3Configuration Change Control
CM-3(2)Testing, Validation, and Documentation of Changes
CM-3(4)Security and Privacy Representatives
CM-4(2)Verification of Controls
CM-5Access Restrictions for Change
CM-6Configuration Settings
CM-7(2)Prevent Program Execution
CM-7(5)Authorized Software Allow-by-Exception
CM-8System Component Inventory
CM-8(1)Updates During Installation and Removal
CM-8(3)Automated Unauthorized Component Detection
CP-1Policy and Procedures
CP-10System Recovery and Reconstitution
CP-10(2)Transaction Recovery
CP-2(1)Coordinate with Related Plans
CP-2(3)Resume Mission and Business Functions
CP-2(8)Identify Critical Assets
CP-4Contingency Plan Testing
CP-4(1)Coordinate with Related Plans
CP-6Alternate Storage Site
CP-6(1)Separation from Primary Site
CP-7Alternate Processing Site
CP-7(1)Separation from Primary Site
CP-7(3)Priority of Service
CP-8Telecommunications Services
CP-8(1)Priority of Service Provisions
CP-8(2)Single Points of Failure
CP-9(1)Testing for Reliability and Integrity
CP-9(8)Cryptographic Protection
IA-1Policy and Procedures
IA-2Identification and Authentication (Organizational Users)
IA-3Device Identification and Authentication
IA-4Identifier Management
IA-5Authenticator Management
IA-6Authentication Feedback
IA-7Cryptographic Module Authentication
IA-8Identification and Authentication (Non-Organizational Users)
IR-1Event Detection and Triage
IR-3Continuity of Operations
IR-7Incident Response Assistance
IR-8Incident Response Plan
MA-1Policy and Procedures
MA-2Controlled Maintenance
MA-5Maintenance Personnel
MP-1Policy and Procedures
PE-1Policy and Procedures
PE-14Environmental Controls
PE-15Water Damage Protection
PE-16Delivery and Removal
PE-2Physical Access Authorizations
PE-3Physical Access Control
PE-6Monitoring Physical Access
PE-8Visitor Access Records
PE-9Power Equipment and Cabling
PL-1Policy and Procedures
PL-2System Security and Privacy Plans
PL-8Security and Privacy Architectures
PM-1Information Security Program Plan
PM-10Authorization Process
PM-11Mission and Business Process Definition
PM-12Insider Threat Program
PM-13Security and Privacy Workforce
PM-14Testing, Training, and Monitoring
PM-15Security and Privacy Groups and Associations
PM-16Threat Awareness Program
PM-17Protecting CUI on External Systems
PM-18Privacy Program Plan
PM-19Privacy Program Leadership Role
PM-2Information Security Program Leadership Role
PM-20Dissemination of Privacy Program Information
PM-21Accounting of Disclosures
PM-22Personally Identifiable Information Quality Management
PM-23Data Governance Body
PM-24Data Integrity Board
PM-25Minimization of PII Used in Testing, Training, and Research
PM-26Complaint Management
PM-29Risk Management Program Leadership Roles
PM-3Information Security and Privacy Resources
PM-30Supply Chain Risk Management Strategy
PM-31Continuous Monitoring Strategy
PM-4Plan of Action and Milestones Process
PM-6Measures of Performance
PM-7Enterprise Architecture
PM-8Critical Infrastructure Plan
PM-9Risk Management Strategy
PS-1Policy and Procedures
PS-2Position Risk Designation
PS-4Personnel Termination
PS-7External Personnel Security
PS-9Position Descriptions
PT-1Policy and Procedures
PT-2Authority to Process PII
PT-3PII Processing Purposes
PT-6System of Records Notice
PT-7Specific Categories of PII
PT-8Computer Matching Requirements
RA-5Vulnerability Monitoring and Scanning
RA-7Identifies and Analyzes Risk
RA-9Identifies and Analyzes Significant Change
SA-1Logging and Monitoring
SA-10Developer Configuration Management
SA-11Developer Testing and Evaluation
SA-15Development Process, Standards, and Tools
SA-2Common Operating Picture
SA-22Unsupported System Components
SA-3System Development Life Cycle
SA-8Security and Privacy Engineering Principles
SA-9External System Services
SC-1Policy and Procedures
SC-12Cryptographic Key Establishment and Management
SC-13Cryptographic Protection
SC-15Collaborative Computing Devices and Applications
SC-17Public Key Infrastructure Certificates
SC-2Separation of System and User Functionality
SC-20Secure Name/Address Resolution Service (Authoritative)
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22Architecture and Provisioning for Name/Address Resolution Service
SC-23Session Authenticity
SC-28Protection of Information at Rest
SC-4Information in Shared System Resources
SC-5Denial-of-Service Protection
SC-8Transmission Confidentiality and Integrity
SI-1Policy and Procedures
SI-10Information Input Validation
SI-12Information Management and Retention
SI-3Malicious Code Protection
SI-5Security Alerts, Advisories, and Directives
SI-7Software, Firmware, and Information Integrity
SR-1Policy and Procedures (SR-1)
SR-10Inspection of Systems or Components (SR-10)
SR-11Component Authenticity (SR-11)
SR-12Component Disposal (SR-12)
SR-2Supply Chain Risk Management Plan (SR-2)
SR-3Supply Chain Controls and Processes (SR-3)
SR-5Acquisition Strategies, Tools, and Methods (SR-5)
SR-6Supplier Assessments and Reviews (SR-6)
SR-8Notification Agreements (SR-8)
Show the 12 you already have
CA-9Internal System Connections
IR-2Incident Response and Recovery
RA-1Policy and Procedures
AC-19Access Control for Mobile Devices
CM-9Configuration Management Plan
PE-4Access Control for Transmission
PE-5Access Control for Output Devices
RA-2Security Categorization
How this is calculated
Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition