Framework overlap

Does NIST Cybersecurity Framework 2.0 cover IEC 62351?

You hold NIST Cybersecurity Framework 2.0 and have been told to do IEC 62351. Here is how much overlaps, control by control.

18% of IEC 62351 you already have

NIST Cybersecurity Framework 2.0 already covers about 18% of IEC 62351, leaving 27 of 33 controls as genuinely new work.

Already covered 4 Likely covered 2 New work 27

What is genuinely new work

Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.

62351-10
Security architecture guidelines
62351-11
Security for XML documents
62351-3
Profiles including TCP/IP
62351-4
Profiles including MMS and similar payloads
62351-5
Security for IEC 60870-5 and derivatives
62351-6
Security for IEC 61850 profiles
62351-7
Network and system management (NSM)
IEC62351-10
Security Architecture
IEC62351-100
Conformance Testing
IEC62351-11
XML File Security
IEC62351-12
Resilience for DER and Substation Automation
IEC62351-13
Guidelines on Security Topics
IEC62351-14
Cybersecurity Event Logging
IEC62351-3
TLS for TCP/IP Profiles
IEC62351-4
MMS and IEC 61850 Application Security
IEC62351-5
IEC 60870-5 and DNP3 Secure Authentication
IEC62351-6
IEC 61850 GOOSE and SV Security
IEC62351-7
Network and System Management
IEC62351-8
Role-Based Access Control
IEC62351-9
Cybersecurity Key Management
IEC62351-CERT
Certificate Lifecycle for Substations
IEC62351-ICCP
ICCP/TASE.2 Secure Bilateral
IEC62351-IR
Incident Response for Substations
IEC62351-MON
Security Monitoring of Substation Networks
IEC62351-PATCH
Patch and Vulnerability Management for OT
IEC62351-SEG
Segmentation of Process and Station Buses
IEC62351-SUP
Supplier Security Requirements
Show the 6 you already have
62351-12
Resilience and security recommendations for DER
62351-13
Cyber-physical generation and storage resilience
62351-2
Glossary of terms
62351-8
Role-based access control (RBAC)
62351-14
Cyber security event logging
62351-9
Cyber security key management

How this is calculated

Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition