Framework overlap

Does NIST SP 800-53 Revision 5.1 HIGH cover FBI CJIS Security Policy?

You hold NIST SP 800-53 Revision 5.1 HIGH and have been told to do FBI CJIS Security Policy. Here is how much overlaps, control by control.

36% of FBI CJIS Security Policy you already have

NIST SP 800-53 Revision 5.1 HIGH already covers about 36% of FBI CJIS Security Policy, leaving 21 of 33 controls as genuinely new work.

Already covered 1 Likely covered 11 New work 21

What is genuinely new work

Nothing in NIST SP 800-53 Revision 5.1 HIGH reaches these. This is the list to scope.

CJIS-1
Information Exchange Agreements
CJIS-15
Mobile Devices
CJIS-18
Security Assessment and Authorization
CJIS-20
System Acquisition
CJIS-5.1
Information Exchange Agreements
CJIS-5.10
System and Communications Protection
CJIS-5.11
Formal Audits
CJIS-5.12
Personnel Security
CJIS-5.13
Mobile Devices
CJIS-5.2
Security Awareness Training
CJIS-5.3
Incident Response
CJIS-5.4
Auditing and Accountability
CJIS-5.6
Identification and Authentication
CJIS-5.8
Media Protection
CJIS-5.9
Physical Protection
CJIS-AM-1
Account Management
CJIS-CM-1
Cloud Service Provider Controls
CJIS-IR-2
Notification to CJIS Systems Officer
CJIS-PE-2
Physically Secure Location
CJIS-SC-1
Boundary Protection
CJIS-SC-2
Wireless Network Protections
Show the 12 you already have
CJIS-17
Risk Assessment
CJIS-10
System and Information Integrity
CJIS-14
Physical Protection
CJIS-16
Cloud Computing
CJIS-19
Supply Chain Risk Management
CJIS-2
Security Awareness Training
CJIS-3
Personnel Security
CJIS-5.5
Access Control
CJIS-5.7
Configuration Management
CJIS-7
Configuration Management
CJIS-8
Media Protection
CJIS-9
System and Communications Protection

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-53 Revision 5.1 HIGH to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition