3% of FedRAMP Moderate you already have
Belgium CyberFundamentals already covers about 3% of FedRAMP Moderate, leaving
232 of 238 controls as genuinely new work.
Already covered 0
Likely covered 6
New work 232
No control in Belgium CyberFundamentals
maps directly to one in FedRAMP Moderate. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Belgium CyberFundamentals reaches these. This is the list to scope.
AC-1Policy and Procedures
AC-10Concurrent Session Control
AC-14Permitted Actions Without Identification or Authentication
AC-17(1)Monitoring and Control
AC-17(2)Protection of Confidentiality and Integrity Using Encryption
AC-17(3)Managed Access Control Points
AC-17(4)Privileged Commands and Access
AC-18(1)Authentication and Encryption
AC-19Access Control for Mobile Devices
AC-19(5)Full Device or Container-Based Encryption
AC-2(1)Automated System Account Management
AC-2(12)Account Monitoring for Atypical Usage
AC-2(13)Disable Accounts for High-Risk Individuals
AC-2(2)Automated Temporary and Emergency Account Management
AC-2(4)Automated Audit Actions
AC-2(7)Privileged User Accounts
AC-2(9)Restrictions on Use of Shared and Group Accounts
AC-20Use of External Systems
AC-20(1)Limits on Authorized Use
AC-20(2)Portable Storage Devices Restricted Use
AC-22Publicly Accessible Content
AC-4Information Flow Enforcement
AC-4(21)Physical or Logical Separation of Information Flows
AC-6(1)Authorize Access to Security Functions
AC-6(10)Prohibit Non-Privileged Users from Executing Privileged Functions
AC-6(2)Non-Privileged Access for Nonsecurity Functions
AC-6(5)Privileged Accounts
AC-6(7)Review of User Privileges
AC-6(9)Log Use of Privileged Functions
AC-7Unsuccessful Logon Attempts
AC-8System Use Notification
AT-1Policy and Procedures
AT-2Literacy Training and Awareness
AT-2(3)Social Engineering and Mining
AU-1Policy and Procedures
AU-11Audit Record Retention
AU-12Audit Record Generation
AU-3Content of Audit Records
AU-3(1)Additional Audit Information
AU-4Audit Log Storage Capacity
AU-5Response to Audit Logging Process Failures
AU-6Audit Record Review, Analysis, and Reporting
AU-6(1)Automated Process Integration
AU-6(3)Correlate Audit Record Repositories
AU-7Audit Record Reduction and Report Generation
AU-7(1)Automatic Processing
AU-9Protection of Audit Information
AU-9(2)Store on Separate Physical Systems or Components
AU-9(4)Access by Subset of Privileged Users
CA-1Policy and Procedures
CA-2(1)Independent Assessors
CA-5Plan of Action and Milestones
CA-7Continuous Monitoring
CA-7(1)Independent Assessment
CM-1Policy and Procedures
CM-10Software Usage Restrictions
CM-11User-Installed Software
CM-2Baseline Configuration
CM-2(2)Automation Support for Accuracy and Currency
CM-2(3)Retention of Previous Configurations
CM-2(7)Configure Systems and Components for High-Risk Areas
CM-3Configuration Change Control
CM-3(2)Testing, Validation, and Documentation of Changes
CM-3(4)Security and Privacy Representatives
CM-5Access Restrictions for Change
CM-6Configuration Settings
CM-6(1)Automated Management, Application, and Verification
CM-7(2)Prevent Program Execution
CM-7(5)Authorized Software Allow-by-Exception
CM-8System Component Inventory
CM-8(1)Updates During Installation and Removal
CM-8(3)Automated Unauthorized Component Detection
CM-9Configuration Management Plan
CP-1Policy and Procedures
CP-10System Recovery and Reconstitution
CP-2(1)Coordinate with Related Plans
CP-2(3)Resume Mission and Business Functions
CP-4Contingency Plan Testing
CP-4(1)Coordinate with Related Plans
CP-6Alternate Storage Site
CP-7Alternate Processing Site
CP-8Telecommunications Services
CP-9(1)Testing for Reliability and Integrity
IA-1Policy and Procedures
IA-2Identification and Authentication (Organizational Users)
IA-2(1)MFA to Privileged Accounts
IA-2(12)Acceptance of PIV Credentials
IA-2(2)MFA to Non-Privileged Accounts
IA-2(8)Access to Accounts Replay Resistant
IA-3Device Identification and Authentication
IA-4Identifier Management
IA-5Authenticator Management
IA-5(1)Password-Based Authentication
IA-5(2)Public Key-Based Authentication
IA-5(6)Protection of Authenticators
IA-6Authentication Feedback
IA-7Cryptographic Module Authentication
IA-8Identification and Authentication (Non-Organizational Users)
IR-1Event Detection and Triage
IR-3Continuity of Operations
IR-4(1)Automated Incident Handling Processes
IR-6(1)Automated Reporting
IR-7Incident Response Assistance
IR-8Incident Response Plan
MA-1Policy and Procedures
MA-2Controlled Maintenance
MA-5Maintenance Personnel
MP-1Policy and Procedures
PE-1Policy and Procedures
PE-14Environmental Controls
PE-16Delivery and Removal
PE-2Physical Access Authorizations
PE-3Physical Access Control
PE-6Monitoring Physical Access
PE-8Visitor Access Records
PL-1Policy and Procedures
PL-2System Security and Privacy Plans
PL-8Security and Privacy Architectures
PS-1Policy and Procedures
PS-2Position Risk Designation
PS-4Personnel Termination
PS-7External Personnel Security
RA-2Security Categorization
RA-5Vulnerability Monitoring and Scanning
RA-5(2)Update Vulnerabilities to be Scanned
RA-7Identifies and Analyzes Risk
SA-1Logging and Monitoring
SA-10Developer Configuration Management
SA-11Developer Testing and Evaluation
SA-2Common Operating Picture
SA-3System Development Life Cycle
SA-4(10)Use of Approved PIV Products
SA-8Security and Privacy Engineering Principles
SA-9External System Services
SA-9(2)Identification of Functions, Ports, Protocols, and Services
SC-1Policy and Procedures
SC-12Cryptographic Key Establishment and Management
SC-13Cryptographic Protection
SC-15Collaborative Computing Devices and Applications
SC-17Public Key Infrastructure Certificates
SC-2Separation of System and User Functionality
SC-20Secure Name/Address Resolution Service (Authoritative)
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22Architecture and Provisioning for Name/Address Resolution Service
SC-23Session Authenticity
SC-28Protection of Information at Rest
SC-28(1)Cryptographic Protection
SC-4Information in Shared System Resources
SC-5Denial-of-Service Protection
SC-7(4)External Telecommunications Services
SC-7(5)Deny by Default Allow by Exception
SC-7(7)Split Tunneling for Remote Devices
SC-7(8)Route Traffic to Authenticated Proxy Servers
SC-8Transmission Confidentiality and Integrity
SC-8(1)Cryptographic Protection
SI-1Policy and Procedures
SI-10Information Input Validation
SI-12Information Management and Retention
SI-2(2)Automated Flaw Remediation Status
SI-3Malicious Code Protection
SI-4(2)Automated Tools and Mechanisms for Real-Time Analysis
SI-4(4)Inbound and Outbound Communications Traffic
SI-4(5)System-Generated Alerts
SI-5Security Alerts, Advisories, and Directives
SI-7Software, Firmware, and Information Integrity
SI-7(7)Integration of Detection and Response
SR-1Policy and Procedures (SR-1)
SR-10Inspection of Systems or Components (SR-10)
SR-11Component Authenticity (SR-11)
SR-12Component Disposal (SR-12)
SR-2Supply Chain Risk Management Plan (SR-2)
SR-3Supply Chain Controls and Processes (SR-3)
SR-5Acquisition Strategies, Tools, and Methods (SR-5)
SR-6Supplier Assessments and Reviews (SR-6)
SR-8Notification Agreements (SR-8)
Show the 6 you already have
CA-9Internal System Connections
IR-2Incident Response and Recovery
RA-1Policy and Procedures
How this is calculated
Already covered means a mapping runs from a control in Belgium CyberFundamentals to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition