Framework overlap

Does NIST SP 800-53 Rev 5 cover NIST SP 800-53 Rev 5 LOW?

You hold NIST SP 800-53 Rev 5 and have been told to do NIST SP 800-53 Rev 5 LOW. Here is how much overlaps, control by control.

6% of NIST SP 800-53 Rev 5 LOW you already have

NIST SP 800-53 Rev 5 already covers about 6% of NIST SP 800-53 Rev 5 LOW, leaving 162 of 173 controls as genuinely new work.

Already covered 2 Likely covered 9 New work 162

What is genuinely new work

Nothing in NIST SP 800-53 Rev 5 reaches these. This is the list to scope.

AC-1
Policy and Procedures
AC-14
Permitted Actions Without Identification or Authentication
AC-17
Remote Access
AC-18
Wireless Access
AC-20
Use of External Systems
AC-22
Publicly Accessible Content
AC-7
Unsuccessful Logon Attempts
AC-8
System Use Notification
AT-1
Policy and Procedures
AT-2
Literacy Training and Awareness
AT-2(2)
Insider Threat
AT-3
Role-Based Training
AT-4
Training Records
AU-1
Policy and Procedures
AU-11
Audit Record Retention
AU-12
Audit Record Generation
AU-3
Content of Audit Records
AU-4
Audit Log Storage Capacity
AU-5
Response to Audit Logging Process Failures
AU-6
Audit Record Review, Analysis, and Reporting
AU-8
Time Stamps
AU-9
Protection of Audit Information
CA-1
Policy and Procedures
CA-2
Control Assessments
CA-3
Information Exchange
CA-5
Plan of Action and Milestones
CA-6
Authorization
CA-7
Continuous Monitoring
CA-7(4)
Risk Monitoring
CM-1
Policy and Procedures
CM-10
Software Usage Restrictions
CM-11
User-Installed Software
CM-2
Baseline Configuration
CM-4
Impact Analyses
CM-5
Access Restrictions for Change
CM-6
Configuration Settings
CM-7
Least Functionality
CM-8
System Component Inventory
CP-1
Policy and Procedures
CP-10
System Recovery and Reconstitution
CP-2
Contingency Plan
CP-3
Contingency Training
CP-4
Contingency Plan Testing
CP-9
System Backup
IA-1
Policy and Procedures
IA-11
Re-Authentication
IA-2
Identification and Authentication (Organizational Users)
IA-4
Identifier Management
IA-5
Authenticator Management
IA-6
Authentication Feedback
IA-7
Cryptographic Module Authentication
IA-8
Identification and Authentication (Non-Organizational Users)
IR-1
Event Detection and Triage
IR-5
Incident Monitoring
IR-6
Incident Reporting
IR-7
Incident Response Assistance
IR-8
Incident Response Plan
MA-1
Policy and Procedures
MA-2
Controlled Maintenance
MA-4
Nonlocal Maintenance
MA-5
Maintenance Personnel
MP-1
Policy and Procedures
MP-2
Media Access
MP-6
Media Sanitization
MP-7
Media Use
PE-1
Policy and Procedures
PE-12
Emergency Lighting
PE-13
Fire Protection
PE-14
Environmental Controls
PE-15
Water Damage Protection
PE-16
Delivery and Removal
PE-2
Physical Access Authorizations
PE-3
Physical Access Control
PE-6
Monitoring Physical Access
PE-8
Visitor Access Records
PL-1
Policy and Procedures
PL-10
Baseline Selection
PL-11
Baseline Tailoring
PL-2
System Security and Privacy Plans
PL-4
Rules of Behavior
PM-1
Information Security Program Plan
PM-10
Authorization Process
PM-11
Mission and Business Process Definition
PM-12
Insider Threat Program
PM-13
Security and Privacy Workforce
PM-14
Testing, Training, and Monitoring
PM-15
Security and Privacy Groups and Associations
PM-16
Threat Awareness Program
PM-17
Protecting CUI on External Systems
PM-18
Privacy Program Plan
PM-19
Privacy Program Leadership Role
PM-2
Information Security Program Leadership Role
PM-20
Dissemination of Privacy Program Information
PM-21
Accounting of Disclosures
PM-22
Personally Identifiable Information Quality Management
PM-23
Data Governance Body
PM-24
Data Integrity Board
PM-25
Minimization of PII Used in Testing, Training, and Research
PM-26
Complaint Management
PM-27
Privacy Reporting
PM-28
Risk Framing
PM-29
Risk Management Program Leadership Roles
PM-3
Information Security and Privacy Resources
PM-30
Supply Chain Risk Management Strategy
PM-31
Continuous Monitoring Strategy
PM-32
Purposing
PM-4
Plan of Action and Milestones Process
PM-5
System Inventory
PM-6
Measures of Performance
PM-7
Enterprise Architecture
PM-8
Critical Infrastructure Plan
PM-9
Risk Management Strategy
PS-1
Policy and Procedures
PS-2
Position Risk Designation
PS-3
Personnel Screening
PS-4
Personnel Termination
PS-5
Personnel Transfer
PS-6
Access Agreements
PS-7
External Personnel Security
PS-8
Personnel Sanctions
PS-9
Position Descriptions
PT-1
Policy and Procedures
PT-2
Authority to Process PII
PT-3
PII Processing Purposes
PT-4
Consent
PT-5
Privacy Notice
PT-6
System of Records Notice
PT-7
Specific Categories of PII
PT-8
Computer Matching Requirements
RA-2
Security Categorization
RA-5
Vulnerability Monitoring and Scanning
RA-7
Identifies and Analyzes Risk
SA-1
Logging and Monitoring
SA-2
Common Operating Picture
SA-22
Unsupported System Components
SA-4
Acquisition Process
SA-8
Security and Privacy Engineering Principles
SA-9
External System Services
SC-1
Policy and Procedures
SC-12
Cryptographic Key Establishment and Management
SC-13
Cryptographic Protection
SC-15
Collaborative Computing Devices and Applications
SC-20
Secure Name/Address Resolution Service (Authoritative)
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22
Architecture and Provisioning for Name/Address Resolution Service
SC-39
Process Isolation
SC-5
Denial-of-Service Protection
SC-7
Boundary Protection
SI-1
Policy and Procedures
SI-12
Information Management and Retention
SI-2
Flaw Remediation
SI-3
Malicious Code Protection
SI-4
System Monitoring
SI-5
Security Alerts, Advisories, and Directives
SR-1
Policy and Procedures (SR-1)
SR-10
Inspection of Systems or Components (SR-10)
SR-11
Component Authenticity (SR-11)
SR-12
Component Disposal (SR-12)
SR-2
Supply Chain Risk Management Plan (SR-2)
SR-3
Supply Chain Controls and Processes (SR-3)
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)
SR-8
Notification Agreements (SR-8)
Show the 11 you already have
IR-4
Incident Handling
RA-1
Policy and Procedures
AC-19
Access Control for Mobile Devices
AC-2
Account Management
AC-3
Access Enforcement
AU-2
Event Logging
CA-9
Internal System Connections
IR-2
Incident Response and Recovery
RA-3
Risk Assessment
SA-3
System Development Life Cycle
SA-5
System Documentation

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-53 Rev 5 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition