63% of NIST SP 800-53A Rev. 5 you already have
NIST SP 800-207 already covers about 63% of NIST SP 800-53A Rev. 5, leaving
18 of 48 controls as genuinely new work.
Already covered 0
Likely covered 30
New work 18
No control in NIST SP 800-207
maps directly to one in NIST SP 800-53A Rev. 5. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST SP 800-207 reaches these. This is the list to scope.
53A-ASMT-PLANDevelop a Security and Privacy Assessment Plan
53A-ASSESSOR-INDEPEstablish Assessor Independence
53A-AUTOMATED-EVIDUse Automated Evidence Collection
53A-CONTINUOUSSupport Continuous Control Monitoring
53A-CONTROL-INHERITAssess Inherited and Hybrid Controls
53A-DEPTH-COVERAGEDetermine Assessment Depth and Coverage
53A-EVIDENCE-CHAINMaintain Evidence Chain of Custody
53A-FINDINGSDocument Assessment Findings and Recommendations
53A-METHOD-EXAMINEApply the Examine Assessment Method
53A-METHOD-INTERVIEWApply the Interview Assessment Method
53A-METHOD-TESTApply the Test Assessment Method
53A-OBJECT-INVENTORYIdentify Assessment Objects
53A-OBJECTIVEDefine Assessment Objectives and Determination Statements
53A-PRIVACY-ASMTAssess Privacy Controls
53A-RETESTRetest After Remediation
53A-SAMPLINGApply Sampling for Population Assessments
53A-SARProduce Security and Privacy Assessment Report
53A-SUPPLY-CHAINAssess Supply Chain Risk Management Controls
Show the 30 you already have
SP800-53A-FAM-ACAssessment Procedures: Access Control (AC)
SP800-53A-FAM-ATAssessment Procedures: Awareness and Training (AT)
SP800-53A-FAM-AUAssessment Procedures: Audit and Accountability (AU)
SP800-53A-FAM-CAAssessment Procedures: Assessment, Authorization, and Monitoring (CA)
SP800-53A-FAM-CMAssessment Procedures: Configuration Management (CM)
SP800-53A-FAM-CPAssessment Procedures: Contingency Planning (CP)
SP800-53A-FAM-IAAssessment Procedures: Identification and Authentication (IA)
SP800-53A-FAM-IRAssessment Procedures: Incident Response (IR)
SP800-53A-FAM-MAAssessment Procedures: Maintenance (MA)
SP800-53A-FAM-MPAssessment Procedures: Media Protection (MP)
SP800-53A-FAM-PEAssessment Procedures: Physical and Environmental Protection (PE)
SP800-53A-FAM-PLAssessment Procedures: Planning (PL)
SP800-53A-FAM-PMAssessment Procedures: Program Management (PM)
SP800-53A-FAM-PSAssessment Procedures: Personnel Security (PS)
SP800-53A-FAM-PTAssessment Procedures: PII Processing and Transparency (PT)
SP800-53A-FAM-RAAssessment Procedures: Risk Assessment (RA)
SP800-53A-FAM-SAAssessment Procedures: System and Services Acquisition (SA)
SP800-53A-FAM-SCAssessment Procedures: System and Communications Protection (SC)
SP800-53A-FAM-SIAssessment Procedures: System and Information Integrity (SI)
SP800-53A-FAM-SRAssessment Procedures: Supply Chain Risk Management (SR)
SP800-53A-METHOD-EXAMINEAssessment Method: Examine
SP800-53A-METHOD-INTERVIEWAssessment Method: Interview
SP800-53A-METHOD-TESTAssessment Method: Test
SP800-53A-OBJECTSAssessment Objects
SP800-53A-STEP-ANALYZEAnalyze Assessment Report Results
SP800-53A-STEP-CAPABILITYAssess Security and Privacy Capabilities
SP800-53A-STEP-CONDUCTConduct Control Assessments
SP800-53A-STEP-PLANDevelop Security and Privacy Assessment Plans
SP800-53A-STEP-PREPAREPrepare for Control Assessments
SP800-53A-STEP-SELECTSelect and Tailor Assessment Procedures
How this is calculated
Already covered means a mapping runs from a control in NIST SP 800-207 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition