22% of NIST Cybersecurity Framework 2.0 you already have
OCC Heightened Standards (12 CFR Part 30, Appendix D) already covers about 22% of NIST Cybersecurity Framework 2.0, leaving
83 of 106 controls as genuinely new work.
Already covered 0
Likely covered 23
New work 83
No control in OCC Heightened Standards (12 CFR Part 30, Appendix D)
maps directly to one in NIST Cybersecurity Framework 2.0. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in OCC Heightened Standards (12 CFR Part 30, Appendix D) reaches these. This is the list to scope.
GV.OV-01Risk management strategy outcomes are reviewed
GV.OV-02Risk management strategy is reviewed for coverage
GV.OV-03Risk management performance is evaluated
NIST-CSF-DE.AE-02Potentially adverse events are analyzed to better understand associated activities
NIST-CSF-DE.AE-03Information is correlated from multiple sources
NIST-CSF-DE.AE-04Estimated impact and scope of adverse events are understood
NIST-CSF-DE.AE-06Information on adverse events is provided to authorized staff
NIST-CSF-DE.CM-01Networks and network services are monitored to find potentially adverse events
NIST-CSF-DE.CM-02The physical environment is monitored to find potentially adverse events
NIST-CSF-DE.CM-03Personnel activity and technology usage are monitored to find potentially adverse events
NIST-CSF-DE.CM-06External service provider activities are monitored to find potentially adverse events
NIST-CSF-DE.CM-09Computing hardware and software are monitored to find potentially adverse events
NIST-CSF-GV.OC-02Internal and external stakeholders are understood
NIST-CSF-GV.OC-03Legal, regulatory, and contractual requirements are understood
NIST-CSF-GV.OC-04Critical objectives, capabilities, and services are understood
NIST-CSF-GV.OC-05Outcomes and dependencies of critical services are understood
NIST-CSF-GV.PO-01Cybersecurity risk management policy is established based on context and strategy
NIST-CSF-GV.PO-02Policy is reviewed, updated, communicated, and enforced
NIST-CSF-GV.RM-01Risk management objectives are established and agreed upon
NIST-CSF-GV.RM-02Risk appetite and risk tolerance statements are established
NIST-CSF-GV.RM-05Communication lines for cybersecurity risk management are established
NIST-CSF-GV.RM-06A standardized method for calculating and expressing cybersecurity risk is established
NIST-CSF-GV.RR-01Organizational leadership is responsible for cybersecurity risk management
NIST-CSF-GV.RR-02Roles and responsibilities for cybersecurity risk management are established
NIST-CSF-GV.RR-03Adequate resources are allocated for cybersecurity risk management
NIST-CSF-GV.RR-04Cybersecurity is included in human resources practices
NIST-CSF-GV.SC-02Cybersecurity roles and responsibilities for suppliers are established
NIST-CSF-GV.SC-03Supply chain risk management is integrated into risk management
NIST-CSF-GV.SC-04Suppliers are known and prioritized by criticality
NIST-CSF-GV.SC-05Requirements are established and managed for suppliers
NIST-CSF-GV.SC-06Planning and due diligence are performed to reduce supply chain risks
NIST-CSF-GV.SC-07Supply chain risk management is verified throughout supplier relationships
NIST-CSF-GV.SC-08Relevant suppliers and partners are included in incident planning
NIST-CSF-GV.SC-09Supply chain security practices are integrated into security program
NIST-CSF-GV.SC-10Cybersecurity supply chain risk management plans include provisions for post-acquisition activities
NIST-CSF-ID.AM-01Inventories of hardware managed by the organization are maintained
NIST-CSF-ID.AM-02Inventories of software, services, and systems managed by the organization are maintained
NIST-CSF-ID.AM-03Representations of authorized network communication and data flows are maintained
NIST-CSF-ID.AM-05Assets are prioritized based on classification, criticality, resources, and impact
NIST-CSF-ID.AM-07Inventories of data and corresponding metadata are maintained
NIST-CSF-ID.AM-08Systems, hardware, software, and services are managed throughout their life cycles
NIST-CSF-ID.IM-01Improvements are identified from security test and exercise results
NIST-CSF-ID.IM-02Improvements are identified from security assessments
NIST-CSF-ID.IM-03Improvements are identified from operational activities and incidents
NIST-CSF-ID.RA-01Vulnerabilities in assets are identified, validated, and recorded
NIST-CSF-ID.RA-03Internal and external threats are identified and recorded
NIST-CSF-ID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified
NIST-CSF-ID.RA-05Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk
NIST-CSF-ID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicated
NIST-CSF-ID.RA-07Changes and exceptions are managed, assessed for risk impact, recorded, and tracked
NIST-CSF-ID.RA-08Effectiveness of risk responses is assessed
NIST-CSF-PR.AA-03Users, services, and hardware are authenticated
NIST-CSF-PR.AA-04Identity assertions are protected, conveyed, and verified
NIST-CSF-PR.AA-06Physical access to assets is managed, monitored, and enforced
NIST-CSF-PR.AT-01Personnel are provided awareness and training to perform cybersecurity duties
NIST-CSF-PR.AT-02Individuals in specialized roles are provided awareness and training
NIST-CSF-PR.DS-01The confidentiality, integrity, and availability of data-at-rest are protected
NIST-CSF-PR.DS-02The confidentiality, integrity, and availability of data-in-transit are protected
NIST-CSF-PR.DS-11Backups of data are created, protected, maintained, and tested
NIST-CSF-PR.IR-01Networks and environments are protected from unauthorized access
NIST-CSF-PR.IR-02The organization's technology assets are protected from environmental threats
NIST-CSF-PR.PS-02Software is maintained, replaced, and removed commensurate with risk
NIST-CSF-PR.PS-03Hardware is maintained, replaced, and removed commensurate with risk
NIST-CSF-PR.PS-04Log records are generated and made available for continuous monitoring
NIST-CSF-PR.PS-05Installation and execution of unauthorized software is prevented
NIST-CSF-PR.PS-06Secure software development practices are integrated throughout the SDLC
NIST-CSF-RC.CO-03Recovery activities and progress are communicated to stakeholders
NIST-CSF-RC.CO-04Public updates on incident recovery are shared using approved methods
NIST-CSF-RC.RP-02Recovery actions are selected, scoped, and prioritized
NIST-CSF-RC.RP-03The integrity of backups is verified before use in restoration
NIST-CSF-RC.RP-04Critical functions and services are restored to operational capability
NIST-CSF-RC.RP-05Integrity of restored assets is verified
NIST-CSF-RS.AN-03Analysis is performed to determine what has taken place during an incident
NIST-CSF-RS.AN-06Actions performed during an investigation are recorded
NIST-CSF-RS.AN-07Incident data and metadata are collected and their integrity preserved
NIST-CSF-RS.AN-08Incidents are analyzed to determine root cause
NIST-CSF-RS.CO-02Internal and external stakeholders are notified of incidents
NIST-CSF-RS.CO-03Information is shared with designated internal and external stakeholders
NIST-CSF-RS.MA-02Incident reports are triaged and validated
NIST-CSF-RS.MA-03Incidents are categorized and prioritized
NIST-CSF-RS.MA-04Incidents are escalated or elevated as needed
NIST-CSF-RS.MI-01Incidents are contained
NIST-CSF-RS.MI-02Incidents are eradicated
Show the 23 you already have
NIST-CSF-DE.AE-07Cyber threat intelligence and contextual information are integrated into analysis
NIST-CSF-DE.AE-08Incidents are declared when adverse events meet defined criteria
NIST-CSF-GV.OC-01Organizational context for cybersecurity risk management is understood
NIST-CSF-GV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk
NIST-CSF-GV.RM-04Strategic direction for cybersecurity risk management is established
NIST-CSF-GV.RM-07Opportunities for improvements are identified from risk assessments
NIST-CSF-GV.SC-01Cybersecurity supply chain risk management program is established
NIST-CSF-ID.AM-04Inventories of services provided by suppliers are maintained
NIST-CSF-ID.IM-04Incident response plans and other cybersecurity plans are established and maintained
NIST-CSF-ID.RA-02Cyber threat intelligence is received from information sharing forums
NIST-CSF-ID.RA-09Integrity and accuracy of risk assessment results are verified
NIST-CSF-ID.RA-10Critical suppliers are assessed on the basis of their risk
NIST-CSF-PR.AA-01Identities and credentials for authorized users, services, and hardware are managed
NIST-CSF-PR.AA-02Identities are proofed and bound to credentials based on the context of interactions
NIST-CSF-PR.AA-05Access permissions, entitlements, and authorizations are defined and managed
NIST-CSF-PR.DS-10The confidentiality, integrity, and availability of data-in-use are protected
NIST-CSF-PR.IR-03Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
NIST-CSF-PR.IR-04Adequate resource capacity to ensure availability is maintained
NIST-CSF-PR.PS-01Configuration management practices are established and applied
NIST-CSF-RC.RP-01The recovery portion of the incident response plan is executed
NIST-CSF-RC.RP-06End-of-recovery is declared based on criteria and documentation
NIST-CSF-RS.MA-01The incident response plan is executed in coordination with relevant third parties
NIST-CSF-RS.MA-05Criteria for initiating incident recovery are applied
How this is calculated
Already covered means a mapping runs from a control in OCC Heightened Standards (12 CFR Part 30, Appendix D) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition