Framework overlap

Does NIST SP 800-171 cover NIST SP 800-187?

You hold NIST SP 800-171 and have been told to do NIST SP 800-187. Here is how much overlaps, control by control.

47% of NIST SP 800-187 you already have

NIST SP 800-171 already covers about 47% of NIST SP 800-187, leaving 17 of 32 controls as genuinely new work.

Already covered 0 Likely covered 15 New work 17

No control in NIST SP 800-171 maps directly to one in NIST SP 800-187. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-171 reaches these. This is the list to scope.

SP800-187-3.1
LTE Architecture Overview
SP800-187-3.10
SS7 Interworking Risk Mitigation
SP800-187-3.11
MME and HSS Hardening
SP800-187-3.12
Lawful Intercept Controls
SP800-187-3.13
Subscriber Privacy Logging
SP800-187-3.14
Denial of Service Mitigation
SP800-187-3.15
Roaming Security Agreements
SP800-187-3.16
Voice over LTE Security
SP800-187-3.17
Monitoring and Incident Response for LTE
SP800-187-3.2
User Equipment Identity Protection
SP800-187-3.3
Mutual Authentication via EPS-AKA
SP800-187-3.4
Air Interface Confidentiality
SP800-187-3.5
Air Interface Integrity Protection
SP800-187-3.6
Backhaul Protection with IPsec
SP800-187-3.7
eNodeB Physical and Logical Hardening
SP800-187-3.8
Femtocell and Small Cell Controls
SP800-187-3.9
Diameter Signaling Protection
Show the 15 you already have
SP800-187-ARCH-EPC
LTE Component: Evolved Packet Core (EPC)
SP800-187-ARCH-EUTRAN
LTE Component: E-UTRAN
SP800-187-ARCH-UE
LTE Component: Mobile Devices (UE)
SP800-187-SEC-AIRINTERFACE
Air Interface Security
SP800-187-SEC-BACKHAUL
Backhaul Security
SP800-187-SEC-CORE
Core Network Security
SP800-187-SEC-CRYPTO
Cryptographic Overview
SP800-187-SEC-EUTRAN
E-UTRAN Security
SP800-187-SEC-HARDWARE
Hardware Security
SP800-187-SEC-UEAUTH
UE Authentication
SP800-187-THR-MALWARE-CORE
Threat: Malware Impacting Core Infrastructure
SP800-187-THR-MALWARE-RAN
Threat: Malware Impacting RAN Infrastructure
SP800-187-THR-MALWARE-UE
Threat: Malware Attacks on UEs
SP800-187-THR-ROGUE-BS
Threat: Rogue Base Stations and Eavesdropping
SP800-187-THR-SIGNALING
Threat: Signaling and Protocol Attacks

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition