Framework overlap

Does ASD Strategies to Mitigate Cyber Security Incidents cover NIST SP 800-66 Rev 2?

You hold ASD Strategies to Mitigate Cyber Security Incidents and have been told to do NIST SP 800-66 Rev 2. Here is how much overlaps, control by control.

83% of NIST SP 800-66 Rev 2 you already have

ASD Strategies to Mitigate Cyber Security Incidents already covers about 83% of NIST SP 800-66 Rev 2, leaving 11 of 65 controls as genuinely new work.

Already covered 30 Likely covered 24 New work 11

What is genuinely new work

Nothing in ASD Strategies to Mitigate Cyber Security Incidents reaches these. This is the list to scope.

164.310(a)(2)(ii)
Facility Security Plan (Addressable)
164.316(b)(2)
Time Limit, Availability, and Updates (Required)
RA-DOC
Risk Analysis: Document the Risk Assessment Results
RA-EPHI-LOC
Risk Analysis: Identify Where ePHI Is Created, Received, Maintained, or Transmitted
RA-IMPACT
Risk Analysis: Determine the Impact of a Threat Exploiting a Vulnerability
RA-LIKELIHOOD
Risk Analysis: Determine the Likelihood of a Threat Exploiting a Vulnerability
RA-PREP
Risk Analysis: Prepare for the Assessment
RA-RISK
Risk Analysis: Determine the Level of Risk
RA-SCOPE
Risk Analysis: Identify Scope of the Analysis
RA-THREATS
Risk Analysis: Identify Threats to ePHI
RA-VULN
Risk Analysis: Identify Potential Vulnerabilities and Predisposing Conditions
Show the 54 you already have
164.308(a)(1)(ii)(C)
Sanction Policy (Required)
164.308(a)(1)(ii)(D)
Information System Activity Review (Required)
164.308(a)(3)(i)
Workforce Security (Standard)
164.308(a)(3)(ii)(A)
Authorization and Supervision (Addressable)
164.308(a)(3)(ii)(B)
Workforce Clearance Procedure (Addressable)
164.308(a)(3)(ii)(C)
Termination Procedures (Addressable)
164.308(a)(4)(ii)(A)
Isolating Health Care Clearinghouse Functions (Required if applicable)
164.308(a)(4)(ii)(B)
Access Authorization (Addressable)
164.308(a)(4)(ii)(C)
Access Establishment and Modification (Addressable)
164.308(a)(5)(i)
Security Awareness and Training (Standard)
164.308(a)(5)(ii)(A)
Security Reminders (Addressable)
164.308(a)(5)(ii)(B)
Protection from Malicious Software (Addressable)
164.308(a)(5)(ii)(C)
Log-in Monitoring (Addressable)
164.308(a)(5)(ii)(D)
Password Management (Addressable)
164.308(a)(6)(i)
Security Incident Procedures (Standard)
164.308(a)(6)(ii)
Response and Reporting (Required)
164.308(a)(7)(i)
Contingency Plan (Standard)
164.308(a)(7)(ii)(A)
Data Backup Plan (Required)
164.308(a)(7)(ii)(B)
Disaster Recovery Plan (Required)
164.308(a)(7)(ii)(C)
Emergency Mode Operation Plan (Required)
164.308(a)(7)(ii)(D)
Testing and Revision Procedures (Addressable)
164.310(d)(1)
Device and Media Controls (Standard)
164.310(d)(2)(iii)
Accountability (Addressable)
164.310(d)(2)(iv)
Data Backup and Storage (Addressable)
164.312(a)(1)
Access Control (Standard)
164.312(a)(2)(i)
Unique User Identification (Required)
164.312(b)
Audit Controls (Standard)
164.312(d)
Person or Entity Authentication (Standard)
164.312(e)(1)
Transmission Security (Standard)
164.312(e)(2)(ii)
Encryption of Transmissions (Addressable)
164.308(a)(1)(i)
Security Management Process (Standard)
164.308(a)(1)(ii)(A)
Risk Analysis (Required)
164.308(a)(1)(ii)(B)
Risk Management (Required)
164.308(a)(2)
Assigned Security Responsibility (Standard)
164.308(a)(4)(i)
Information Access Management (Standard)
164.308(a)(7)(ii)(E)
Applications and Data Criticality Analysis (Addressable)
164.308(a)(8)
Evaluation (Standard)
164.308(b)(1)
Business Associate Contracts and Other Arrangements (Standard)
164.310(a)(1)
Facility Access Controls (Standard)
164.310(a)(2)(i)
Contingency Operations (Addressable)
164.310(a)(2)(iii)
Access Control and Validation Procedures (Addressable)
164.310(a)(2)(iv)
Maintenance Records (Addressable)
164.310(b)
Workstation Use (Standard)
164.310(c)
Workstation Security (Standard)
164.310(d)(2)(i)
Disposal (Required)
164.310(d)(2)(ii)
Media Re-use (Required)
164.312(a)(2)(ii)
Emergency Access Procedure (Required)
164.312(a)(2)(iii)
Automatic Logoff (Addressable)
164.312(a)(2)(iv)
Encryption and Decryption (Addressable)
164.312(c)(1)
Integrity (Standard)
164.312(c)(2)
Mechanism to Authenticate ePHI (Addressable)
164.312(e)(2)(i)
Integrity Controls for Transmission (Addressable)
164.316(a)
Policies and Procedures (Standard)
164.316(b)(1)
Documentation (Standard)

How this is calculated

Already covered means a mapping runs from a control in ASD Strategies to Mitigate Cyber Security Incidents to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition