27% of FBI CJIS Security Policy you already have
Belgium CyberFundamentals already covers about 27% of FBI CJIS Security Policy, leaving
24 of 33 controls as genuinely new work.
Already covered 0
Likely covered 9
New work 24
No control in Belgium CyberFundamentals
maps directly to one in FBI CJIS Security Policy. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Belgium CyberFundamentals reaches these. This is the list to scope.
CJIS-1Information Exchange Agreements
CJIS-18Security Assessment and Authorization
CJIS-20System Acquisition
CJIS-5.1Information Exchange Agreements
CJIS-5.10System and Communications Protection
CJIS-5.12Personnel Security
CJIS-5.2Security Awareness Training
CJIS-5.3Incident Response
CJIS-5.4Auditing and Accountability
CJIS-5.6Identification and Authentication
CJIS-5.7Configuration Management
CJIS-5.9Physical Protection
CJIS-AM-1Account Management
CJIS-CM-1Cloud Service Provider Controls
CJIS-IR-2Notification to CJIS Systems Officer
CJIS-PE-2Physically Secure Location
CJIS-SC-1Boundary Protection
CJIS-SC-2Wireless Network Protections
Show the 9 you already have
CJIS-10System and Information Integrity
CJIS-14Physical Protection
CJIS-19Supply Chain Risk Management
CJIS-2Security Awareness Training
CJIS-7Configuration Management
CJIS-9System and Communications Protection
How this is calculated
Already covered means a mapping runs from a control in Belgium CyberFundamentals to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition