31% of NIST SP 800-160 you already have
CISA Zero Trust Maturity Model already covers about 31% of NIST SP 800-160, leaving
34 of 49 controls as genuinely new work.
Already covered 0
Likely covered 15
New work 34
No control in CISA Zero Trust Maturity Model
maps directly to one in NIST SP 800-160. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in CISA Zero Trust Maturity Model reaches these. This is the list to scope.
SE-ACAssurance Case Development
SE-ARCHArchitecture Definition
SE-BCBusiness or Mission Analysis
SE-CMConfiguration Management Process
SE-HFHuman Factors in Secure Systems Engineering
SE-IAInformation Assurance and Security Engineering Trade-offs
SE-QAQuality Assurance Process
SE-RMRisk Management Process
SE-SNStakeholder Needs and Requirements Definition
SE-SRSystem Requirements Definition
SP800-160-AGR-ACQAcquisition Process
SP800-160-AGR-SUPSupply Process
SP800-160-OPE-HRHuman Resource Management Process
SP800-160-TE-ANALYSISSystem Analysis Process
SP800-160-TE-ARCHArchitecture Definition Process
SP800-160-TE-DESIGNDesign Definition Process
SP800-160-TE-DISPOSALDisposal Process
SP800-160-TE-INTEGIntegration Process
SP800-160-TE-MAINTAINMaintenance Process
SP800-160-TE-STAKEStakeholder Needs and Requirements Definition Process
SP800-160-TE-SYSREQSystem Requirements Definition Process
SP800-160-TM-ASSESSProject Assessment and Control Process
SP800-160-TM-INFOInformation Management Process
SP800-160-TM-RISKRisk Management Process
Show the 15 you already have
SP800-160-OPE-INFRAInfrastructure Management Process
SP800-160-OPE-KMKnowledge Management Process
SP800-160-OPE-LCMLife Cycle Model Management Process
SP800-160-OPE-PORTFOLIOPortfolio Management Process
SP800-160-OPE-QMQuality Management Process
SP800-160-TE-IMPLImplementation Process
SP800-160-TE-OPERATEOperation Process
SP800-160-TE-TRANSTransition Process
SP800-160-TE-VALIDATEValidation Process
SP800-160-TE-VERIFYVerification Process
SP800-160-TM-CONFIGConfiguration Management Process
SP800-160-TM-DECISIONDecision Management Process
SP800-160-TM-MEASUREMeasurement Process
SP800-160-TM-PLANProject Planning Process
SP800-160-TM-QAQuality Assurance Process
How this is calculated
Already covered means a mapping runs from a control in CISA Zero Trust Maturity Model to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition