Framework overlap

Does Kids Online Safety Act (KOSA) cover CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0?

You hold Kids Online Safety Act (KOSA) and have been told to do CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0. Here is how much overlaps, control by control.

37% of CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 you already have

Kids Online Safety Act (KOSA) already covers about 37% of CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, leaving 22 of 35 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 22

No control in Kids Online Safety Act (KOSA) maps directly to one in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Kids Online Safety Act (KOSA) reaches these. This is the list to scope.

CPG-1.B
Minimum Password Strength
CPG-1.D
Revoking Credentials for Departing Employees
CPG-1.E
Separating User and Privileged Accounts
CPG-1.F
Phishing-Resistant MFA
CPG-2.A
Asset Inventory
CPG-2.B
Prohibit Connection of Unauthorized Devices
CPG-2.C
Hardware and Software Approval Process
CPG-2.D
Disable Macros by Default
CPG-2.E
Document Device Configurations
CPG-2.F
No Exploitable Services on the Internet
CPG-2.G
Limit OT Connections to Public Internet
CPG-2.H
Document Network Topology
CPG-3.D
Secure Sensitive Data
CPG-4.A
Organizational Cybersecurity Leadership
CPG-4.B
OT Cybersecurity Leadership
CPG-4.D
OT-Specific Cybersecurity Training
CPG-5.A
Vulnerability Disclosure Program
CPG-5.B
Mitigating Known Vulnerabilities
CPG-5.C
No Exploitable Services on the Internet
CPG-5.D
Vulnerability Disclosure Program
CPG-7.B
Incident Response Plans
CPG-8.B
Email Security (DMARC)
Show the 13 you already have
CPG-1.A
Changing Default Passwords
CPG-1.C
Unique Credentials
CPG-3.A
Log Collection
CPG-3.B
Secure Log Storage
CPG-3.C
Strong and Agile Encryption
CPG-4.C
Basic Cybersecurity Training
CPG-6.A
Vendor and Supplier Incident Reporting
CPG-6.B
Supply Chain Incident Reporting
CPG-7.A
Incident Reporting
CPG-7.C
System Backups
CPG-7.D
Incident Response Testing
CPG-8.A
Network Segmentation
CPG-8.C
Encrypted DNS

How this is calculated

Already covered means a mapping runs from a control in Kids Online Safety Act (KOSA) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition