40% of CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 you already have
IRM Enterprise Risk Management Framework (Institute of Risk Management) already covers about 40% of CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, leaving
21 of 35 controls as genuinely new work.
Already covered 2
Likely covered 12
New work 21
What is genuinely new work
Nothing in IRM Enterprise Risk Management Framework (Institute of Risk Management) reaches these. This is the list to scope.
CPG-1.BMinimum Password Strength
CPG-1.ESeparating User and Privileged Accounts
CPG-1.FPhishing-Resistant MFA
CPG-2.BProhibit Connection of Unauthorized Devices
CPG-2.CHardware and Software Approval Process
CPG-2.DDisable Macros by Default
CPG-2.EDocument Device Configurations
CPG-2.FNo Exploitable Services on the Internet
CPG-2.GLimit OT Connections to Public Internet
CPG-2.HDocument Network Topology
CPG-3.DSecure Sensitive Data
CPG-4.AOrganizational Cybersecurity Leadership
CPG-4.BOT Cybersecurity Leadership
CPG-4.DOT-Specific Cybersecurity Training
CPG-5.AVulnerability Disclosure Program
CPG-5.BMitigating Known Vulnerabilities
CPG-5.CNo Exploitable Services on the Internet
CPG-5.DVulnerability Disclosure Program
CPG-7.BIncident Response Plans
CPG-8.BEmail Security (DMARC)
Show the 14 you already have
CPG-6.AVendor and Supplier Incident Reporting
CPG-6.BSupply Chain Incident Reporting
CPG-1.AChanging Default Passwords
CPG-1.CUnique Credentials
CPG-1.DRevoking Credentials for Departing Employees
CPG-3.BSecure Log Storage
CPG-3.CStrong and Agile Encryption
CPG-4.CBasic Cybersecurity Training
CPG-7.AIncident Reporting
CPG-7.DIncident Response Testing
CPG-8.ANetwork Segmentation
How this is calculated
Already covered means a mapping runs from a control in IRM Enterprise Risk Management Framework (Institute of Risk Management) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition