Framework overlap

Does CISA Zero Trust Maturity Model cover DoD Zero Trust Reference Architecture?

You hold CISA Zero Trust Maturity Model and have been told to do DoD Zero Trust Reference Architecture. Here is how much overlaps, control by control.

18% of DoD Zero Trust Reference Architecture you already have

CISA Zero Trust Maturity Model already covers about 18% of DoD Zero Trust Reference Architecture, leaving 37 of 45 controls as genuinely new work.

Already covered 0 Likely covered 8 New work 37

No control in CISA Zero Trust Maturity Model maps directly to one in DoD Zero Trust Reference Architecture. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in CISA Zero Trust Maturity Model reaches these. This is the list to scope.

DODZT-1.2
Conditional User Access
DODZT-1.3
Multi-Factor Authentication
DODZT-1.4
Privileged Access Management
DODZT-1.5
Identity Federation and User Credentialing
DODZT-1.6
Behavioral, Contextual ID, and Biometrics
DODZT-1.7
Least Privileged Access
DODZT-1.8
Continuous Authentication
DODZT-1.9
Integrated ICAM Platform
DODZT-2.2
Device Detection and Compliance
DODZT-2.3
Device Authorization with Real-Time Inspection
DODZT-2.4
Remote Access
DODZT-2.5
Partially and Fully Automated Asset, Vulnerability and Patch Management
DODZT-2.6
Unified Endpoint Management and Mobile Device Management
DODZT-3.2
Secure Software Development and Integration
DODZT-3.3
Software Risk Management
DODZT-3.4
Resource Authorization and Integration
DODZT-4.1
Data Catalog Risk Alignment
DODZT-4.2
DoD Enterprise Data Governance
DODZT-4.3
Data Labeling and Tagging
DODZT-4.4
Data Monitoring and Sensing
DODZT-4.5
Data Encryption and Rights Management
DODZT-4.6
Data Loss Prevention
DODZT-4.7
Data Access Control
DODZT-5.1
Data Flow Mapping
DODZT-5.2
Software Defined Networking
DODZT-6.1
Policy Decision Point and Policy Orchestration
DODZT-6.2
Critical Process Automation
DODZT-6.3
Machine Learning
DODZT-6.4
Artificial Intelligence
DODZT-6.5
Security Orchestration, Automation and Response
DODZT-6.6
API Standardization
DODZT-6.7
Security Operations Center and Incident Response
DODZT-7.1
Log All Traffic
DODZT-7.2
Security Information and Event Management
DODZT-7.3
Common Security and Risk Analytics
DODZT-7.5
Threat Intelligence Integration
DODZT-7.6
Automated Dynamic Policies
Show the 8 you already have
DODZT-1.1
User Inventory
DODZT-2.1
Device Inventory
DODZT-2.7
Endpoint and Extended Detection and Response
DODZT-3.1
Application Inventory
DODZT-3.5
Continuous Monitoring and Ongoing Authorizations
DODZT-5.3
Macro Segmentation
DODZT-5.4
Micro Segmentation
DODZT-7.4
User and Entity Behavior Analytics

How this is calculated

Already covered means a mapping runs from a control in CISA Zero Trust Maturity Model to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition