33% of CISA Zero Trust Maturity Model you already have
NIST SP 800-172 already covers about 33% of CISA Zero Trust Maturity Model, leaving
31 of 46 controls as genuinely new work.
Already covered 0
Likely covered 15
New work 31
No control in NIST SP 800-172
maps directly to one in CISA Zero Trust Maturity Model. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST SP 800-172 reaches these. This is the list to scope.
ZTMM-APP-1Application Access
ZTMM-APP-2Application Threat Protection
ZTMM-APP-3Secure Application Development and Deployment
ZTMM-APP-4Application Visibility and Analytics
ZTMM-APP-GOVApplications Pillar: Governance
ZTMM-APP-TESTApplications Pillar: Application Security Testing
ZTMM-CROSS-1Visibility and Analytics
ZTMM-CROSS-2Automation and Orchestration
ZTMM-CROSS-3Governance for Zero Trust
ZTMM-DAT-1Data Inventory and Classification
ZTMM-DAT-2Data Access Control
ZTMM-DAT-3Data Encryption
ZTMM-DAT-4Data Loss Prevention
ZTMM-DAT-AVAILData Pillar: Data Availability
ZTMM-DAT-CATData Pillar: Data Categorization
ZTMM-DAT-GOVData Pillar: Governance
ZTMM-DEV-1Device Inventory
ZTMM-DEV-2Device Compliance and Posture
ZTMM-DEV-3Device Threat Protection
ZTMM-DEV-GOVDevices Pillar: Governance
ZTMM-ID-1Identity Authentication
ZTMM-ID-3Risk Assessments for Identity
ZTMM-ID-4Access Management
ZTMM-ID-AOIdentity Pillar: Automation and Orchestration
ZTMM-ID-GOVIdentity Pillar: Governance
ZTMM-MAT-1Maturity Stage Self-Assessment
ZTMM-NET-1Network Segmentation
ZTMM-NET-2Network Traffic Management
ZTMM-NET-3Resilience and Availability
ZTMM-NET-ENCNetworks Pillar: Traffic Encryption
Show the 15 you already have
ZTMM-APP-AOApplications Pillar: Automation and Orchestration
ZTMM-APP-VAApplications Pillar: Visibility and Analytics
ZTMM-DAT-AOData Pillar: Automation and Orchestration
ZTMM-DAT-VAData Pillar: Visibility and Analytics
ZTMM-DEV-AODevices Pillar: Automation and Orchestration
ZTMM-DEV-SCRMDevices Pillar: Asset and Supply Chain Risk Management
ZTMM-DEV-VADevices Pillar: Visibility and Analytics
ZTMM-ID-VAIdentity Pillar: Visibility and Analytics
ZTMM-NET-AONetworks Pillar: Automation and Orchestration
ZTMM-NET-GOVNetworks Pillar: Governance
ZTMM-NET-VANetworks Pillar: Visibility and Analytics
ZTMM-STAGE-ADVMaturity Stage: Advanced
ZTMM-STAGE-INITMaturity Stage: Initial
ZTMM-STAGE-OPTMaturity Stage: Optimal
ZTMM-STAGE-TRADMaturity Stage: Traditional
How this is calculated
Already covered means a mapping runs from a control in NIST SP 800-172 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition