Framework overlap

Does ISO 22320:2018 cover NIST SP 800-171A Rev 3?

You hold ISO 22320:2018 and have been told to do NIST SP 800-171A Rev 3. Here is how much overlaps, control by control.

69% of NIST SP 800-171A Rev 3 you already have

ISO 22320:2018 already covers about 69% of NIST SP 800-171A Rev 3, leaving 11 of 35 controls as genuinely new work.

Already covered 7 Likely covered 17 New work 11

What is genuinely new work

Nothing in ISO 22320:2018 reaches these. This is the list to scope.

3.1.1
Authorized Access Control
3.1.2
Transaction and Function Control
3.13
Deploy a Data Loss Prevention Solution
3.13.1
Boundary Protection Assessment
3.14
Log Sensitive Data Access
3.15
Planning
3.8
Document Data Flows
3.9.1
Personnel Screening Assessment
FEDRAMP-SC-1
System and Communications Protection Policy
FEDRAMP-SC-12
Cryptographic Key Establishment and Management
FEDRAMP-SC-7
Boundary Protection
Show the 24 you already have
3.16
System and Services Acquisition
3.17
Supply Chain Risk Management
3.3
Configure Data Access Control Lists
3.6
Encrypt Data on End-User Devices
3.6.1
Incident Response Capability
FEDRAMP-CM-6
Configuration Settings
FEDRAMP-CP-9
System Backup
3.1
Physical Security
3.10
Encrypt Sensitive Data in Transit
3.11
Encrypt Sensitive Data at Rest
3.12
Segment Data Processing and Storage Based on Sensitivity
3.2
Establish and Maintain a Data Inventory
3.2.1
Account data storage minimised
3.3.1
Audit Record Creation
3.4
Enforce Data Retention
3.5
Securely Dispose of Data
3.7
Establish and Maintain a Data Classification Scheme
3.7.1
Key generation procedures
3.9
Encrypt Data on Removable Media
FEDRAMP-CM-1
Configuration Management Policy
FEDRAMP-CM-2
Baseline Configuration
FEDRAMP-SC-13
Cryptographic Protection
FEDRAMP-SC-28
Protection of Information at Rest
FEDRAMP-SC-8
Transmission Confidentiality and Integrity

How this is calculated

Already covered means a mapping runs from a control in ISO 22320:2018 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition