59% of Australian Energy Sector Cyber Security Framework (AESCSF) you already have
NIST Cybersecurity Framework 2.0 already covers about 59% of Australian Energy Sector Cyber Security Framework (AESCSF), leaving
13 of 32 controls as genuinely new work.
Already covered 19
Likely covered 0
New work 13
What is genuinely new work
Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.
AESCSF-ACM-3Change management
AESCSF-APM-1Australian privacy management
AESCSF-APM-2Privacy breach management
AESCSF-CPM-3Cyber security architecture
AESCSF-EDM-2External dependency assessment
AESCSF-EDM-3Dependency resilience
AESCSF-IR-2Incident detection and handling
AESCSF-ISC-2Stakeholder communications
AESCSF-RM-3Manage and treat cyber risks
AESCSF-SA-3Common operating picture
AESCSF-TVM-3Patch and remediation management
AESCSF-WM-1Cyber security workforce management
AESCSF-WM-3Personnel security
Show the 19 you already have
AESCSF-ACM-1Asset inventory
AESCSF-ACM-2Configuration management
AESCSF-CPM-1Cyber security program management
AESCSF-CPM-2Cyber security governance and strategy
AESCSF-EDM-1Supply chain risk management
AESCSF-IAM-1Identity management
AESCSF-IAM-2Access control
AESCSF-IAM-3Multi-factor authentication
AESCSF-IR-1Incident response plan
AESCSF-IR-3Continuity of operations and recovery
AESCSF-IR-4Incident reporting
AESCSF-ISC-1Cyber security information sharing
AESCSF-RM-1Establish cyber security risk management strategy
AESCSF-RM-2Identify and assess cyber risks
AESCSF-SA-1Logging and monitoring
AESCSF-SA-2Anomaly and event detection
AESCSF-TVM-1Vulnerability management
AESCSF-TVM-2Threat management
AESCSF-WM-2Training and awareness
How this is calculated
Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition