Framework overlap

Does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 cover FIRST CSIRT Services Framework and Standards?

You hold CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 and have been told to do FIRST CSIRT Services Framework and Standards. Here is how much overlaps, control by control.

25% of FIRST CSIRT Services Framework and Standards you already have

CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 already covers about 25% of FIRST CSIRT Services Framework and Standards, leaving 9 of 12 controls as genuinely new work.

Already covered 2 Likely covered 1 New work 9

What is genuinely new work

Nothing in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 reaches these. This is the list to scope.

FIRST-CSIRTF-Mandate-Quality
CSIRT Services Framework v2.1 - Mandate, Scope and Quality Management
FIRST-CSIRTF-SA1-ISEM
Service Area 1 - Information Security Event Management (Monitoring, Detection, Triage)
FIRST-CSIRTF-SA4-SituationalAwareness
Service Area 4 - Situational Awareness and Threat Intelligence
FIRST-CVSS-v4
FIRST Common Vulnerability Scoring System (CVSS) v4.0 (2023) and CVSS v3.1 Legacy
FIRST-IEP-MPCVD
FIRST Information Exchange Policy (IEP) v2.0 + Multi-Party Coordinated Vulnerability Disclosure (MPCVD)
FIRST-PSIRT-Services
FIRST PSIRT Services Framework (2020) - Product Security Incident Response Team Service Catalog
FIRST-Sectoral-NationalCSIRT
FIRST Sectoral Coordination - National CSIRTs, ISACs, ENISA, NIS2 + Industry Frameworks
FIRST-Status-Pipeline
FIRST Standards Pipeline - 2024-2025 Roadmap and Coordination with NIS2, CIRCIA, EU CRA
FIRST-TLP-v2
FIRST Traffic Light Protocol (TLP) v2.0 (2022) - Information-Sharing Classification
Show the 3 you already have
FIRST-CSIRTF-SA3-VulnMgmt
Service Area 3 - Vulnerability Management and Coordinated Disclosure
FIRST-CSIRTF-SA5-KnowledgeTransfer
Service Area 5 - Knowledge Transfer (Awareness, Training, Exercises, Advisory)
FIRST-CSIRTF-SA2-ISIM
Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)

How this is calculated

Already covered means a mapping runs from a control in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition