Framework overlap

Does NIST Cybersecurity Framework 2.0 cover FedRAMP High?

You hold NIST Cybersecurity Framework 2.0 and have been told to do FedRAMP High. Here is how much overlaps, control by control.

2% of FedRAMP High you already have

NIST Cybersecurity Framework 2.0 already covers about 2% of FedRAMP High, leaving 408 of 417 controls as genuinely new work.

Already covered 4 Likely covered 5 New work 408

What is genuinely new work

Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.

AC-1
Policy and Procedures
AC-10
Concurrent Session Control
AC-11
Device Lock
AC-12
Session Termination
AC-14
Permitted Actions Without Identification or Authentication
AC-17
Remote Access
AC-17(1)
Monitoring and Control
AC-17(2)
Protection of Confidentiality and Integrity Using Encryption
AC-17(3)
Managed Access Control Points
AC-17(4)
Privileged Commands and Access
AC-17(9)
Disconnect or Disable Access
AC-18
Wireless Access
AC-18(1)
Authentication and Encryption
AC-18(3)
Disable Wireless Networking
AC-18(4)
Restrict Configurations by Users
AC-18(5)
Antennas and Transmission Power Levels
AC-19
Access Control for Mobile Devices
AC-19(5)
Full Device or Container-Based Encryption
AC-2(1)
Automated System Account Management
AC-2(11)
Usage Conditions
AC-2(12)
Account Monitoring for Atypical Usage
AC-2(13)
Disable Accounts for High-Risk Individuals
AC-2(2)
Automated Temporary and Emergency Account Management
AC-2(3)
Disable Accounts
AC-2(4)
Automated Audit Actions
AC-2(5)
Inactivity Logout
AC-2(7)
Privileged User Accounts
AC-2(9)
Restrictions on Use of Shared and Group Accounts
AC-20
Use of External Systems
AC-20(1)
Limits on Authorized Use
AC-20(2)
Portable Storage Devices Restricted Use
AC-21
Information Sharing
AC-22
Publicly Accessible Content
AC-4
Information Flow Enforcement
AC-4(21)
Physical or Logical Separation of Information Flows
AC-4(4)
Flow Control of Encrypted Information
AC-4(8)
Security and Privacy Policy Filters
AC-5
Separation of Duties
AC-6
Least Privilege
AC-6(1)
Authorize Access to Security Functions
AC-6(10)
Prohibit Non-Privileged Users from Executing Privileged Functions
AC-6(2)
Non-Privileged Access for Nonsecurity Functions
AC-6(3)
Network Access to Privileged Commands
AC-6(5)
Privileged Accounts
AC-6(7)
Review of User Privileges
AC-6(8)
Privilege Levels for Code Execution
AC-6(9)
Log Use of Privileged Functions
AC-7
Unsuccessful Logon Attempts
AC-8
System Use Notification
AT-1
Policy and Procedures
AT-2
Literacy Training and Awareness
AT-2(2)
Insider Threat
AT-2(3)
Social Engineering and Mining
AT-3
Role-Based Training
AT-4
Training Records
AU-1
Policy and Procedures
AU-10
Non-Repudiation
AU-11
Audit Record Retention
AU-12
Audit Record Generation
AU-12(1)
System-wide and Time-correlated Audit Trail
AU-12(3)
Changes by Authorized Individuals
AU-2
Event Logging
AU-3
Content of Audit Records
AU-3(1)
Additional Audit Information
AU-4
Audit Log Storage Capacity
AU-5
Response to Audit Logging Process Failures
AU-5(1)
Storage Capacity Warning
AU-5(2)
Real-Time Alerts
AU-6
Audit Record Review, Analysis, and Reporting
AU-6(1)
Automated Process Integration
AU-6(3)
Correlate Audit Record Repositories
AU-6(4)
Central Review and Analysis
AU-6(5)
Integrated Analysis of Audit Records
AU-6(6)
Correlation with Physical Monitoring
AU-6(7)
Permitted Actions
AU-7
Audit Record Reduction and Report Generation
AU-7(1)
Automatic Processing
AU-8
Time Stamps
AU-9
Protection of Audit Information
AU-9(2)
Store on Separate Physical Systems or Components
AU-9(3)
Cryptographic Protection
AU-9(4)
Access by Subset of Privileged Users
CA-1
Policy and Procedures
CA-2
Control Assessments
CA-2(1)
Independent Assessors
CA-2(2)
Specialized Assessments
CA-2(3)
Leveraging Results from External Organizations
CA-3
Information Exchange
CA-5
Plan of Action and Milestones
CA-6
Authorization
CA-7
Continuous Monitoring
CA-7(1)
Independent Assessment
CA-7(3)
Trend Analyses
CA-8(1)
Independent Penetration Agent or Team
CA-8(2)
Red Team Exercises
CM-1
Policy and Procedures
CM-10
Software Usage Restrictions
CM-11
User-Installed Software
CM-12
Information Location
CM-12(1)
Automated Tools to Support Information Location
CM-2
Baseline Configuration
CM-2(2)
Automation Support for Accuracy and Currency
CM-2(3)
Retention of Previous Configurations
CM-2(7)
Configure Systems and Components for High-Risk Areas
CM-3
Configuration Change Control
CM-3(1)
Automated Documentation, Notification, and Prohibition
CM-3(2)
Testing, Validation, and Documentation of Changes
CM-3(4)
Security and Privacy Representatives
CM-3(6)
Cryptography Management
CM-4
Impact Analyses
CM-4(1)
Separate Test Environments
CM-5
Access Restrictions for Change
CM-5(1)
Automated Access Enforcement and Audit Records
CM-5(2)
Review System Changes
CM-5(3)
Signed Components
CM-6
Configuration Settings
CM-6(1)
Automated Management, Application, and Verification
CM-6(2)
Respond to Unauthorized Changes
CM-7
Least Functionality
CM-7(1)
Periodic Review
CM-7(2)
Prevent Program Execution
CM-7(3)
Registration Compliance
CM-7(5)
Authorized Software Allow-by-Exception
CM-8
System Component Inventory
CM-8(1)
Updates During Installation and Removal
CM-8(2)
Automated Maintenance
CM-8(3)
Automated Unauthorized Component Detection
CM-8(4)
Accountability Information
CM-9
Configuration Management Plan
CP-1
Policy and Procedures
CP-10
System Recovery and Reconstitution
CP-10(2)
Transaction Recovery
CP-10(4)
Restore Within Time Period
CP-2
Contingency Plan
CP-2(1)
Coordinate with Related Plans
CP-2(2)
Capacity Planning
CP-2(3)
Resume Mission and Business Functions
CP-2(5)
Continue Mission and Business Functions
CP-2(8)
Identify Critical Assets
CP-3
Contingency Training
CP-3(1)
Simulated Events
CP-4
Contingency Plan Testing
CP-4(1)
Coordinate with Related Plans
CP-4(2)
Alternate Processing Site
CP-6
Alternate Storage Site
CP-6(1)
Separation from Primary Site
CP-6(2)
Recovery Time and Recovery Point Objectives
CP-6(3)
Accessibility
CP-7
Alternate Processing Site
CP-7(1)
Separation from Primary Site
CP-7(2)
Accessibility
CP-7(3)
Priority of Service
CP-7(4)
Preparation for Use
CP-8
Telecommunications Services
CP-8(1)
Priority of Service Provisions
CP-8(2)
Single Points of Failure
CP-8(3)
Separation of Primary and Alternate Providers
CP-8(4)
Provider Contingency Plan
CP-9
System Backup
CP-9(1)
Testing for Reliability and Integrity
CP-9(2)
Test Restoration Using Sampling
CP-9(3)
Separate Storage for Critical Information
CP-9(5)
Transfer to Alternate Storage Site
CP-9(8)
Cryptographic Protection
IA-1
Policy and Procedures
IA-11
Re-Authentication
IA-12
Identity Proofing
IA-12(2)
Identity Evidence
IA-12(3)
Identity Evidence Validation and Verification
IA-12(4)
In-Person Validation and Verification
IA-12(5)
Address Confirmation
IA-2
Identification and Authentication (Organizational Users)
IA-2(1)
MFA to Privileged Accounts
IA-2(12)
Acceptance of PIV Credentials
IA-2(2)
MFA to Non-Privileged Accounts
IA-2(5)
Individual Authentication with Group Authentication
IA-2(6)
Access to Accounts via Separate Device
IA-2(8)
Access to Accounts Replay Resistant
IA-3
Device Identification and Authentication
IA-4
Identifier Management
IA-4(4)
Identify User Status
IA-5
Authenticator Management
IA-5(1)
Password-Based Authentication
IA-5(2)
Public Key-Based Authentication
IA-5(6)
Protection of Authenticators
IA-5(7)
No Embedded Unencrypted Static Authenticators
IA-5(8)
Multiple System Accounts
IA-6
Authentication Feedback
IA-7
Cryptographic Module Authentication
IA-8
Identification and Authentication (Non-Organizational Users)
IA-8(1)
Acceptance of PIV Credentials from Other Agencies
IA-8(2)
Acceptance of External Authenticators
IA-8(4)
Use of Defined Profiles
IR-1
Event Detection and Triage
IR-2(1)
Simulated Events
IR-2(2)
Automated Training Environments
IR-3
Continuity of Operations
IR-3(2)
Coordination with Related Plans
IR-4(1)
Automated Incident Handling Processes
IR-4(3)
Continuity of Operations
IR-4(4)
Information Correlation
IR-4(6)
Insider Threats
IR-4(8)
Correlation with External Organizations
IR-5
Incident Monitoring
IR-5(1)
Automated Tracking, Data Collection, and Analysis
IR-6
Incident Reporting
IR-6(1)
Automated Reporting
IR-6(3)
Supply Chain Coordination
IR-7
Incident Response Assistance
IR-7(1)
Automation Support for Availability of Information and Support
IR-8
Incident Response Plan
IR-8(1)
Breaches
IR-9
Information Spillage Response
IR-9(2)
Training
IR-9(3)
Post-Spill Operations
IR-9(4)
Exposure to Unauthorized Personnel
MA-1
Policy and Procedures
MA-2
Controlled Maintenance
MA-2(2)
Automated Maintenance Activities
MA-3
Maintenance Tools
MA-3(1)
Inspect Tools
MA-3(2)
Inspect Media
MA-3(3)
Prevent Unauthorized Removal
MA-4
Nonlocal Maintenance
MA-4(3)
Comparable Security and Sanitization
MA-5
Maintenance Personnel
MA-5(1)
Individuals Without Appropriate Access
MA-6
Timely Maintenance
MP-1
Policy and Procedures
MP-2
Media Access
MP-3
Media Marking
MP-4
Media Storage
MP-5
Media Transport
MP-6
Media Sanitization
MP-6(1)
Review, Approve, Track, Document, Verify
MP-6(2)
Equipment Testing
MP-6(3)
Nondestructive Techniques
MP-7
Media Use
PE-1
Policy and Procedures
PE-10
Emergency Shutoff
PE-11
Emergency Power
PE-11(1)
Alternate Power Supply Minimal Operational Capability
PE-12
Emergency Lighting
PE-13
Fire Protection
PE-13(1)
Detection Systems Automatic Activation and Notification
PE-13(2)
Suppression Systems Automatic Activation and Notification
PE-14
Environmental Controls
PE-15
Water Damage Protection
PE-15(1)
Automation Support
PE-16
Delivery and Removal
PE-17
Alternate Work Site
PE-18
Location of System Components
PE-2
Physical Access Authorizations
PE-3
Physical Access Control
PE-3(1)
System Access
PE-4
Access Control for Transmission
PE-5
Access Control for Output Devices
PE-6
Monitoring Physical Access
PE-6(1)
Intrusion Alarms and Surveillance Equipment
PE-6(4)
Monitoring Physical Access to Systems
PE-8
Visitor Access Records
PE-8(1)
Automated Records Maintenance and Review
PE-9
Power Equipment and Cabling
PL-1
Policy and Procedures
PL-10
Baseline Selection
PL-11
Baseline Tailoring
PL-2
System Security and Privacy Plans
PL-4
Rules of Behavior
PL-4(1)
Social Media and External Site/Application Usage Restrictions
PL-8
Security and Privacy Architectures
PS-1
Policy and Procedures
PS-2
Position Risk Designation
PS-3
Personnel Screening
PS-3(3)
Information Requiring Special Protective Measures
PS-4
Personnel Termination
PS-4(2)
Automated Actions
PS-5
Personnel Transfer
PS-6
Access Agreements
PS-7
External Personnel Security
PS-8
Personnel Sanctions
PS-9
Position Descriptions
RA-3(1)
Supply Chain Risk Assessment
RA-5
Vulnerability Monitoring and Scanning
RA-5(11)
Public Disclosure Program
RA-5(2)
Update Vulnerabilities to be Scanned
RA-5(4)
Discoverable Information
RA-5(5)
Privileged Access
RA-7
Identifies and Analyzes Risk
RA-9
Identifies and Analyzes Significant Change
SA-1
Logging and Monitoring
SA-10
Developer Configuration Management
SA-10(1)
Software and Firmware Integrity Verification
SA-11
Developer Testing and Evaluation
SA-11(1)
Static Code Analysis
SA-11(2)
Threat Modeling and Vulnerability Analyses
SA-11(8)
Dynamic Code Analysis
SA-15
Development Process, Standards, and Tools
SA-16
Developer-Provided Training
SA-17
Developer Security and Privacy Architecture and Design
SA-2
Common Operating Picture
SA-21
Developer Screening
SA-22
Unsupported System Components
SA-3
System Development Life Cycle
SA-4
Acquisition Process
SA-4(1)
Functional Properties of Controls
SA-4(10)
Use of Approved PIV Products
SA-4(2)
Design and Implementation Information for Controls
SA-4(5)
System, Component, and Service Configurations
SA-4(8)
Continuous Monitoring Plan for Controls
SA-4(9)
Functions, Ports, Protocols, and Services in Use
SA-5
System Documentation
SA-8
Security and Privacy Engineering Principles
SA-9
External System Services
SA-9(1)
Risk Assessments and Organizational Approvals
SA-9(2)
Identification of Functions, Ports, Protocols, and Services
SA-9(4)
Consistent Interests of Consumers and Providers
SA-9(5)
Processing, Storage, and Service Location
SC-1
Policy and Procedures
SC-10
Network Disconnect
SC-12
Cryptographic Key Establishment and Management
SC-12(1)
Availability
SC-12(2)
Symmetric Keys
SC-12(3)
Asymmetric Keys
SC-13
Cryptographic Protection
SC-15
Collaborative Computing Devices and Applications
SC-17
Public Key Infrastructure Certificates
SC-18
Mobile Code
SC-2
Separation of System and User Functionality
SC-20
Secure Name/Address Resolution Service (Authoritative)
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22
Architecture and Provisioning for Name/Address Resolution Service
SC-23
Session Authenticity
SC-23(1)
Invalidate Session Identifiers at Logout
SC-24
Fail in Known State
SC-28
Protection of Information at Rest
SC-28(1)
Cryptographic Protection
SC-3
Security Function Isolation
SC-39
Process Isolation
SC-4
Information in Shared System Resources
SC-45
System Time Synchronization
SC-45(1)
Synchronization with Authoritative Time Source
SC-5
Denial-of-Service Protection
SC-5(1)
Restrict Ability to Attack Other Systems
SC-5(2)
Capacity, Bandwidth, and Redundancy
SC-5(3)
Detection and Monitoring
SC-6
Resource Availability
SC-7
Boundary Protection
SC-7(10)
Prevent Exfiltration
SC-7(12)
Host-Based Protection
SC-7(13)
Isolation of Security Tools, Mechanisms, and Support Components
SC-7(18)
Fail Secure
SC-7(20)
Dynamic Isolation and Segregation
SC-7(21)
Isolation of System Components
SC-7(3)
Access Points
SC-7(4)
External Telecommunications Services
SC-7(5)
Deny by Default Allow by Exception
SC-7(7)
Split Tunneling for Remote Devices
SC-7(8)
Route Traffic to Authenticated Proxy Servers
SC-8
Transmission Confidentiality and Integrity
SC-8(1)
Cryptographic Protection
SI-1
Policy and Procedures
SI-10
Information Input Validation
SI-11
Error Handling
SI-12
Information Management and Retention
SI-16
Memory Protection
SI-17
Fail-Safe Procedures
SI-2
Flaw Remediation
SI-2(1)
Central Management
SI-2(2)
Automated Flaw Remediation Status
SI-2(3)
Time to Remediate Flaws and Benchmarks for Corrective Actions
SI-3
Malicious Code Protection
SI-4
System Monitoring
SI-4(1)
System-Wide Intrusion Detection System
SI-4(10)
Visibility of Encrypted Communications
SI-4(11)
Analyze Communications Traffic Anomalies
SI-4(12)
Automated Organization-Generated Alerts
SI-4(14)
Wireless Intrusion Detection
SI-4(16)
Correlate Monitoring Information
SI-4(18)
Analyze Traffic and Covert Exfiltration
SI-4(19)
Risk for Individuals
SI-4(2)
Automated Tools and Mechanisms for Real-Time Analysis
SI-4(20)
Privileged Users
SI-4(22)
Unauthorized Network Services
SI-4(23)
Host-Based Devices
SI-4(4)
Inbound and Outbound Communications Traffic
SI-4(5)
System-Generated Alerts
SI-5
Security Alerts, Advisories, and Directives
SI-5(1)
Automated Alerts and Advisories
SI-6
Security and Privacy Function Verification
SI-7
Software, Firmware, and Information Integrity
SI-7(1)
Integrity Checks
SI-7(14)
Binary or Machine-Executable Code
SI-7(2)
Automated Notifications of Integrity Violations
SI-7(5)
Automated Response to Integrity Violations
SI-7(7)
Integration of Detection and Response
SI-8
Spam Protection
SI-8(2)
Automatic Updates
SR-1
Policy and Procedures (SR-1)
SR-10
Inspection of Systems or Components (SR-10)
SR-11
Component Authenticity (SR-11)
SR-11(1)
Anti-counterfeit Training (SR-11(1))
SR-11(2)
Configuration Control for Component Service and Repair (SR-11(2))
SR-12
Component Disposal (SR-12)
SR-2
Supply Chain Risk Management Plan (SR-2)
SR-3
Supply Chain Controls and Processes (SR-3)
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)
SR-6
Supplier Assessments and Reviews (SR-6)
SR-8
Notification Agreements (SR-8)
Show the 9 you already have
CA-8
Penetration Testing
CA-9
Internal System Connections
IR-4
Incident Handling
RA-1
Policy and Procedures
AC-2
Account Management
AC-3
Access Enforcement
IR-2
Incident Response and Recovery
RA-2
Security Categorization
RA-3
Risk Assessment

How this is calculated

Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition