Framework overlap

Does Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 cover NIST SP 800-128?

You hold Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 and have been told to do NIST SP 800-128. Here is how much overlaps, control by control.

33% of NIST SP 800-128 you already have

Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 already covers about 33% of NIST SP 800-128, leaving 26 of 39 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 26

No control in Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 maps directly to one in NIST SP 800-128. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 reaches these. This is the list to scope.

SP800-128-ACCESS-RESTRICT
Access Restrictions for Change
SP800-128-PH-PLAN
SecCM Phase: Planning
SP800-128-PLAN-DOC
Configuration Management Plan
SP800-128-POLICY
Configuration Management Policy and Procedures
SP800-128-SIA
Security Impact Analysis
SecCM-CHANGE-3
Access Restrictions for Change
SecCM-CHANGE-4
Testing and Validation
SecCM-CHANGE-5
Retention of Configuration Records
SecCM-CHANGE-6
Automated Change Control Tools
SecCM-CHANGE-7
Emergency Change Handling
SecCM-ID-1
Configuration Item Identification
SecCM-ID-4
Least Functionality
SecCM-ID-5
Implementation and Provisioning
SecCM-MONITOR-1
Continuous Monitoring of Configurations
SecCM-MONITOR-2
Configuration Drift Detection
SecCM-MONITOR-3
Vulnerability Identification and Remediation
SecCM-MONITOR-4
Compliance Reporting
SecCM-MONITOR-5
Unauthorized Change Detection
SecCM-MONITOR-6
Metrics and Measurement
SecCM-MONITOR-7
Feedback into Baselines
SecCM-MONITOR-8
Audit and Independent Assessment
SecCM-PLAN-1
SecCM Policy and Procedures
SecCM-PLAN-2
SecCM Plan
SecCM-PLAN-3
Roles and Responsibilities
SecCM-PLAN-4
Integration with Organizational CM
SecCM-PLAN-5
Tools, Techniques, and Resources
Show the 13 you already have
SP800-128-BASELINE
Baseline Configuration
SP800-128-CCB
Configuration Control Board
SP800-128-CHANGE-CONTROL
Configuration Change Control
SP800-128-CONFIG-ITEMS
Configuration Items
SP800-128-INVENTORY
Component Inventory
SP800-128-MONITORING
Configuration Monitoring
SP800-128-PH-CONTROL
SecCM Phase: Controlling Configuration Changes
SP800-128-PH-IDENTIFY
SecCM Phase: Identifying and Implementing Configurations
SP800-128-PH-MONITOR
SecCM Phase: Monitoring
SP800-128-SECURE-CONFIG
Secure Configurations of Information Systems
SecCM-CHANGE-1
Configuration Change Control Process
SecCM-ID-2
Baseline Configuration Development
SecCM-ID-3
Common Secure Configurations

How this is calculated

Already covered means a mapping runs from a control in Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition