Framework overlap

Does NIST Cybersecurity Framework 2.0 cover Japan AI Guidelines?

You hold NIST Cybersecurity Framework 2.0 and have been told to do Japan AI Guidelines. Here is how much overlaps, control by control.

54% of Japan AI Guidelines you already have

NIST Cybersecurity Framework 2.0 already covers about 54% of Japan AI Guidelines, leaving 6 of 13 controls as genuinely new work.

Already covered 0 Likely covered 7 New work 6

No control in NIST Cybersecurity Framework 2.0 maps directly to one in Japan AI Guidelines. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.

JP-AIG-Accountability-Governance-AI-Inventory-Stakeholder-Engagement-Board-Reporting-Tone-at-Top
Japan AI Guidelines Accountability + Governance + AI Inventory + Stakeholder Engagement + Board Reporting + Tone at Top + AI Ethics Committee + DPO + AI Officer + Regulatory Compli
JP-AIG-Generative-AI-Foundation-Model-Specific-Risks-Hallucination-Watermarking-Copyright-LLM-Multimodal
Japan AI Guidelines Generative AI + Foundation Model Specific Risks + Hallucination + Watermarking + Copyright + LLM + Multimodal + Prompt Injection + Jailbreak + Model Extraction
JP-AIG-Human-Oversight-Control-In-the-Loop-On-the-Loop-Article-22-GDPR-Equivalent-Automated-Decision-Restrictions
Japan AI Guidelines Human Oversight + Human-in-the-Loop + Human-on-the-Loop + Human-out-of-Loop + Article 22 GDPR Equivalent APPI Automated Decision Restrictions + Override Capabil
JP-AIG-Incident-Reporting-Response-AISI-METI-Notification-G7-Hiroshima-Reporting-Mechanism-Voluntary
Japan AI Guidelines AI Incident Reporting + Response + AISI/METI Notification + G7 Hiroshima Reporting Mechanism + Voluntary + AI Incident Database + OECD AI Incidents Monitor + Se
JP-AIG-Security-Adversarial-Attack-Protection-Prompt-Injection-Data-Poisoning-Model-Extraction-AISI-Red-Team
Japan AI Guidelines Security + Adversarial Attack Protection + Prompt Injection + Data Poisoning + Model Extraction + Membership Inference + AISI Red-Team + MLSecOps + Supply Chain
JP-AIG-Third-Party-AI-Supplier-Assurance-Foundation-Model-Provider-AISI-Evaluation-Voluntary-Audit
Japan AI Guidelines Third-Party AI Supplier Assurance + Foundation Model Provider + AISI Evaluation + Voluntary Audit + ISO/IEC 42001 AI Management System + Sub-Processor + Cloud A
Show the 7 you already have
JP-AIG-Continuous-Monitoring-Lifecycle-Model-Evaluation-Performance-Drift-Post-Deployment
Japan AI Guidelines Continuous Monitoring + AI System Lifecycle Management + Model Evaluation + Performance Drift + Concept Drift + Post-Deployment + Retraining Triggers + Safe Upd
JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection
Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Inf
JP-AIG-Fairness-Bias-Detection-Mitigation-Inclusive-AI-Discrimination-Prevention-10-Principles-2019-Heritage
Japan AI Guidelines Fairness + Bias Detection + Mitigation + Inclusive AI + Discrimination Prevention + 10 Principles 2019 Heritage + Protected Attributes + Disparate Impact + Stat
JP-AIG-Risk-Based-AI-System-Categorisation-Tiered-Approach-EU-AI-Act-Aligned-Generative-Foundation-Models
Japan AI Guidelines Risk-Based AI System Categorisation + Tiered Approach + EU AI Act Aligned + Generative AI + Foundation Models + High-Risk + Limited-Risk + Minimal-Risk + AISI C
JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming
Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Inci
JP-AIG-Scope-METI-MIC-AI-Guidelines-Business-v1.0-April2024-Society-5.0-Cabinet-Office-AI-Strategy-Council
Japan AI Guidelines Scope + METI/MIC AI Guidelines for Business v1.0 (April 2024) + Society 5.0 + Cabinet Office AI Strategy Council + 10 Principles 2019 Heritage + Education + Lit
JP-AIG-Transparency-Documentation-Model-Card-System-Card-Tier-Based-Disclosure-Hiroshima-Code-of-Conduct
Japan AI Guidelines Transparency + Documentation + Model Card + System Card + Datasheet + Tier-Based Disclosure + Hiroshima Code of Conduct + AI Generated Content + Watermarking +

How this is calculated

Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition