Framework overlap

Does NIST Cybersecurity Framework 2.0 cover COBIT 2019?

You hold NIST Cybersecurity Framework 2.0 and have been told to do COBIT 2019. Here is how much overlaps, control by control.

3% of COBIT 2019 you already have

NIST Cybersecurity Framework 2.0 already covers about 3% of COBIT 2019, leaving 66 of 68 controls as genuinely new work.

Already covered 2 Likely covered 0 New work 66

What is genuinely new work

Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.

APO01
Managed I&T Management Framework
APO02
Managed Strategy
APO07
Managed Human Resources
APO08
Managed Relationships
APO09
Managed Service Agreements
APO10
Managed Vendors
APO12
Managed Risk
APO13
Managed Security
APO14
Managed Data
BAI01
Managed Programs
BAI02
Managed Requirements Definition
BAI03
Managed Solutions Identification and Build
BAI06
Managed IT Changes
BAI07
Managed IT Change Acceptance and Transitioning
BAI08
Managed Knowledge
BAI09
Managed Assets
BAI10
Managed Configuration
COBIT-APO01
Managed IT management framework
COBIT-APO02
Managed strategy
COBIT-APO03
Managed enterprise architecture
COBIT-APO04
Managed innovation
COBIT-APO05
Managed portfolio
COBIT-APO06
Managed budget and costs
COBIT-APO07
Managed human resources
COBIT-APO08
Managed relationships
COBIT-APO09
Managed service agreements
COBIT-APO10
Managed vendors
COBIT-APO11
Managed quality
COBIT-APO12
Managed risk
COBIT-APO13
Managed security
COBIT-APO14
Managed data
COBIT-BAI01
Managed programs
COBIT-BAI03
Managed solutions identification and build
COBIT-BAI05
Managed organizational change
COBIT-BAI06
Managed IT changes
COBIT-BAI07
Managed IT change acceptance and transitioning
COBIT-BAI08
Managed knowledge
COBIT-BAI09
Managed assets
COBIT-BAI10
Managed configuration
COBIT-BAI11
Managed projects
COBIT-DSS01
Managed operations
COBIT-DSS02
Managed service requests and incidents
COBIT-DSS03
Managed problems
COBIT-DSS04
Managed continuity
COBIT-DSS05
Managed security services
COBIT-DSS06
Managed business process controls
COBIT-EDM01
Ensured governance framework setting and maintenance
COBIT-EDM02
Ensured benefits delivery
COBIT-EDM03
Ensured risk optimization
COBIT-EDM04
Ensured resource optimization
COBIT-EDM05
Ensured stakeholder engagement
COBIT-MEA01
Managed performance and conformance monitoring
COBIT-MEA02
Managed system of internal control
COBIT-MEA03
Managed compliance with external requirements
COBIT-MEA04
Managed assurance
DSS01
Managed Operations
DSS02
Managed Service Requests and Incidents
DSS05
Managed Security Services
EDM01
Ensured Governance Framework Setting and Maintenance
EDM02
Ensured Benefits Delivery
EDM03
Ensured Risk Optimization
EDM04
Ensured Resource Optimization
EDM05
Ensured Stakeholder Engagement
MEA01
Managed Performance and Conformance Monitoring
MEA02
Managed System of Internal Control
MEA03
Managed Compliance with External Requirements
Show the 2 you already have
COBIT-BAI02
Managed requirements definition
COBIT-BAI04
Managed availability and capacity

How this is calculated

Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition