Framework overlap

Does NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security cover NIST SP 800-207?

You hold NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security and have been told to do NIST SP 800-207. Here is how much overlaps, control by control.

25% of NIST SP 800-207 you already have

NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security already covers about 25% of NIST SP 800-207, leaving 38 of 51 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 38

No control in NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security maps directly to one in NIST SP 800-207. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security reaches these. This is the list to scope.

SP800-207-2.1
Tenet 1: All Data Sources and Computing Services as Resources
SP800-207-2.3
Tenet 3: Per Session Resource Access
SP800-207-2.4
Tenet 4: Dynamic Policy Driven Access
SP800-207-2.5
Tenet 5: Monitor Integrity and Posture of Assets
SP800-207-2.6
Tenet 6: Dynamic Authentication and Authorization
SP800-207-2.7
Tenet 7: Telemetry to Improve Posture
SP800-207-3.1
Policy Engine Capabilities
SP800-207-3.2
Policy Administrator Role
SP800-207-3.3
Policy Enforcement Point Coverage
SP800-207-3.4
Continuous Diagnostics and Mitigation Inputs
SP800-207-3.5
Identity Management Integration
SP800-207-4.1
Enhanced Identity Governance Deployment
SP800-207-4.3
Software Defined Perimeter Deployment
SP800-207-5.1
Trust Algorithm Documentation
SP800-207-6.1
ZTA Threats and Mitigations
SP800-207-7.1
Migration Strategy and Roadmap
SP800-207-7.2
Interoperability with Existing Controls
SP800-207-DEP-AGENT
Device Agent/Gateway-Based Deployment
SP800-207-DEP-ENCLAVE
Enclave-Based Deployment
SP800-207-DEP-PORTAL
Resource Portal-Based Deployment
SP800-207-MIG-ASSETS
Migration Step: Identify Assets Owned by the Enterprise
SP800-207-MIG-POLICY
Migration Step: Formulate Policies for the ZTA Candidate
SP800-207-MIG-PROCESS
Migration Step: Identify Key Processes and Evaluate Risks
SP800-207-NET-REQ
Network Requirements to Support ZTA
SP800-207-SC-CROSSENT
Deployment Scenario: Collaboration Across Enterprise Boundaries
SP800-207-SC-MULTICLOUD
Deployment Scenario: Multi-cloud / Cloud-to-Cloud Enterprise
SP800-207-SC-PUBLIC
Deployment Scenario: Public- or Customer-Facing Services
SP800-207-SC-SATELLITE
Deployment Scenario: Enterprise with Satellite Facilities
SP800-207-SUP-COMPLY
Industry Compliance System
SP800-207-SUP-DAP
Data Access Policies
SP800-207-SUP-LOGS
Network and System Activity Logs
SP800-207-SUP-SIEM
Security Information and Event Management (SIEM) System
SP800-207-SUP-THREAT
Threat Intelligence Feeds
SP800-207-TA-CRITERIA
Criteria-Based vs Score-Based Trust Algorithm
SP800-207-THR-DOS
Threat: Denial-of-Service or Network Disruption
SP800-207-THR-PROPRIETARY
Threat: Reliance on Proprietary Data Formats or Solutions
SP800-207-THR-STORAGE
Threat: Storage of System and Network Information
SP800-207-THR-VISIBILITY
Threat: Limited Visibility on the Network
Show the 13 you already have
SP800-207-2.2
Tenet 2: All Communication Secured Regardless of Network
SP800-207-4.2
Micro Segmentation Deployment
SP800-207-DEP-SANDBOX
Device Application Sandboxing
SP800-207-MIG-ACTORS
Migration Step: Identify Actors on the Enterprise
SP800-207-MIG-DEPLOY
Migration Step: Identify Candidate Solutions, Deploy, and Expand
SP800-207-SC-CONTRACTED
Deployment Scenario: Contracted Services and Nonemployee Access
SP800-207-SUP-CDM
Continuous Diagnostics and Mitigation (CDM) System
SP800-207-SUP-IDM
Identity Management System
SP800-207-SUP-PKI
Enterprise Public Key Infrastructure (PKI)
SP800-207-TA-CONTEXT
Singular vs Contextual Trust Algorithm
SP800-207-THR-CREDS
Threat: Stolen Credentials and Insider Threat
SP800-207-THR-NPE
Threat: Use of Non-Person Entities (NPE) in ZTA Administration
SP800-207-THR-SUBVERT
Threat: Subversion of ZTA Decision Process

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition