Framework overlap

Does NIST SP 800-171 cover NIST SP 800-150?

You hold NIST SP 800-171 and have been told to do NIST SP 800-150. Here is how much overlaps, control by control.

40% of NIST SP 800-150 you already have

NIST SP 800-171 already covers about 40% of NIST SP 800-150, leaving 21 of 35 controls as genuinely new work.

Already covered 0 Likely covered 14 New work 21

No control in NIST SP 800-171 maps directly to one in NIST SP 800-150. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-171 reaches these. This is the list to scope.

SP800-150-DESIGNATIONS
Sharing Designations
SP800-150-RULES
Establish Information Sharing Rules
SP800-150-SENSITIVITY
Information Sensitivity and Privacy
TIS-1
Threat Information Sharing Goals and Objectives
TIS-10
Threat Information Sharing Channels
TIS-11
Trust Establishment with Sharing Partners
TIS-12
Anonymisation and Attribution Controls
TIS-13
Consumption and Integration of Threat Information
TIS-14
Feedback to Producers and Communities
TIS-15
Operational Security of Sharing Activities
TIS-16
Threat Sharing Programme Metrics
TIS-17
Incident-Driven Sharing
TIS-18
Continuous Improvement and Programme Review
TIS-2
Roles and Responsibilities for Threat Sharing
TIS-3
Threat Information Sharing Plan
TIS-4
Legal, Regulatory, and Contractual Review
TIS-5
Information Handling and Sensitivity Marking
TIS-6
Data Minimisation and Sanitisation
TIS-7
Threat Information Sources and Feeds
TIS-8
Threat Information Production and Curation
TIS-9
Indicator and Observable Management
Show the 14 you already have
SP800-150-ALERTS
Consume and Respond to Security Alerts
SP800-150-BENEFITS
Benefits of Information Sharing
SP800-150-CHALLENGES
Challenges to Information Sharing
SP800-150-COMMUNICATE
Engage in Ongoing Communication
SP800-150-EXTERNAL
Identify External Sources of Cyber Threat Information
SP800-150-GOALS
Define Information Sharing Goals and Objectives
SP800-150-INDICATORS-USE
Consume and Use Indicators
SP800-150-INFO-TYPES
Threat Information Types
SP800-150-INTERNAL
Identify Internal Sources of Cyber Threat Information
SP800-150-JOIN
Join a Sharing Community
SP800-150-PROCEDURES
Sharing and Tracking Procedures
SP800-150-PRODUCE
Produce and Publish Indicators
SP800-150-STORE
Organize and Store Cyber Threat Information
SP800-150-SUPPORT
Plan for Ongoing Support

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition