4% of NIST SP 800-53 Rev 5 LOW you already have
GDPR already covers about 4% of NIST SP 800-53 Rev 5 LOW, leaving
166 of 173 controls as genuinely new work.
Already covered 2
Likely covered 5
New work 166
What is genuinely new work
Nothing in GDPR reaches these. This is the list to scope.
AC-1Policy and Procedures
AC-14Permitted Actions Without Identification or Authentication
AC-19Access Control for Mobile Devices
AC-20Use of External Systems
AC-22Publicly Accessible Content
AC-7Unsuccessful Logon Attempts
AC-8System Use Notification
AT-1Policy and Procedures
AT-2Literacy Training and Awareness
AU-1Policy and Procedures
AU-11Audit Record Retention
AU-12Audit Record Generation
AU-3Content of Audit Records
AU-4Audit Log Storage Capacity
AU-5Response to Audit Logging Process Failures
AU-6Audit Record Review, Analysis, and Reporting
AU-9Protection of Audit Information
CA-1Policy and Procedures
CA-5Plan of Action and Milestones
CA-7Continuous Monitoring
CM-1Policy and Procedures
CM-10Software Usage Restrictions
CM-11User-Installed Software
CM-2Baseline Configuration
CM-5Access Restrictions for Change
CM-6Configuration Settings
CM-8System Component Inventory
CP-1Policy and Procedures
CP-10System Recovery and Reconstitution
CP-4Contingency Plan Testing
IA-1Policy and Procedures
IA-2Identification and Authentication (Organizational Users)
IA-4Identifier Management
IA-5Authenticator Management
IA-6Authentication Feedback
IA-7Cryptographic Module Authentication
IA-8Identification and Authentication (Non-Organizational Users)
IR-1Event Detection and Triage
IR-7Incident Response Assistance
IR-8Incident Response Plan
MA-1Policy and Procedures
MA-2Controlled Maintenance
MA-5Maintenance Personnel
MP-1Policy and Procedures
PE-1Policy and Procedures
PE-14Environmental Controls
PE-15Water Damage Protection
PE-16Delivery and Removal
PE-2Physical Access Authorizations
PE-3Physical Access Control
PE-6Monitoring Physical Access
PE-8Visitor Access Records
PL-1Policy and Procedures
PL-2System Security and Privacy Plans
PM-1Information Security Program Plan
PM-10Authorization Process
PM-11Mission and Business Process Definition
PM-12Insider Threat Program
PM-13Security and Privacy Workforce
PM-14Testing, Training, and Monitoring
PM-15Security and Privacy Groups and Associations
PM-16Threat Awareness Program
PM-17Protecting CUI on External Systems
PM-18Privacy Program Plan
PM-19Privacy Program Leadership Role
PM-2Information Security Program Leadership Role
PM-20Dissemination of Privacy Program Information
PM-21Accounting of Disclosures
PM-22Personally Identifiable Information Quality Management
PM-23Data Governance Body
PM-24Data Integrity Board
PM-25Minimization of PII Used in Testing, Training, and Research
PM-26Complaint Management
PM-29Risk Management Program Leadership Roles
PM-3Information Security and Privacy Resources
PM-30Supply Chain Risk Management Strategy
PM-31Continuous Monitoring Strategy
PM-4Plan of Action and Milestones Process
PM-6Measures of Performance
PM-7Enterprise Architecture
PM-8Critical Infrastructure Plan
PM-9Risk Management Strategy
PS-1Policy and Procedures
PS-2Position Risk Designation
PS-4Personnel Termination
PS-7External Personnel Security
PS-9Position Descriptions
PT-1Policy and Procedures
PT-2Authority to Process PII
PT-3PII Processing Purposes
PT-6System of Records Notice
PT-7Specific Categories of PII
PT-8Computer Matching Requirements
RA-2Security Categorization
RA-5Vulnerability Monitoring and Scanning
RA-7Identifies and Analyzes Risk
SA-1Logging and Monitoring
SA-2Common Operating Picture
SA-22Unsupported System Components
SA-3System Development Life Cycle
SA-8Security and Privacy Engineering Principles
SA-9External System Services
SC-1Policy and Procedures
SC-12Cryptographic Key Establishment and Management
SC-13Cryptographic Protection
SC-15Collaborative Computing Devices and Applications
SC-20Secure Name/Address Resolution Service (Authoritative)
SC-21Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22Architecture and Provisioning for Name/Address Resolution Service
SC-5Denial-of-Service Protection
SI-1Policy and Procedures
SI-12Information Management and Retention
SI-3Malicious Code Protection
SI-5Security Alerts, Advisories, and Directives
SR-1Policy and Procedures (SR-1)
SR-10Inspection of Systems or Components (SR-10)
SR-11Component Authenticity (SR-11)
SR-12Component Disposal (SR-12)
SR-2Supply Chain Risk Management Plan (SR-2)
SR-3Supply Chain Controls and Processes (SR-3)
SR-5Acquisition Strategies, Tools, and Methods (SR-5)
SR-8Notification Agreements (SR-8)
Show the 7 you already have
IR-2Incident Response and Recovery
RA-1Policy and Procedures
CA-9Internal System Connections
How this is calculated
Already covered means a mapping runs from a control in GDPR to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition