34% of NIST SP 1800-32 you already have
DAMA-DMBOK2 already covers about 34% of NIST SP 1800-32, leaving
29 of 44 controls as genuinely new work.
Already covered 6
Likely covered 9
New work 29
What is genuinely new work
Nothing in DAMA-DMBOK2 reaches these. This is the list to scope.
DER-DE-01Continuous Monitoring of DER Communications
DER-DE-02Logging and Audit Trail Collection
DER-DE-03Integrity Monitoring of DER Settings
DER-GV-01DER Cybersecurity Governance
DER-GV-02Supply Chain Risk Management for DER
DER-ID-01DER Asset Inventory
DER-ID-02Data Flow Mapping for DER
DER-ID-03DER Threat and Risk Assessment
DER-PR-01Authentication for DER Communications
DER-PR-02Secure Configuration of DER Devices
DER-PR-03Network Segmentation for DER Operations
DER-PR-04Cryptographic Protection of DER Communications
DER-PR-05Identity and Access Management for DER Operators
DER-PR-06Secure Firmware Update Process
DER-RC-01Recovery Planning for DER
DER-RC-02Backup and Configuration Restoration
DER-RC-03Lessons Learned and Continuous Improvement
DER-RS-01Incident Response for DER
DER-RS-02Isolation and Containment Procedures
DER-RS-03Communication with External Stakeholders
NIST1800-32-01Critical asset identification and inventory
NIST1800-32-03Security governance structure
NIST1800-32-04Roles and responsibilities for critical systems
NIST1800-32-06Physical and logical access controls
NIST1800-32-10Revocation of access procedures
NIST1800-32-11Security patch management for OT
NIST1800-32-15Ports and services management
NIST1800-32-16Incident response plan for operational disruptions
NIST1800-32-17Recovery plan for critical systems
Show the 15 you already have
NIST1800-32-07Personnel risk assessment
NIST1800-32-08Electronic access perimeter management
NIST1800-32-09Interactive remote access security
NIST1800-32-18Reporting obligations to authorities
NIST1800-32-19Coordination with sector-specific agencies
NIST1800-32-20Exercises and drills for OT incidents
NIST1800-32-02System security categorization
NIST1800-32-05Security policy for operational technology
NIST1800-32-12Malware prevention for operational systems
NIST1800-32-13Network security monitoring
NIST1800-32-14System security hardening
NIST1800-32-21Supply chain risk management for critical components
NIST1800-32-22Configuration management for OT systems
NIST1800-32-23Change management procedures
NIST1800-32-24Vulnerability assessment for critical systems
How this is calculated
Already covered means a mapping runs from a control in DAMA-DMBOK2 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition