Framework overlap

Does NIST SP 800-171A cover Australian Energy Sector Cyber Security Framework (AESCSF)?

You hold NIST SP 800-171A and have been told to do Australian Energy Sector Cyber Security Framework (AESCSF). Here is how much overlaps, control by control.

22% of Australian Energy Sector Cyber Security Framework (AESCSF) you already have

NIST SP 800-171A already covers about 22% of Australian Energy Sector Cyber Security Framework (AESCSF), leaving 25 of 32 controls as genuinely new work.

Already covered 0 Likely covered 7 New work 25

No control in NIST SP 800-171A maps directly to one in Australian Energy Sector Cyber Security Framework (AESCSF). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-171A reaches these. This is the list to scope.

AESCSF-ACM-1
Asset inventory
AESCSF-APM-1
Australian privacy management
AESCSF-APM-2
Privacy breach management
AESCSF-CPM-1
Cyber security program management
AESCSF-CPM-2
Cyber security governance and strategy
AESCSF-CPM-3
Cyber security architecture
AESCSF-EDM-1
Supply chain risk management
AESCSF-EDM-2
External dependency assessment
AESCSF-EDM-3
Dependency resilience
AESCSF-IAM-3
Multi-factor authentication
AESCSF-IR-2
Incident detection and handling
AESCSF-IR-4
Incident reporting
AESCSF-ISC-1
Cyber security information sharing
AESCSF-ISC-2
Stakeholder communications
AESCSF-RM-1
Establish cyber security risk management strategy
AESCSF-RM-2
Identify and assess cyber risks
AESCSF-RM-3
Manage and treat cyber risks
AESCSF-SA-1
Logging and monitoring
AESCSF-SA-2
Anomaly and event detection
AESCSF-SA-3
Common operating picture
AESCSF-TVM-1
Vulnerability management
AESCSF-TVM-2
Threat management
AESCSF-WM-1
Cyber security workforce management
AESCSF-WM-2
Training and awareness
AESCSF-WM-3
Personnel security
Show the 7 you already have
AESCSF-ACM-2
Configuration management
AESCSF-ACM-3
Change management
AESCSF-IAM-1
Identity management
AESCSF-IAM-2
Access control
AESCSF-IR-1
Incident response plan
AESCSF-IR-3
Continuity of operations and recovery
AESCSF-TVM-3
Patch and remediation management

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171A to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition