Framework overlap

Does India CERT-In Cyber Security Directions 2022 cover NIST AI Risk Management Framework (AI RMF 1.0)?

You hold India CERT-In Cyber Security Directions 2022 and have been told to do NIST AI Risk Management Framework (AI RMF 1.0). Here is how much overlaps, control by control.

29% of NIST AI Risk Management Framework (AI RMF 1.0) you already have

India CERT-In Cyber Security Directions 2022 already covers about 29% of NIST AI Risk Management Framework (AI RMF 1.0), leaving 37 of 52 controls as genuinely new work.

Already covered 3 Likely covered 12 New work 37

What is genuinely new work

Nothing in India CERT-In Cyber Security Directions 2022 reaches these. This is the list to scope.

AIRMF-GOV-03
AI Compliance and Legal
AIRMF-GOV-04
Third-Party AI Risk
AIRMF-GV-1.1
Legal and regulatory requirements involving AI are understood, managed, and documented
AIRMF-GV-1.2
Trustworthy AI characteristics are integrated into organisational policies, processes, and procedures
AIRMF-GV-2.1
Roles and responsibilities related to AI risk management are documented and clear
AIRMF-GV-3.1
Decision making related to mapping, measuring, and managing AI risks is informed by diverse perspectives
AIRMF-GV-4.1
Organisational culture and incentives prioritise AI risk management
AIRMF-MAN-02
AI Monitoring and Maintenance
AIRMF-MAP-01
AI System Context
AIRMF-MEA-02
Bias and Fairness Assessment
AIRMF-MN-1.1
AI risks are prioritised and resources are allocated to manage them
AIRMF-MN-2.1
Mechanisms for tracking identified risks over time are in place
AIRMF-MN-3.1
AI risks and benefits from third party resources are managed
AIRMF-MN-4.1
AI risk management documentation and processes are improved continuously
AIRMF-MN-4.3
Incidents and errors are communicated to relevant AI actors
AIRMF-MP-1.1
Context of AI system use is established and understood
AIRMF-MP-2.1
Categorisation of AI systems is performed
AIRMF-MP-3.1
AI capabilities, targeted usage, goals, and expected benefits and costs are understood
AIRMF-MP-4.1
Approaches and metrics for risk identification are established
AIRMF-MP-5.1
Risks and benefits are characterised for components, including third party components
AIRMF-MS-1.1
Appropriate methods and metrics for measuring AI risk are identified and applied
AIRMF-MS-2.1
Test sets, evaluation criteria, and ongoing tracking are documented
AIRMF-MS-2.11
Fairness and bias are evaluated and results documented
AIRMF-MS-2.7
AI system security and resilience are evaluated
AIRMF-MS-2.8
AI system explainability and interpretability are evaluated
AIRMF-MS-3.1
Approaches and metrics for risk measurement are validated by stakeholders
NIST-AI600-GOV-2
Safety-First Culture
NIST-AI600-GOV-3
Content Provenance Governance
NIST-AI600-GOV-4
Pre-Deployment Testing Governance
NIST-AI600-GOV-5
Incident Disclosure Governance
NIST-AI600-MAP-3
Third-Party Risk Mapping
NIST-AI600-MEA-1
Confabulation Testing
NIST-AI600-MEA-2
Bias and Fairness Evaluation
NIST-AI600-MEA-4
Environmental Impact Measurement
NIST-AI600-MEA-5
Red-Teaming and Adversarial Testing
NIST-AI600-MGT-1
Content Provenance Implementation
NIST-AI600-MGT-2
Human Oversight Integration
Show the 15 you already have
AIRMF-MAN-03
AI Incident Response
AIRMF-MAP-02
AI Risk Identification
AIRMF-MAP-03
AI Impact Assessment
AIRMF-GOV-01
AI Risk Management Policies
AIRMF-GOV-02
AI Risk Culture
AIRMF-MAN-01
AI Risk Treatment
AIRMF-MEA-01
AI Performance Metrics
AIRMF-MEA-03
AI Transparency and Explainability
NIST-AI600-GOV-1
Legal and Regulatory Compliance
NIST-AI600-MAP-1
GAI Risk Identification
NIST-AI600-MAP-2
Stakeholder Impact Assessment
NIST-AI600-MEA-3
Privacy Leak Assessment
NIST-AI600-MGT-3
Third-Party Dependency Management
NIST-AI600-MGT-4
Incident Response for GAI
NIST-AI600-MGT-5
Decommissioning Procedures

How this is calculated

Already covered means a mapping runs from a control in India CERT-In Cyber Security Directions 2022 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition