24% of NIST SP 800-53 Rev 5 you already have
FedRAMP Rev 5 already covers about 24% of NIST SP 800-53 Rev 5, leaving
145 of 192 controls as genuinely new work.
Already covered 0
Likely covered 47
New work 145
No control in FedRAMP Rev 5
maps directly to one in NIST SP 800-53 Rev 5. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in FedRAMP Rev 5 reaches these. This is the list to scope.
NIST800-AC-1Access control policy and procedures
NIST800-AC-12Session control
NIST800-AC-14Permitted actions without identification or authentication
NIST800-AC-18Wireless access
NIST800-AC-19Access control for mobile devices
NIST800-AC-22Publicly accessible content
NIST800-AC-4Information flow enforcement
NIST800-AC-5Separation of duties
NIST800-AT-1Policy and procedures for awareness and training
NIST800-AT-2Literacy training and awareness
NIST800-AT-4Training records
NIST800-AT-6Training feedback
NIST800-AU-1Policy and procedures for audit and accountability
NIST800-AU-11Audit record retention
NIST800-AU-4Audit log storage capacity
NIST800-AU-5Response to audit logging process failures
NIST800-AU-6Audit record review, analysis, and reporting
NIST800-AU-7Audit record reduction and report generation
NIST800-AU-9Protection of audit information
NIST800-CA-1Policy and procedures for assessment, authorization, and monitoring
NIST800-CA-3Information exchange
NIST800-CA-5Plan of action and milestones
NIST800-CA-6Authorization
NIST800-CA-9Internal system connections
NIST800-CM-1Policy and procedures for configuration management
NIST800-CM-10Software usage restrictions
NIST800-CM-11User-installed software
NIST800-CM-2Baseline configuration
NIST800-CM-5Access restrictions for change
NIST800-CM-7Least functionality
NIST800-CP-3Contingency training
NIST800-CP-4Contingency plan testing
NIST800-CP-6Alternate storage site
NIST800-CP-7Alternate processing site
NIST800-IA-1Policy and procedures for identification and authentication
NIST800-IA-11Re-authentication
NIST800-IA-12Identity proofing
NIST800-IA-2Identification and authentication of organizational users
NIST800-IA-3Device identification and authentication
NIST800-IA-5Authenticator management
NIST800-IA-6Authentication feedback
NIST800-IR-1Policy and procedures for incident response
NIST800-IR-3Incident response testing
NIST800-IR-6Incident reporting
NIST800-IR-8Incident response plan
NIST800-MA-1Policy and procedures for maintenance
NIST800-MA-2Controlled maintenance
NIST800-MA-3Maintenance tools
NIST800-MA-4Nonlocal maintenance
NIST800-MA-5Maintenance personnel
NIST800-MP-1Policy and procedures for media protection
NIST800-MP-3Media marking
NIST800-MP-4Media storage
NIST800-MP-5Media transport
NIST800-MP-6Media sanitization
NIST800-PE-1Policy and procedures for physical and environmental protection
NIST800-PE-10Emergency shutoff
NIST800-PE-11Emergency power
NIST800-PE-12Emergency lighting
NIST800-PE-13Fire protection
NIST800-PE-15Water damage protection
NIST800-PE-17Alternate work site
NIST800-PE-4Access control for transmission
NIST800-PE-5Access control for output devices
NIST800-PE-6Monitoring physical access
NIST800-PE-8Visitor access records
NIST800-PE-9Power equipment and cabling
NIST800-PL-1Policy and procedures for planning
NIST800-PL-10Baseline selection
NIST800-PL-11Baseline tailoring
NIST800-PL-2System security and privacy plans
NIST800-PL-4Rules of behavior
NIST800-PL-8Security and privacy architectures
NIST800-PS-1Policy and procedures for personnel security
NIST800-PS-2Position risk designation
NIST800-PS-3Personnel screening
NIST800-PS-4Personnel termination
NIST800-PS-5Personnel transfer
NIST800-PS-6Access agreements
NIST800-PS-7External personnel security
NIST800-PS-8Personnel sanctions
NIST800-PS-9Position descriptions
NIST800-RA-10Threat hunting
NIST800-RA-7Risk response
NIST800-RA-9Criticality analysis
NIST800-SA-1Policy and procedures for system and services acquisition
NIST800-SA-11Developer testing and evaluation
NIST800-SA-15Development process, standards, and tools
NIST800-SA-2Allocation of resources
NIST800-SA-22Developer security and privacy architecture
NIST800-SA-3System development life cycle
NIST800-SA-4Acquisition process
NIST800-SA-5System documentation
NIST800-SA-8Security and privacy engineering principles
NIST800-SA-9External system services
NIST800-SC-1Policy and procedures for system and communications protection
NIST800-SC-10Network disconnect
NIST800-SC-15Collaborative computing devices and applications
NIST800-SC-17Public key infrastructure certificates
NIST800-SC-2Separation of system and user functionality
NIST800-SC-20Secure name/address resolution service
NIST800-SC-21Secure name/address resolution service (recursive)
NIST800-SC-23Session authenticity
NIST800-SC-39Process isolation
NIST800-SC-4Information in shared system resources
NIST800-SC-5Denial-of-service protection
NIST800-SC-7Boundary protection
NIST800-SC-8Transmission confidentiality and integrity
NIST800-SI-1Policy and procedures for system and information integrity
NIST800-SI-10Information input validation
NIST800-SI-12Information management and retention
NIST800-SI-16Memory protection
NIST800-SI-3Malicious code protection
NIST800-SI-4System monitoring
NIST800-SI-5Security alerts, advisories, and directives
NIST800-SI-7Software, firmware, and information integrity
NIST800-SR-1Policy and procedures for supply chain risk management
NIST800-SR-10Inspection of systems or components
NIST800-SR-12Component disposal
NIST800-SR-2Supply chain risk management plan
NIST800-SR-5Acquisition strategies, tools, and methods
SP800-53-ACAccess Control Family
SP800-53-ATAwareness and Training Family
SP800-53-AUAudit and Accountability Family
SP800-53-CAAssessment, Authorization, and Monitoring Family
SP800-53-CMConfiguration Management Family
SP800-53-CPContingency Planning Family
SP800-53-IAIdentification and Authentication Family
SP800-53-IRIncident Response Family
SP800-53-MAMaintenance Family
SP800-53-MPMedia Protection Family
SP800-53-PEPhysical and Environmental Protection Family
SP800-53-PLPlanning Family
SP800-53-PMProgram Management Family
SP800-53-PSPersonnel Security Family
SP800-53-PTPII Processing and Transparency Family
SP800-53-RARisk Assessment Family
SP800-53-SASystem and Services Acquisition Family
SP800-53-SCSystem and Communications Protection Family
SP800-53-SISystem and Information Integrity Family
SP800-53-SRSupply Chain Risk Management Family
Show the 47 you already have
NIST800-AC-17Remote access
NIST800-AC-2Account management
NIST800-AC-20Use of external systems
NIST800-AC-3Access enforcement
NIST800-AC-6Least privilege
NIST800-AC-7Unsuccessful logon attempts
NIST800-AT-3Role-based training
NIST800-AU-12Audit record generation
NIST800-AU-2Event logging
NIST800-AU-3Content of audit records
NIST800-CA-2Control assessments
NIST800-CA-7Continuous monitoring
NIST800-CA-8Penetration testing
NIST800-CM-3Configuration change control
NIST800-CM-4Impact analyses
NIST800-CM-6Configuration settings
NIST800-CM-8System component inventory
NIST800-CM-9Configuration management plan
NIST800-CP-1Policy and procedures for contingency planning
NIST800-CP-10System recovery and reconstitution
NIST800-CP-2Contingency plan
NIST800-CP-8Telecommunications services
NIST800-CP-9System backup
NIST800-IA-4Identifier management
NIST800-IA-7Cryptographic module authentication
NIST800-IA-8Identification and authentication of non-organizational users
NIST800-IR-2Incident response training
NIST800-IR-4Incident handling
NIST800-IR-5Incident monitoring
NIST800-IR-7Incident response assistance
NIST800-PE-14Environmental controls
NIST800-PE-2Physical access authorizations
NIST800-PE-3Physical access control
NIST800-RA-1Policy and procedures for risk assessment
NIST800-RA-2Security categorization
NIST800-RA-3Risk assessment
NIST800-RA-5Vulnerability monitoring and scanning
NIST800-SA-10Developer configuration management
NIST800-SC-12Cryptographic key establishment and management
NIST800-SC-13Cryptographic protection
NIST800-SC-22Architecture and provisioning for name/address resolution service
NIST800-SC-28Protection of information at rest
NIST800-SI-2Flaw remediation
NIST800-SR-11Component authenticity
NIST800-SR-3Supply chain controls and processes
NIST800-SR-6Supplier assessments and reviews
NIST800-SR-8Notification agreements
How this is calculated
Already covered means a mapping runs from a control in FedRAMP Rev 5 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition