Framework overlap

Does NIST Cybersecurity Framework 2.0 cover FedRAMP Moderate?

You hold NIST Cybersecurity Framework 2.0 and have been told to do FedRAMP Moderate. Here is how much overlaps, control by control.

4% of FedRAMP Moderate you already have

NIST Cybersecurity Framework 2.0 already covers about 4% of FedRAMP Moderate, leaving 229 of 238 controls as genuinely new work.

Already covered 4 Likely covered 5 New work 229

What is genuinely new work

Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.

AC-1
Policy and Procedures
AC-10
Concurrent Session Control
AC-11
Device Lock
AC-12
Session Termination
AC-14
Permitted Actions Without Identification or Authentication
AC-17
Remote Access
AC-17(1)
Monitoring and Control
AC-17(2)
Protection of Confidentiality and Integrity Using Encryption
AC-17(3)
Managed Access Control Points
AC-17(4)
Privileged Commands and Access
AC-18
Wireless Access
AC-18(1)
Authentication and Encryption
AC-19
Access Control for Mobile Devices
AC-19(5)
Full Device or Container-Based Encryption
AC-2(1)
Automated System Account Management
AC-2(12)
Account Monitoring for Atypical Usage
AC-2(13)
Disable Accounts for High-Risk Individuals
AC-2(2)
Automated Temporary and Emergency Account Management
AC-2(3)
Disable Accounts
AC-2(4)
Automated Audit Actions
AC-2(5)
Inactivity Logout
AC-2(7)
Privileged User Accounts
AC-2(9)
Restrictions on Use of Shared and Group Accounts
AC-20
Use of External Systems
AC-20(1)
Limits on Authorized Use
AC-20(2)
Portable Storage Devices Restricted Use
AC-21
Information Sharing
AC-22
Publicly Accessible Content
AC-4
Information Flow Enforcement
AC-4(21)
Physical or Logical Separation of Information Flows
AC-5
Separation of Duties
AC-6
Least Privilege
AC-6(1)
Authorize Access to Security Functions
AC-6(10)
Prohibit Non-Privileged Users from Executing Privileged Functions
AC-6(2)
Non-Privileged Access for Nonsecurity Functions
AC-6(5)
Privileged Accounts
AC-6(7)
Review of User Privileges
AC-6(9)
Log Use of Privileged Functions
AC-7
Unsuccessful Logon Attempts
AC-8
System Use Notification
AT-1
Policy and Procedures
AT-2
Literacy Training and Awareness
AT-2(2)
Insider Threat
AT-2(3)
Social Engineering and Mining
AT-3
Role-Based Training
AT-4
Training Records
AU-1
Policy and Procedures
AU-11
Audit Record Retention
AU-12
Audit Record Generation
AU-2
Event Logging
AU-3
Content of Audit Records
AU-3(1)
Additional Audit Information
AU-4
Audit Log Storage Capacity
AU-5
Response to Audit Logging Process Failures
AU-6
Audit Record Review, Analysis, and Reporting
AU-6(1)
Automated Process Integration
AU-6(3)
Correlate Audit Record Repositories
AU-7
Audit Record Reduction and Report Generation
AU-7(1)
Automatic Processing
AU-8
Time Stamps
AU-9
Protection of Audit Information
AU-9(2)
Store on Separate Physical Systems or Components
AU-9(4)
Access by Subset of Privileged Users
CA-1
Policy and Procedures
CA-2
Control Assessments
CA-2(1)
Independent Assessors
CA-3
Information Exchange
CA-5
Plan of Action and Milestones
CA-6
Authorization
CA-7
Continuous Monitoring
CA-7(1)
Independent Assessment
CM-1
Policy and Procedures
CM-10
Software Usage Restrictions
CM-11
User-Installed Software
CM-2
Baseline Configuration
CM-2(2)
Automation Support for Accuracy and Currency
CM-2(3)
Retention of Previous Configurations
CM-2(7)
Configure Systems and Components for High-Risk Areas
CM-3
Configuration Change Control
CM-3(2)
Testing, Validation, and Documentation of Changes
CM-3(4)
Security and Privacy Representatives
CM-4
Impact Analyses
CM-5
Access Restrictions for Change
CM-6
Configuration Settings
CM-6(1)
Automated Management, Application, and Verification
CM-7
Least Functionality
CM-7(1)
Periodic Review
CM-7(2)
Prevent Program Execution
CM-7(5)
Authorized Software Allow-by-Exception
CM-8
System Component Inventory
CM-8(1)
Updates During Installation and Removal
CM-8(3)
Automated Unauthorized Component Detection
CM-9
Configuration Management Plan
CP-1
Policy and Procedures
CP-10
System Recovery and Reconstitution
CP-2
Contingency Plan
CP-2(1)
Coordinate with Related Plans
CP-2(3)
Resume Mission and Business Functions
CP-3
Contingency Training
CP-4
Contingency Plan Testing
CP-4(1)
Coordinate with Related Plans
CP-6
Alternate Storage Site
CP-7
Alternate Processing Site
CP-8
Telecommunications Services
CP-9
System Backup
CP-9(1)
Testing for Reliability and Integrity
IA-1
Policy and Procedures
IA-11
Re-Authentication
IA-2
Identification and Authentication (Organizational Users)
IA-2(1)
MFA to Privileged Accounts
IA-2(12)
Acceptance of PIV Credentials
IA-2(2)
MFA to Non-Privileged Accounts
IA-2(8)
Access to Accounts Replay Resistant
IA-3
Device Identification and Authentication
IA-4
Identifier Management
IA-5
Authenticator Management
IA-5(1)
Password-Based Authentication
IA-5(2)
Public Key-Based Authentication
IA-5(6)
Protection of Authenticators
IA-6
Authentication Feedback
IA-7
Cryptographic Module Authentication
IA-8
Identification and Authentication (Non-Organizational Users)
IR-1
Event Detection and Triage
IR-3
Continuity of Operations
IR-4(1)
Automated Incident Handling Processes
IR-5
Incident Monitoring
IR-6
Incident Reporting
IR-6(1)
Automated Reporting
IR-7
Incident Response Assistance
IR-8
Incident Response Plan
MA-1
Policy and Procedures
MA-2
Controlled Maintenance
MA-4
Nonlocal Maintenance
MA-5
Maintenance Personnel
MP-1
Policy and Procedures
MP-2
Media Access
MP-3
Media Marking
MP-4
Media Storage
MP-5
Media Transport
MP-6
Media Sanitization
MP-7
Media Use
PE-1
Policy and Procedures
PE-12
Emergency Lighting
PE-13
Fire Protection
PE-14
Environmental Controls
PE-16
Delivery and Removal
PE-17
Alternate Work Site
PE-2
Physical Access Authorizations
PE-3
Physical Access Control
PE-6
Monitoring Physical Access
PE-8
Visitor Access Records
PL-1
Policy and Procedures
PL-2
System Security and Privacy Plans
PL-4
Rules of Behavior
PL-8
Security and Privacy Architectures
PS-1
Policy and Procedures
PS-2
Position Risk Designation
PS-3
Personnel Screening
PS-4
Personnel Termination
PS-5
Personnel Transfer
PS-6
Access Agreements
PS-7
External Personnel Security
PS-8
Personnel Sanctions
RA-5
Vulnerability Monitoring and Scanning
RA-5(2)
Update Vulnerabilities to be Scanned
RA-5(5)
Privileged Access
RA-7
Identifies and Analyzes Risk
SA-1
Logging and Monitoring
SA-10
Developer Configuration Management
SA-11
Developer Testing and Evaluation
SA-2
Common Operating Picture
SA-3
System Development Life Cycle
SA-4
Acquisition Process
SA-4(10)
Use of Approved PIV Products
SA-5
System Documentation
SA-8
Security and Privacy Engineering Principles
SA-9
External System Services
SA-9(2)
Identification of Functions, Ports, Protocols, and Services
SC-1
Policy and Procedures
SC-10
Network Disconnect
SC-12
Cryptographic Key Establishment and Management
SC-13
Cryptographic Protection
SC-15
Collaborative Computing Devices and Applications
SC-17
Public Key Infrastructure Certificates
SC-18
Mobile Code
SC-2
Separation of System and User Functionality
SC-20
Secure Name/Address Resolution Service (Authoritative)
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22
Architecture and Provisioning for Name/Address Resolution Service
SC-23
Session Authenticity
SC-28
Protection of Information at Rest
SC-28(1)
Cryptographic Protection
SC-39
Process Isolation
SC-4
Information in Shared System Resources
SC-5
Denial-of-Service Protection
SC-7
Boundary Protection
SC-7(3)
Access Points
SC-7(4)
External Telecommunications Services
SC-7(5)
Deny by Default Allow by Exception
SC-7(7)
Split Tunneling for Remote Devices
SC-7(8)
Route Traffic to Authenticated Proxy Servers
SC-8
Transmission Confidentiality and Integrity
SC-8(1)
Cryptographic Protection
SI-1
Policy and Procedures
SI-10
Information Input Validation
SI-11
Error Handling
SI-12
Information Management and Retention
SI-16
Memory Protection
SI-2
Flaw Remediation
SI-2(2)
Automated Flaw Remediation Status
SI-3
Malicious Code Protection
SI-4
System Monitoring
SI-4(2)
Automated Tools and Mechanisms for Real-Time Analysis
SI-4(4)
Inbound and Outbound Communications Traffic
SI-4(5)
System-Generated Alerts
SI-5
Security Alerts, Advisories, and Directives
SI-7
Software, Firmware, and Information Integrity
SI-7(1)
Integrity Checks
SI-7(7)
Integration of Detection and Response
SI-8
Spam Protection
SR-1
Policy and Procedures (SR-1)
SR-10
Inspection of Systems or Components (SR-10)
SR-11
Component Authenticity (SR-11)
SR-12
Component Disposal (SR-12)
SR-2
Supply Chain Risk Management Plan (SR-2)
SR-3
Supply Chain Controls and Processes (SR-3)
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)
SR-6
Supplier Assessments and Reviews (SR-6)
SR-8
Notification Agreements (SR-8)
Show the 9 you already have
CA-8
Penetration Testing
CA-9
Internal System Connections
IR-4
Incident Handling
RA-1
Policy and Procedures
AC-2
Account Management
AC-3
Access Enforcement
IR-2
Incident Response and Recovery
RA-2
Security Categorization
RA-3
Risk Assessment

How this is calculated

Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition