Framework overlap

Does GDPR cover NIST SP 800-171?

You hold GDPR and have been told to do NIST SP 800-171. Here is how much overlaps, control by control.

11% of NIST SP 800-171 you already have

GDPR already covers about 11% of NIST SP 800-171, leaving 83 of 93 controls as genuinely new work.

Already covered 0 Likely covered 10 New work 83

No control in GDPR maps directly to one in NIST SP 800-171. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in GDPR reaches these. This is the list to scope.

171-AC-1
Access Control Policy and Procedures
171-AC-2
Least Privilege and Separation of Duties
171-AC-3
Remote Access and Mobile Devices
171-AT-1
Security Awareness and Role-Based Training
171-AU-1
Audit Event Capture
171-AU-2
Audit Review and Analysis
171-CM-1
Baseline Configuration and Inventory
171-IA-1
Identification and Authentication
171-IA-2
Multi-Factor Authentication
171-IR-1
Incident Handling Capability
171-IR-2
Incident Reporting
171-MA-1
Maintenance Authorisation and Control
171-MP-1
Media Protection
171-PE-1
Physical Access Authorisations
171-RA-2
Vulnerability Scanning and Remediation
171-SC-1
Boundary Protection
171-SC-2
Encryption of Controlled Unclassified Information
171-SI-1
Flaw Remediation
171-SI-2
Malicious Code Protection
3.1.1
Authorized Access Control
3.1.2
Transaction and Function Control
3.1.20
External Connections Control
3.10.6
Alternate Work Site Safeguards
3.11.1
Risk Assessments
3.11.2
Vulnerability Scanning
3.12.1
Security Control Assessment
3.13.11
Cryptographic Protection
3.13.5
Network Segmentation
3.13.8
Transmission Confidentiality
3.14.1
Flaw Remediation
3.14.6
Monitoring for Attacks
3.4.1
Baseline Configuration Maintenance
3.4.6
Least Functionality
3.5.3
Multi Factor Authentication
3.8.3
Media Sanitization
3.9.2
Personnel Transfer and Termination
A.03.01.01
Account Management Assessment
A.03.01.05
Least Privilege Assessment
A.03.01.12
Remote Access Assessment
A.03.03.01
Event Logging Assessment
A.03.04.01
Baseline Configuration Assessment
A.03.04.02
Configuration Settings Assessment
A.03.05.03
Multi Factor Authentication Assessment
A.03.06.01
Incident Handling Assessment
A.03.07.04
Maintenance Tools Assessment
A.03.08.03
Media Sanitization Assessment
A.03.09.02
Personnel Termination Assessment
A.03.10.01
Physical Access Authorization Assessment
A.03.11.01
Risk Assessment Process
A.03.11.02
Vulnerability Monitoring Assessment
A.03.12.01
Security Control Assessments
A.03.13.11
Cryptographic Protection of CUI at Rest
A.03.14.01
Flaw Remediation Assessment
A.03.14.06
System Monitoring Assessment
A.03.15.01
System Security Plan Assessment
SP800-171-3.10.1
Limit physical access
SP800-171-3.10.3
Escort and monitor visitors
SP800-171-3.10.6
Safeguard CUI at alternate work sites
SP800-171-3.12.1
Periodically assess security controls
SP800-171-3.12.2
Plans of action for deficiencies
SP800-171-3.12.3
Continuously monitor controls
SP800-171-3.13.1
Monitor and protect communications at boundaries
SP800-171-3.13.6
Deny network traffic by default
SP800-171-3.13.8
Encrypt CUI in transmission
SP800-171-3.14.1
Identify, report, and correct flaws
SP800-171-3.14.2
Malicious code protection
SP800-171-3.14.3
Monitor security alerts and advisories
SP800-171-3.14.6
Monitor systems and traffic for attacks
SP800-171-3.5.1
Identify system users, processes, and devices
SP800-171-3.5.10
Store and transmit only encrypted passwords
SP800-171-3.5.2
Authenticate identities before access
SP800-171-3.5.3
Multifactor authentication for privileged/network access
SP800-171-3.5.4
Replay-resistant authentication
SP800-171-3.6.1
Operational incident-handling capability
SP800-171-3.6.3
Test incident response capability
SP800-171-3.7.1
Perform system maintenance
SP800-171-3.7.2
Control maintenance tools and personnel
SP800-171-3.7.5
MFA for nonlocal maintenance
SP800-171-3.8.1
Protect system media containing CUI
SP800-171-3.8.3
Sanitize or destroy media before disposal
SP800-171-3.8.7
Control removable media
SP800-171-3.9.1
Screen individuals before CUI access
SP800-171-3.9.2
Protect CUI during personnel actions
Show the 10 you already have
171-RA-1
Risk Assessment
3.3.1
Audit Record Creation
3.6.1
Incident Response Capability
SP800-171-3.11.1
Periodically assess risk
SP800-171-3.11.2
Scan for vulnerabilities
SP800-171-3.11.3
Remediate vulnerabilities
SP800-171-3.13.11
Employ FIPS-validated cryptography
SP800-171-3.13.16
Protect confidentiality of CUI at rest
SP800-171-3.6.2
Track, document, and report incidents
SP800-171-3.8.6
Encrypt CUI on digital media during transport

How this is calculated

Already covered means a mapping runs from a control in GDPR to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition