20% of SANS Incident Handler's Handbook and PICERL Methodology you already have
NIST AI Risk Management Framework (AI RMF 1.0) already covers about 20% of SANS Incident Handler's Handbook and PICERL Methodology, leaving
32 of 40 controls as genuinely new work.
Already covered 5
Likely covered 3
New work 32
What is genuinely new work
Nothing in NIST AI Risk Management Framework (AI RMF 1.0) reaches these. This is the list to scope.
PICERL-C-01Containment: Short Term Containment Strategy
PICERL-C-02Containment: System Backup Before Remediation
PICERL-C-03Containment: Long Term Containment
PICERL-C1Short-Term Containment
PICERL-E-01Eradication: Root Cause Analysis
PICERL-E-02Eradication: Removal of Threat Actor Artefacts
PICERL-E-03Eradication: Credential Reset and Identity Hygiene
PICERL-E2Root Cause Analysis
PICERL-E3Backdoor Elimination
PICERL-I-01Identification: Detection Sources and Alert Triage
PICERL-I-02Identification: Incident Declaration and Notification
PICERL-I-03Identification: Evidence Collection and Chain of Custody
PICERL-I-04Identification: Scope Determination
PICERL-I1Monitoring and Detection
PICERL-I2Evidence Collection
PICERL-I3Incident Classification
PICERL-L-01Lessons Learned: Post Incident Review
PICERL-L-02Lessons Learned: Control Improvements and Detection Engineering
PICERL-L-03Lessons Learned: Metrics and Reporting to Executives
PICERL-L1Post-Incident Review
PICERL-L2Documentation and Reporting
PICERL-P-01Preparation: Incident Response Policy and Charter
PICERL-P-02Preparation: Incident Response Team Roles and Skills
PICERL-P-03Preparation: Jump Kit and Tooling Readiness
PICERL-P-04Preparation: Logging, Detection, and Telemetry Baseline
PICERL-P-05Preparation: Tabletop Exercises and Drills
PICERL-P1Security Policy Review
PICERL-P4Tools and Documentation
PICERL-R-01Recovery: Restoration Planning and Sequencing
PICERL-R-02Recovery: Validation and Monitoring
PICERL-R-03Recovery: Communications and Stakeholder Updates
PICERL-R3Enhanced Monitoring
Show the 8 you already have
PICERL-C3Long-Term Containment
PICERL-L3Plan Improvement
PICERL-R1System Restoration
PICERL-R2Security Verification
How this is calculated
Already covered means a mapping runs from a control in NIST AI Risk Management Framework (AI RMF 1.0) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition