Framework overlap

Does CISA Zero Trust Maturity Model cover NIST SP 800-160?

You hold CISA Zero Trust Maturity Model and have been told to do NIST SP 800-160. Here is how much overlaps, control by control.

31% of NIST SP 800-160 you already have

CISA Zero Trust Maturity Model already covers about 31% of NIST SP 800-160, leaving 34 of 49 controls as genuinely new work.

Already covered 0 Likely covered 15 New work 34

No control in CISA Zero Trust Maturity Model maps directly to one in NIST SP 800-160. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in CISA Zero Trust Maturity Model reaches these. This is the list to scope.

SE-AC
Assurance Case Development
SE-ARCH
Architecture Definition
SE-BC
Business or Mission Analysis
SE-CM
Configuration Management Process
SE-DES
Design Definition
SE-DIS
Disposal
SE-HF
Human Factors in Secure Systems Engineering
SE-IA
Information Assurance and Security Engineering Trade-offs
SE-IMP
Implementation
SE-INT
Integration
SE-MNT
Maintenance
SE-OP
Operation
SE-QA
Quality Assurance Process
SE-RM
Risk Management Process
SE-SA
System Analysis
SE-SN
Stakeholder Needs and Requirements Definition
SE-SR
System Requirements Definition
SE-TR
Transition
SE-VAL
Validation
SE-VER
Verification
SP800-160-AGR-ACQ
Acquisition Process
SP800-160-AGR-SUP
Supply Process
SP800-160-OPE-HR
Human Resource Management Process
SP800-160-TE-ANALYSIS
System Analysis Process
SP800-160-TE-ARCH
Architecture Definition Process
SP800-160-TE-DESIGN
Design Definition Process
SP800-160-TE-DISPOSAL
Disposal Process
SP800-160-TE-INTEG
Integration Process
SP800-160-TE-MAINTAIN
Maintenance Process
SP800-160-TE-STAKE
Stakeholder Needs and Requirements Definition Process
SP800-160-TE-SYSREQ
System Requirements Definition Process
SP800-160-TM-ASSESS
Project Assessment and Control Process
SP800-160-TM-INFO
Information Management Process
SP800-160-TM-RISK
Risk Management Process
Show the 15 you already have
SP800-160-OPE-INFRA
Infrastructure Management Process
SP800-160-OPE-KM
Knowledge Management Process
SP800-160-OPE-LCM
Life Cycle Model Management Process
SP800-160-OPE-PORTFOLIO
Portfolio Management Process
SP800-160-OPE-QM
Quality Management Process
SP800-160-TE-IMPL
Implementation Process
SP800-160-TE-OPERATE
Operation Process
SP800-160-TE-TRANS
Transition Process
SP800-160-TE-VALIDATE
Validation Process
SP800-160-TE-VERIFY
Verification Process
SP800-160-TM-CONFIG
Configuration Management Process
SP800-160-TM-DECISION
Decision Management Process
SP800-160-TM-MEASURE
Measurement Process
SP800-160-TM-PLAN
Project Planning Process
SP800-160-TM-QA
Quality Assurance Process

How this is calculated

Already covered means a mapping runs from a control in CISA Zero Trust Maturity Model to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition