Framework overlap

Does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 cover GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6?

You hold CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 and have been told to do GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6. Here is how much overlaps, control by control.

17% of GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6 you already have

CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 already covers about 17% of GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6, leaving 10 of 12 controls as genuinely new work.

Already covered 1 Likely covered 1 New work 10

What is genuinely new work

Nothing in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 reaches these. This is the list to scope.

GGAP-2024-2025-Pipeline-EUGreenDeal-CSRD-AI
GLOBALG.A.P. IFA v6 2024-2025 Pipeline: EU Green Deal, CSRD, EUDR, AI and Sustainability
GGAP-AddOns-GRASP-SPRING-Planet-Forest
GLOBALG.A.P. IFA v6 Add-Ons: GRASP, SPRING, Planet Pro, Forest Responsible and Retailer-Specific
GGAP-Certification-CB-Auditing-MajorMinorMust
GLOBALG.A.P. IFA v6 Certification Bodies, Audit Lifecycle and Compliance Categories
GGAP-Crosswalk-GFSI-FSSC22000-BRCGS-IFS-SQF
GLOBALG.A.P. IFA v6 Crosswalk to GFSI, FSSC 22000, BRCGS, IFS, SQF, ISO 22000 and Codex
GGAP-IFA-LivestockBase-Aquaculture-ProductSpecific
GLOBALG.A.P. IFA v6 Livestock Base (LB), Aquaculture Base (AB) and Product-Specific Standards
GGAP-IFA-v6-Scheme-GFSI-Versions
GLOBALG.A.P. IFA v6 Scheme Structure, GFSI Recognition and Version Lineage
GGAP-Implementation-Roadmap-CIPRO-IT-Smart
GLOBALG.A.P. IFA v6 Implementation Roadmap, CIPRO IT-System, Producer Roles
GGAP-Sectoral-Geographic-Adoption-200K-130Countries
GLOBALG.A.P. IFA v6 Sectoral + Geographic Adoption (~200K Producers in 130+ Countries)
GGAP-Status-FoodPLUS-Governance-StakeholderEngagement
GLOBALG.A.P. Status, FoodPLUS Governance, Stakeholder Engagement and Future Roadmap
GGAP-Sub-Schemes-CFM-LOG-CoC-PoC-Localgap
GLOBALG.A.P. Sub-Schemes: CFM, Logistics, CoC, PoC, localg.a.p. and Special Standards
Show the 2 you already have
GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace
GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
GGAP-IFA-CropsBase-Production-PPP-IPM
GLOBALG.A.P. IFA v6 Crops Base (CB): Propagation, Soil, Water, IPM, PPP, Fertilizer and Harvest

How this is calculated

Already covered means a mapping runs from a control in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition