22% of NIST Cybersecurity Framework 2.0 you already have
ISO 22316 already covers about 22% of NIST Cybersecurity Framework 2.0, leaving
83 of 106 controls as genuinely new work.
Already covered 6
Likely covered 17
New work 83
What is genuinely new work
Nothing in ISO 22316 reaches these. This is the list to scope.
GV.OV-01Risk management strategy outcomes are reviewed
GV.OV-02Risk management strategy is reviewed for coverage
GV.OV-03Risk management performance is evaluated
NIST-CSF-DE.AE-02Potentially adverse events are analyzed to better understand associated activities
NIST-CSF-DE.AE-03Information is correlated from multiple sources
NIST-CSF-DE.AE-04Estimated impact and scope of adverse events are understood
NIST-CSF-DE.AE-06Information on adverse events is provided to authorized staff
NIST-CSF-DE.AE-07Cyber threat intelligence and contextual information are integrated into analysis
NIST-CSF-DE.CM-01Networks and network services are monitored to find potentially adverse events
NIST-CSF-DE.CM-02The physical environment is monitored to find potentially adverse events
NIST-CSF-DE.CM-03Personnel activity and technology usage are monitored to find potentially adverse events
NIST-CSF-DE.CM-06External service provider activities are monitored to find potentially adverse events
NIST-CSF-DE.CM-09Computing hardware and software are monitored to find potentially adverse events
NIST-CSF-GV.OC-01Organizational context for cybersecurity risk management is understood
NIST-CSF-GV.OC-02Internal and external stakeholders are understood
NIST-CSF-GV.OC-03Legal, regulatory, and contractual requirements are understood
NIST-CSF-GV.OC-04Critical objectives, capabilities, and services are understood
NIST-CSF-GV.OC-05Outcomes and dependencies of critical services are understood
NIST-CSF-GV.PO-01Cybersecurity risk management policy is established based on context and strategy
NIST-CSF-GV.PO-02Policy is reviewed, updated, communicated, and enforced
NIST-CSF-GV.RM-01Risk management objectives are established and agreed upon
NIST-CSF-GV.RM-02Risk appetite and risk tolerance statements are established
NIST-CSF-GV.RM-05Communication lines for cybersecurity risk management are established
NIST-CSF-GV.RM-06A standardized method for calculating and expressing cybersecurity risk is established
NIST-CSF-GV.RR-01Organizational leadership is responsible for cybersecurity risk management
NIST-CSF-GV.RR-02Roles and responsibilities for cybersecurity risk management are established
NIST-CSF-GV.RR-03Adequate resources are allocated for cybersecurity risk management
NIST-CSF-GV.RR-04Cybersecurity is included in human resources practices
NIST-CSF-GV.SC-02Cybersecurity roles and responsibilities for suppliers are established
NIST-CSF-GV.SC-03Supply chain risk management is integrated into risk management
NIST-CSF-GV.SC-04Suppliers are known and prioritized by criticality
NIST-CSF-GV.SC-05Requirements are established and managed for suppliers
NIST-CSF-GV.SC-06Planning and due diligence are performed to reduce supply chain risks
NIST-CSF-GV.SC-07Supply chain risk management is verified throughout supplier relationships
NIST-CSF-GV.SC-08Relevant suppliers and partners are included in incident planning
NIST-CSF-GV.SC-09Supply chain security practices are integrated into security program
NIST-CSF-GV.SC-10Cybersecurity supply chain risk management plans include provisions for post-acquisition activities
NIST-CSF-ID.AM-01Inventories of hardware managed by the organization are maintained
NIST-CSF-ID.AM-02Inventories of software, services, and systems managed by the organization are maintained
NIST-CSF-ID.AM-03Representations of authorized network communication and data flows are maintained
NIST-CSF-ID.AM-05Assets are prioritized based on classification, criticality, resources, and impact
NIST-CSF-ID.AM-07Inventories of data and corresponding metadata are maintained
NIST-CSF-ID.AM-08Systems, hardware, software, and services are managed throughout their life cycles
NIST-CSF-ID.IM-01Improvements are identified from security test and exercise results
NIST-CSF-ID.IM-02Improvements are identified from security assessments
NIST-CSF-ID.IM-03Improvements are identified from operational activities and incidents
NIST-CSF-ID.RA-01Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-ID.RA-02Cyber threat intelligence is received from information sharing forums
NIST-CSF-ID.RA-03Internal and external threats are identified and recorded
NIST-CSF-ID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified
NIST-CSF-ID.RA-05Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk
NIST-CSF-ID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicated
NIST-CSF-ID.RA-07Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
NIST-CSF-ID.RA-08Effectiveness of risk responses is assessed
NIST-CSF-PR.AA-03Users, services, and hardware are authenticated
NIST-CSF-PR.AA-04Identity assertions are protected, conveyed, and verified
NIST-CSF-PR.AT-01Personnel are provided awareness and training to perform cybersecurity duties
NIST-CSF-PR.AT-02Individuals in specialized roles are provided awareness and training
NIST-CSF-PR.DS-01The confidentiality, integrity, and availability of data-at-rest are protected
NIST-CSF-PR.DS-02The confidentiality, integrity, and availability of data-in-transit are protected
NIST-CSF-PR.DS-11Backups of data are created, protected, maintained, and tested
NIST-CSF-PR.IR-01Networks and environments are protected from unauthorized access
NIST-CSF-PR.IR-02The organization's technology assets are protected from environmental threats
NIST-CSF-PR.PS-02Software is maintained, replaced, and removed commensurate with risk
NIST-CSF-PR.PS-03Hardware is maintained, replaced, and removed commensurate with risk
NIST-CSF-PR.PS-05Installation and execution of unauthorized software is prevented
NIST-CSF-RC.CO-03Recovery activities and progress are communicated to stakeholders
NIST-CSF-RC.CO-04Public updates on incident recovery are shared using approved methods
NIST-CSF-RC.RP-02Recovery actions are selected, scoped, and prioritized
NIST-CSF-RC.RP-03The integrity of backups is verified before use in restoration
NIST-CSF-RC.RP-04Critical functions and services are restored to operational capability
NIST-CSF-RC.RP-05Integrity of restored assets is verified
NIST-CSF-RS.AN-03Analysis is performed to determine what has taken place during an incident
NIST-CSF-RS.AN-06Actions performed during an investigation are recorded
NIST-CSF-RS.AN-07Incident data and metadata are collected and their integrity preserved
NIST-CSF-RS.AN-08Incidents are analyzed to determine root cause
NIST-CSF-RS.CO-02Internal and external stakeholders are notified of incidents
NIST-CSF-RS.CO-03Information is shared with designated internal and external stakeholders
NIST-CSF-RS.MA-02Incident reports are triaged and validated
NIST-CSF-RS.MA-03Incidents are categorized and prioritized
NIST-CSF-RS.MA-04Incidents are escalated or elevated as needed
NIST-CSF-RS.MI-01Incidents are contained
NIST-CSF-RS.MI-02Incidents are eradicated
Show the 23 you already have
NIST-CSF-GV.SC-01Cybersecurity supply chain risk management program is established
NIST-CSF-ID.AM-04Inventories of services provided by suppliers are maintained
NIST-CSF-ID.RA-10Critical suppliers are assessed on the basis of their risk
NIST-CSF-RC.RP-01The recovery portion of the incident response plan is executed
NIST-CSF-RC.RP-06End-of-recovery is declared based on criteria and documentation
NIST-CSF-RS.MA-05Criteria for initiating incident recovery are applied
NIST-CSF-DE.AE-08Incidents are declared when adverse events meet defined criteria
NIST-CSF-GV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk
NIST-CSF-GV.RM-04Strategic direction for cybersecurity risk management is established
NIST-CSF-GV.RM-07Opportunities for improvements are identified from risk assessments
NIST-CSF-ID.IM-04Incident response plans and other cybersecurity plans are established and maintained
NIST-CSF-ID.RA-09Integrity and accuracy of risk assessment results are verified
NIST-CSF-PR.AA-01Identities and credentials for authorized users, services, and hardware are managed
NIST-CSF-PR.AA-02Identities are proofed and bound to credentials based on the context of interactions
NIST-CSF-PR.AA-05Access permissions, entitlements, and authorizations are defined and managed
NIST-CSF-PR.AA-06Physical access to assets is managed, monitored, and enforced
NIST-CSF-PR.DS-10The confidentiality, integrity, and availability of data-in-use are protected
NIST-CSF-PR.IR-03Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
NIST-CSF-PR.IR-04Adequate resource capacity to ensure availability is maintained
NIST-CSF-PR.PS-01Configuration management practices are established and applied
NIST-CSF-PR.PS-04Log records are generated and made available for continuous monitoring
NIST-CSF-PR.PS-06Secure software development practices are integrated throughout the SDLC
NIST-CSF-RS.MA-01The incident response plan is executed in coordination with relevant third parties
How this is calculated
Already covered means a mapping runs from a control in ISO 22316 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition