Framework overlap

Does NIST SP 800-171A Rev 3 cover APRA CPS 230 Operational Risk Management?

You hold NIST SP 800-171A Rev 3 and have been told to do APRA CPS 230 Operational Risk Management. Here is how much overlaps, control by control.

32% of APRA CPS 230 Operational Risk Management you already have

NIST SP 800-171A Rev 3 already covers about 32% of APRA CPS 230 Operational Risk Management, leaving 32 of 47 controls as genuinely new work.

Already covered 8 Likely covered 7 New work 32

What is genuinely new work

Nothing in NIST SP 800-171A Rev 3 reaches these. This is the list to scope.

CPS230-10
Operational Risk Management Policy
CPS230-12
Internal Controls and Systems
CPS230-14
Senior Management Roles
CPS230-15
Operational Risk Framework
CPS230-17
Critical Operations Identification
CPS230-18
Critical Operations Register
CPS230-19
Critical Operation Tolerance Levels
CPS230-20
Capability to Remain Within Tolerance
CPS230-23
Regular Testing
CPS230-24
Internal Controls
CPS230-29
Communication Plans
CPS230-30
Risk Culture
CPS230-31
Escalation Procedures
CPS230-32
Dependencies Identification
CPS230-33
BCP Testing
CPS230-34
Tailored Testing Programs
CPS230-36
Tolerance Levels for Disruption
CPS230-38
Business Continuity Plan
CPS230-39
Material Service Provider Identification
CPS230-42
APRA Classification Power
CPS230-43
Due Diligence
CPS230-45
APRA Access Provisions
CPS230-47
Monitoring and Reporting
CPS230-48
Service Provider Due Diligence
CPS230-53
Service Provider Monitoring
CPS230-57
Concentration Risk
CPS230-60
APRA Notification of Provider Arrangements
CPS230-63
Operational Risk Reporting
CPS230-7
Board Responsibility
CPS230-70
Change Management
CPS230-8
Board Tolerance Levels
CPS230-9
Senior Management Accountability
Show the 15 you already have
CPS230-11
Risk Identification and Assessment
CPS230-13
Board Accountability
CPS230-16
Internal Audit Review
CPS230-27
Incident Management
CPS230-28
Recovery Objectives
CPS230-37
Service Provider Management Policy
CPS230-46
Ongoing Risk Management
CPS230-49
Internal Audit of Service Providers
CPS230-22
Vulnerability and Gap Identification
CPS230-25
Business Continuity Policy
CPS230-26
Business Continuity Plans
CPS230-40
Material Classification
CPS230-44
Service Provider Risk Identification
CPS230-50
Service Provider Contracts
CPS230-66
Independent Review

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171A Rev 3 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition