18% of IEC 62351 you already have
NIST Cybersecurity Framework 2.0 already covers about 18% of IEC 62351, leaving
27 of 33 controls as genuinely new work.
Already covered 4
Likely covered 2
New work 27
What is genuinely new work
Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.
62351-10Security architecture guidelines
62351-11Security for XML documents
62351-3Profiles including TCP/IP
62351-4Profiles including MMS and similar payloads
62351-5Security for IEC 60870-5 and derivatives
62351-6Security for IEC 61850 profiles
62351-7Network and system management (NSM)
IEC62351-10Security Architecture
IEC62351-100Conformance Testing
IEC62351-11XML File Security
IEC62351-12Resilience for DER and Substation Automation
IEC62351-13Guidelines on Security Topics
IEC62351-14Cybersecurity Event Logging
IEC62351-3TLS for TCP/IP Profiles
IEC62351-4MMS and IEC 61850 Application Security
IEC62351-5IEC 60870-5 and DNP3 Secure Authentication
IEC62351-6IEC 61850 GOOSE and SV Security
IEC62351-7Network and System Management
IEC62351-8Role-Based Access Control
IEC62351-9Cybersecurity Key Management
IEC62351-CERTCertificate Lifecycle for Substations
IEC62351-ICCPICCP/TASE.2 Secure Bilateral
IEC62351-IRIncident Response for Substations
IEC62351-MONSecurity Monitoring of Substation Networks
IEC62351-PATCHPatch and Vulnerability Management for OT
IEC62351-SEGSegmentation of Process and Station Buses
IEC62351-SUPSupplier Security Requirements
Show the 6 you already have
62351-12Resilience and security recommendations for DER
62351-13Cyber-physical generation and storage resilience
62351-8Role-based access control (RBAC)
62351-14Cyber security event logging
62351-9Cyber security key management
How this is calculated
Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition