NIST CSF 2.0 to CIS Controls v8.1 control mapping
NIST CSF 2.0 and CIS Controls v8.1 both map to 134 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.
- Shared NIST 800-53 controls
- 134
- NIST CSF 2.0 controls involved
- 97
- CIS Controls v8.1 controls involved
- 130
- NIST 800-53 families touched
- 16
How this pairing is derived
Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored NIST CSF 2.0 to CIS Controls v8.1 crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.
Shared controls in full
| NIST 800-53 control | Family | NIST CSF 2.0 controls | CIS Controls v8.1 controls |
|---|---|---|---|
| AC-1Policy and Procedures | ACAccess Control | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05 | CIS-4.7, CIS-5, CIS-5.6, CIS-6, CIS-6.6 |
| AC-2(7)Privileged User Accounts | ACAccess Control | PR.AA-05 | CIS-3.3, CIS-6, CIS-6.8 |
| AC-4(25)Data Sanitization | ACAccess Control | ID.AM-07 | CIS-3.5 |
| AC-6Least Privilege | ACAccess Control | PR.AA-05, PR.DS-10 | CIS-5.4 |
| AT-1Policy and Procedures | ATAwareness and Training | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03 | CIS-14, CIS-14.1 |
| AT-2Literacy Training and Awareness | ATAwareness and Training | PR.AT-01 | CIS-14.3, CIS-14.7, CIS-14.8 |
| AT-3Role-based Training | ATAwareness and Training | PR.AT-01, PR.AT-02 | CIS-14.3, CIS-14.4, CIS-14.7, CIS-14.8, CIS-14.9, CIS-16.9 |
| AT-3(2)Physical Security Controls | ATAwareness and Training | PR.AT-01, PR.AT-02 | CIS-14.3, CIS-14.4, CIS-14.7, CIS-14.8, CIS-14.9, CIS-16.9 |
| AU-1Policy and Procedures | AUAudit and Accountability | DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-04 | CIS-13, CIS-13.6, CIS-8, CIS-8.2 |
| AU-2Event Logging | AUAudit and Accountability | DE.AE-03, DE.AE-06, DE.CM-01 | CIS-13.1, CIS-3.14, CIS-8.1, CIS-8.12, CIS-8.2, CIS-8.3, CIS-8.4, CIS-8.5, CIS-8.6, CIS-8.7, CIS-8.8, CIS-8.9 |
| AU-3Content of Audit Records | AUAudit and Accountability | PR.PS-04 | CIS-3.14, CIS-8.2, CIS-8.5 |
| AU-6Audit Record Review, Analysis, and Reporting | AUAudit and Accountability | DE.AE-03, DE.AE-06 | CIS-13.1, CIS-3.14, CIS-8.1, CIS-8.12, CIS-8.2, CIS-8.3, CIS-8.4, CIS-8.5, CIS-8.6, CIS-8.7, CIS-8.8, CIS-8.9 |
| AU-6(3)Correlate Audit Record Repositories | AUAudit and Accountability | DE.AE-03, DE.AE-06 | CIS-13.6, CIS-3.14, CIS-8.12 |
| AU-6(9)Correlation with Information from Nontechnical Sources | AUAudit and Accountability | DE.AE-03, DE.AE-06 | CIS-13.6, CIS-3.14, CIS-8.12 |
| CM-1Policy and Procedures | CMConfiguration Management | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.PS-01, PR.PS-05 | CIS-2, CIS-4, CIS-4.1, CIS-4.2 |
| CM-2Baseline Configuration | CMConfiguration Management | PR.DS-10, PR.PS-05 | CIS-10.3, CIS-10.4, CIS-10.5, CIS-16.7, CIS-4.1, CIS-4.10, CIS-4.2, CIS-4.3, CIS-4.4, CIS-4.5, CIS-4.6, CIS-4.7, CIS-4.8 |
| CM-3(2)Testing, Validation, and Documentation of Changes | CMConfiguration Management | ID.RA-07 | CIS-18.4 |
| CM-6Configuration Settings | CMConfiguration Management | PR.DS-10, PR.PS-05 | CIS-10.3, CIS-10.4, CIS-10.5, CIS-16.7, CIS-4.1, CIS-4.10, CIS-4.2, CIS-4.3, CIS-4.4, CIS-4.5, CIS-4.6, CIS-4.7, CIS-4.8 |
| CM-7Least Functionality | CMConfiguration Management | PR.PS-05 | CIS-4, CIS-4.6, CIS-4.8 |
| CM-7(2)Prevent Program Execution | CMConfiguration Management | PR.PS-05 | CIS-2.5 |
| CM-8System Component Inventory | CMConfiguration Management | ID.AM-01, ID.AM-02 | CIS-1, CIS-1.1, CIS-1.3, CIS-2, CIS-2.1, CIS-2.2, CIS-2.4, CIS-6.6 |
| CM-9Configuration Management Plan | CMConfiguration Management | PR.PS-01, PR.PS-05 | CIS-2, CIS-4, CIS-4.1, CIS-4.2 |
| CM-11(2)Software Installation with Privileged Status | CMConfiguration Management | PR.PS-05 | CIS-9.1, CIS-9.4 |
| CP-1Policy and Procedures | CPContingency Planning | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05 | CIS-11, CIS-11.1 |
| CP-2Contingency Plan | CPContingency Planning | GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05 | CIS-11, CIS-11.1 |
| CP-9System Backup | CPContingency Planning | PR.DS-11 | CIS-11.2 |
| CP-9(1)Testing for Reliability and Integrity | CPContingency Planning | PR.DS-11 | CIS-11.3, CIS-11.5 |
| CP-9(2)Test Restoration Using Sampling | CPContingency Planning | PR.DS-11 | CIS-11.5 |
| CP-10System Recovery and Reconstitution | CPContingency Planning | GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-01, RC.RP-02, RC.RP-04, RC.RP-05, RS.MA-05 | CIS-11, CIS-11.1, CIS-11.3 |
| CP-10(6)Component Protection | CPContingency Planning | RC.RP-03 | CIS-11.3 |
| IA-1Policy and Procedures | IAIdentification and Authentication | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.AA-05 | CIS-4.7, CIS-5, CIS-5.6, CIS-6, CIS-6.6 |
| IA-2Identification and Authentication (Organizational Users) | IAIdentification and Authentication | PR.AA-01, PR.AA-03, PR.AA-05 | CIS-12.5, CIS-5.5, CIS-5.6, CIS-6.7 |
| IA-3Device Identification and Authentication | IAIdentification and Authentication | PR.AA-01, PR.AA-03, PR.AA-05 | CIS-12.5 |
| IA-3(1)Cryptographic Bidirectional Authentication | IAIdentification and Authentication | PR.AA-01, PR.AA-03, PR.AA-05 | CIS-12.5 |
| IA-3(4)Device Attestation | IAIdentification and Authentication | PR.AA-01, PR.AA-03, PR.AA-05 | CIS-12.5 |
| IA-4Identifier Management | IAIdentification and Authentication | PR.AA-03, PR.AA-04, PR.AA-05 | CIS-12.5, CIS-5.6, CIS-6.6 |
| IA-4(4)Identify User Status | IAIdentification and Authentication | PR.AA-03, PR.AA-04, PR.AA-05 | CIS-12.5, CIS-5.6, CIS-6.6 |
| IA-8Identification and Authentication (Non-organizational Users) | IAIdentification and Authentication | PR.AA-01, PR.AA-03, PR.AA-05 | CIS-12.5 |
| IA-9Service Identification and Authentication | IAIdentification and Authentication | PR.AA-01, PR.AA-03, PR.AA-05 | CIS-5.5 |
| IR-1Policy and Procedures | IRIncident Response | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-08, ID.IM-02, ID.IM-03, ID.IM-04, RS.AN-03 | CIS-16.3, CIS-17, CIS-17.5, CIS-17.8 |
| IR-4Incident Handling | IRIncident Response | DE.AE-02, DE.AE-03, DE.AE-04, DE.AE-06, DE.AE-08, GV.SC-08, RC.CO-03, RC.RP-06, RS.AN-06, RS.CO-02, RS.CO-03, RS.MA-01, RS.MA-02, RS.MA-04, RS.MI-01, RS.MI-02 | CIS-17, CIS-17.1, CIS-17.3, CIS-17.4, CIS-17.5, CIS-17.6, CIS-17.9, CIS-2.3 |
| IR-4(3)Continuity of Operations | IRIncident Response | DE.AE-02, DE.AE-04, DE.AE-06, DE.AE-08, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.AN-08, RS.MA-03, RS.MA-05 | CIS-11, CIS-11.1 |
| IR-4(4)Information Correlation | IRIncident Response | DE.AE-03, DE.AE-06 | CIS-13.1, CIS-13.6, CIS-3.14, CIS-8.1, CIS-8.12, CIS-8.2, CIS-8.3, CIS-8.4, CIS-8.5, CIS-8.6, CIS-8.7, CIS-8.8, CIS-8.9 |
| IR-4(10)Supply Chain Coordination | IRIncident Response | GV.SC-08, RS.CO-02, RS.CO-03 | CIS-17.2 |
| IR-4(11)Integrated Incident Response Team | IRIncident Response | DE.AE-06, RS.MA-01, RS.MA-04 | CIS-17.1, CIS-17.4, CIS-17.5, CIS-17.6, CIS-17.9 |
| IR-4(12)Malicious Code and Forensic Analysis | IRIncident Response | ID.IM-02, ID.IM-03, RS.AN-03, RS.AN-06, RS.AN-07 | CIS-16.3, CIS-17.8 |
| IR-5Incident Monitoring | IRIncident Response | DE.AE-06, RC.RP-06, RS.AN-06 | CIS-17.2, CIS-17.6 |
| IR-6Incident Reporting | IRIncident Response | DE.AE-06, RC.CO-03, RS.CO-02, RS.CO-03, RS.MA-01 | CIS-17.2 |
| IR-6(2)Vulnerabilities Related to Incidents | IRIncident Response | ID.IM-02, ID.IM-03, RS.AN-03 | CIS-16.3, CIS-17.2, CIS-17.8 |
| IR-6(3)Supply Chain Coordination | IRIncident Response | RS.CO-02, RS.CO-03 | CIS-17.2 |
| IR-8Incident Response Plan | IRIncident Response | DE.AE-06, ID.IM-04, RS.MA-01, RS.MA-02, RS.MA-04 | CIS-17.1, CIS-17.4, CIS-17.5, CIS-17.6, CIS-17.9 |
| PL-1Policy and Procedures | PLPlanning | GV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.RR-03, GV.SC-01, GV.SC-03, GV.SC-05, ID.RA-09, PR.PS-06 | CIS-15.7, CIS-16 |
| PL-2System Security and Privacy Plans | PLPlanning | ID.AM-03 | CIS-12.4, CIS-3.8 |
| PL-8Security and Privacy Architectures | PLPlanning | PR.IR-01, PR.IR-03 | CIS-12.2, CIS-16.10 |
| PL-9Central Management | PLPlanning | GV.RM-05, GV.RR-01, GV.RR-02 | CIS-10.6, CIS-16.10, CIS-7.4 |
| PL-10Baseline Selection | PLPlanning | PR.DS-10, PR.PS-05 | CIS-10.3, CIS-10.4, CIS-10.5, CIS-16.7, CIS-4.1, CIS-4.10, CIS-4.2, CIS-4.3, CIS-4.4, CIS-4.5, CIS-4.6, CIS-4.7, CIS-4.8 |
| RA-1Policy and Procedures | RARisk Assessment | GV.OV-01, GV.OV-02, GV.OV-03, GV.PO-01, GV.PO-02, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09 | CIS-16.6 |
| RA-2Security Categorization | RARisk Assessment | ID.RA-04 | CIS-16.6 |
| RA-2(1)Impact-level Prioritization | RARisk Assessment | ID.RA-05, ID.RA-06 | CIS-16.6 |
| RA-3(1)Supply Chain Risk Assessment | RARisk Assessment | GV.SC-09 | CIS-15.5 |
| RA-5Vulnerability Monitoring and Scanning | RARisk Assessment | ID.RA-01 | CIS-7.5, CIS-7.6 |
| RA-9Criticality Analysis | RARisk Assessment | GV.OC-04, GV.OC-05, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, ID.AM-05, ID.RA-04, ID.RA-10, PR.PS-06 | CIS-15.3, CIS-15.7 |
| SA-1Policy and Procedures | SASystem and Services Acquisition | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.RA-09, PR.PS-06 | CIS-15.7, CIS-16, CIS-16.1, CIS-16.10, CIS-16.11, CIS-16.5 |
| SA-3System Development Life Cycle | SASystem and Services Acquisition | GV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03 | CIS-15.7 |
| SA-3(1)Manage Preproduction Environment | SASystem and Services Acquisition | GV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03 | CIS-15.7, CIS-16.8 |
| SA-4Acquisition Process | SASystem and Services Acquisition | GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10, ID.RA-09, PR.PS-06 | CIS-15, CIS-15.2, CIS-15.7, CIS-16, CIS-16.4 |
| SA-4(1)Functional Properties of Controls | SASystem and Services Acquisition | ID.AM-03 | CIS-12.4, CIS-3.8 |
| SA-4(2)Design and Implementation Information for Controls | SASystem and Services Acquisition | ID.AM-03 | CIS-12.4, CIS-3.8 |
| SA-4(3)Development Methods, Techniques, and Practices | SASystem and Services Acquisition | PR.PS-06 | CIS-16, CIS-16.1, CIS-16.10, CIS-16.11, CIS-16.5 |
| SA-4(8)Continuous Monitoring Plan for Controls | SASystem and Services Acquisition | ID.IM-01, ID.IM-02 | CIS-16.2 |
| SA-4(12)Data Ownership | SASystem and Services Acquisition | ID.AM-08 | CIS-3.1 |
| SA-8Security and Privacy Engineering Principles | SASystem and Services Acquisition | PR.DS-10, PR.IR-01, PR.IR-03, PR.PS-05 | CIS-10.3, CIS-10.4, CIS-10.5, CIS-12.2, CIS-12.6, CIS-16, CIS-16.10, CIS-16.7, CIS-4.1, CIS-4.10, CIS-4.2, CIS-4.3, CIS-4.4, CIS-4.5, CIS-4.6, CIS-4.7, CIS-4.8 |
| SA-8(14)Least Privilege | SASystem and Services Acquisition | PR.AA-05, PR.DS-10 | CIS-5.4 |
| SA-8(30)Procedural Rigor | SASystem and Services Acquisition | GV.SC-09, ID.AM-08, PR.PS-02, PR.PS-03 | CIS-15.7 |
| SA-8(31)Secure System Modification | SASystem and Services Acquisition | ID.RA-07 | CIS-18.4 |
| SA-9External System Services | SASystem and Services Acquisition | GV.SC-06, GV.SC-07, ID.AM-04 | CIS-15.4, CIS-15.5 |
| SA-9(1)Risk Assessments and Organizational Approvals | SASystem and Services Acquisition | GV.SC-06, GV.SC-07, ID.IM-01, ID.IM-02, ID.RA-10 | CIS-15.5 |
| SA-9(3)Establish and Maintain Trust Relationship with Providers | SASystem and Services Acquisition | GV.OC-02, GV.OC-04, GV.OC-05, GV.RM-05, GV.RR-02, GV.SC-01, GV.SC-02, GV.SC-03, GV.SC-04, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-09, GV.SC-10, ID.AM-05, ID.RA-10 | CIS-15, CIS-15.2, CIS-15.3 |
| SA-10Developer Configuration Management | SASystem and Services Acquisition | ID.RA-09 | CIS-16.11 |
| SA-10(1)Software and Firmware Integrity Verification | SASystem and Services Acquisition | ID.RA-09 | CIS-16.11, CIS-16.5 |
| SA-11Developer Testing and Evaluation | SASystem and Services Acquisition | ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-06 | CIS-16.12, CIS-16.2, CIS-16.3 |
| SA-11(2)Threat Modeling and Vulnerability Analyses | SASystem and Services Acquisition | GV.OC-01, PR.PS-06 | CIS-16.14, CIS-16.2 |
| SA-11(5)Penetration Testing | SASystem and Services Acquisition | ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-06 | CIS-16.12, CIS-16.13, CIS-16.2, CIS-16.3, CIS-18, CIS-18.1, CIS-18.2, CIS-18.5 |
| SA-11(6)Attack Surface Reviews | SASystem and Services Acquisition | ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-02, PR.PS-06 | CIS-16.12, CIS-16.2, CIS-16.3 |
| SA-11(7)Verify Scope of Testing and Evaluation | SASystem and Services Acquisition | ID.IM-01, ID.IM-02, ID.RA-01, PR.PS-02, PR.PS-06 | CIS-16.12, CIS-16.2, CIS-16.3 |
| SA-15Development Process, Standards, and Tools | SASystem and Services Acquisition | PR.PS-06 | CIS-16, CIS-16.1, CIS-16.10, CIS-16.11, CIS-16.5 |
| SA-15(5)Attack Surface Reduction | SASystem and Services Acquisition | PR.DS-10, PR.IR-01, PR.IR-03, PR.PS-05 | CIS-10.3, CIS-10.4, CIS-10.5, CIS-12.2, CIS-12.6, CIS-16, CIS-16.10, CIS-16.7, CIS-4.1, CIS-4.10, CIS-4.2, CIS-4.3, CIS-4.4, CIS-4.5, CIS-4.6, CIS-4.7, CIS-4.8 |
| SA-15(8)Reuse of Threat and Vulnerability Information | SASystem and Services Acquisition | GV.OC-01, PR.PS-06 | CIS-16.14, CIS-16.2 |
| SA-22Unsupported System Components | SASystem and Services Acquisition | PR.PS-02, PR.PS-03 | CIS-2.2 |
| SA-23Specialization | SASystem and Services Acquisition | GV.SC-09, ID.RA-09, PR.PS-06 | CIS-15.7, CIS-16, CIS-16.11, CIS-16.7 |
| SC-1Policy and Procedures | SCSystem and Communications Protection | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03 | CIS-12, CIS-12.1, CIS-12.2, CIS-12.3, CIS-12.6, CIS-16, CIS-16.10 |
| SC-7(8)Route Traffic to Authenticated Proxy Servers | SCSystem and Communications Protection | DE.CM-03 | CIS-13.10, CIS-9, CIS-9.2, CIS-9.3 |
| SC-7(18)Fail Secure | SCSystem and Communications Protection | PR.IR-01, PR.IR-03 | CIS-12.2, CIS-12.6, CIS-16, CIS-16.10 |
| SC-8Transmission Confidentiality and Integrity | SCSystem and Communications Protection | PR.DS-02 | CIS-3.10 |
| SC-8(1)Cryptographic Protection | SCSystem and Communications Protection | PR.DS-01, PR.DS-02, PR.DS-10 | CIS-3.10, CIS-3.11, CIS-3.6, CIS-3.9 |
| SC-8(2)Pre- and Post-transmission Handling | SCSystem and Communications Protection | PR.DS-01, PR.DS-02, PR.DS-10 | CIS-3.10, CIS-3.11, CIS-3.6, CIS-3.9 |
| SC-13Cryptographic Protection | SCSystem and Communications Protection | PR.DS-01, PR.DS-02, PR.DS-10 | CIS-3.10, CIS-3.11, CIS-3.6, CIS-3.9 |
| SC-18(1)Identify Unacceptable Code and Take Corrective Actions | SCSystem and Communications Protection | ID.RA-08, PR.PS-02 | CIS-12.1, CIS-18.3, CIS-7, CIS-7.2, CIS-7.7 |
| SC-18(3)Prevent Downloading and Execution | SCSystem and Communications Protection | DE.CM-03 | CIS-13.10, CIS-9, CIS-9.2, CIS-9.3 |
| SC-28Protection of Information at Rest | SCSystem and Communications Protection | PR.DS-01 | CIS-10, CIS-10.3, CIS-10.4, CIS-10.5, CIS-11, CIS-3.11, CIS-3.6, CIS-3.9 |
| SC-28(1)Cryptographic Protection | SCSystem and Communications Protection | PR.DS-01, PR.DS-02 | CIS-11.3, CIS-3.11, CIS-3.6, CIS-3.9 |
| SC-28(2)Offline Storage | SCSystem and Communications Protection | PR.DS-11 | CIS-11.2 |
| SI-1Policy and Procedures | SISystem and Information Integrity | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03 | CIS-12.2, CIS-12.6, CIS-16, CIS-16.10 |
| SI-2Flaw Remediation | SISystem and Information Integrity | ID.RA-01, ID.RA-08, PR.PS-02 | CIS-10.2, CIS-12.1, CIS-18, CIS-18.3, CIS-7, CIS-7.1, CIS-7.3, CIS-7.4 |
| SI-2(4)Automated Patch Management Tools | SISystem and Information Integrity | PR.PS-02 | CIS-12.1, CIS-18.3, CIS-7.3, CIS-7.4 |
| SI-3Malicious Code Protection | SISystem and Information Integrity | DE.CM-09, ID.RA-01, ID.RA-08, PR.PS-02 | CIS-10, CIS-10.1, CIS-10.2, CIS-10.4, CIS-10.7, CIS-12.1, CIS-18, CIS-18.3, CIS-7, CIS-7.1, CIS-7.3, CIS-7.4 |
| SI-4System Monitoring | SISystem and Information Integrity | DE.AE-03, DE.AE-06, DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-04 | CIS-13, CIS-13.1, CIS-13.6, CIS-3.14, CIS-8, CIS-8.1, CIS-8.12, CIS-8.2, CIS-8.3, CIS-8.4, CIS-8.5, CIS-8.6, CIS-8.7, CIS-8.8, CIS-8.9 |
| SI-4(5)System-generated Alerts | SISystem and Information Integrity | DE.CM-01, PR.PS-04 | CIS-8.2 |
| SI-4(16)Correlate Monitoring Information | SISystem and Information Integrity | DE.AE-03, DE.AE-06 | CIS-13.6, CIS-3.14, CIS-8.12 |
| SI-7(6)Cryptographic Protection | SISystem and Information Integrity | PR.DS-01, PR.DS-02, PR.DS-10 | CIS-3.10, CIS-3.11, CIS-3.6, CIS-3.9 |
| SI-12Information Management and Retention | SISystem and Information Integrity | ID.AM-07 | CIS-3.1, CIS-3.4, CIS-3.5 |
| SI-12(3)Information Disposal | SISystem and Information Integrity | ID.AM-07 | CIS-3.5 |
| MP-1Policy and Procedures | MPMedia Protection | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, ID.AM-08, PR.DS-01, PR.DS-02, PR.DS-10 | CIS-11, CIS-11.3, CIS-3, CIS-3.1, CIS-3.3 |
| MP-2Media Access | MPMedia Protection | DE.CM-09 | CIS-10, CIS-3.1, CIS-3.3 |
| PM-4Plan of Action and Milestones Process | PMProgram Management | ID.IM-01, ID.IM-02, ID.RA-01, ID.RA-08, PR.PS-02 | CIS-7.2, CIS-7.7 |
| PM-5System Inventory | PMProgram Management | GV.SC-04, ID.AM-01, ID.AM-02, ID.AM-08 | CIS-1, CIS-1.1, CIS-2, CIS-2.1, CIS-2.2, CIS-2.4, CIS-6.6 |
| PM-7Enterprise Architecture | PMProgram Management | PR.IR-01, PR.IR-03 | CIS-12.2, CIS-16.10 |
| PM-8Critical Infrastructure Plan | PMProgram Management | GV.OC-03, GV.SC-05, GV.SC-08, ID.IM-04, PR.IR-02, PR.IR-03, RC.RP-02, RC.RP-04, RS.MA-05 | CIS-11, CIS-11.1 |
| PM-9Risk Management Strategy | PMProgram Management | GV.OV-02, GV.OV-03, GV.RM-01, GV.RM-02, GV.RM-03, GV.RM-04, GV.RM-06, GV.RR-01, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, ID.RA-04 | CIS-16.6 |
| PM-11Mission and Business Process Definition | PMProgram Management | ID.RA-04 | CIS-15.7 |
| PM-13Security and Privacy Workforce | PMProgram Management | GV.RM-05, GV.RR-02 | CIS-14, CIS-14.1 |
| PM-28Risk Framing | PMProgram Management | GV.OC-01, GV.RM-04, GV.RM-06, GV.RM-07, ID.RA-05, ID.RA-06 | CIS-16.6 |
| PM-29Risk Management Program Leadership Roles | PMProgram Management | GV.OV-02, GV.OV-03, GV.RM-01, GV.RM-03, GV.RM-04, GV.RM-05, GV.RM-06, GV.RR-01, GV.RR-02, GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10 | CIS-15.2, CIS-16.6 |
| PM-30Supply Chain Risk Management Strategy | PMProgram Management | GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10 | CIS-15.2 |
| PM-30(1)Suppliers of Critical or Mission-essential Items | PMProgram Management | GV.OC-04, GV.OC-05, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, ID.AM-05, ID.RA-10, PR.PS-06 | CIS-15.3, CIS-16.11, CIS-16.7 |
| PM-31Continuous Monitoring Strategy | PMProgram Management | DE.CM-01, DE.CM-03, DE.CM-06, DE.CM-09, PR.PS-04 | CIS-13, CIS-13.6, CIS-8, CIS-8.2 |
| PT-1Policy and Procedures | PTPII Processing and Transparency | GV.OC-03, GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, PR.IR-01, PR.IR-03 | CIS-12.2, CIS-12.6, CIS-16, CIS-16.10 |
| SR-1Policy and Procedures | SRSupply Chain Risk Management | GV.OV-01, GV.OV-02, GV.PO-01, GV.PO-02, GV.SC-01, GV.SC-03, GV.SC-04, GV.SC-06, GV.SC-07, GV.SC-08, GV.SC-10 | CIS-15, CIS-15.2 |
| SR-2Supply Chain Risk Management Plan | SRSupply Chain Risk Management | GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-06, GV.SC-07, GV.SC-09, GV.SC-10, ID.AM-04 | CIS-15.2 |
| SR-3(2)Limitation of Harm | SRSupply Chain Risk Management | GV.SC-06, GV.SC-07 | CIS-15.4 |
| SR-3(3)Sub-tier Flow Down | SRSupply Chain Risk Management | GV.OC-02, GV.OC-03, GV.SC-02, GV.SC-05, GV.SC-06, GV.SC-10 | CIS-15.4 |
| SR-6Supplier Assessments and Reviews | SRSupply Chain Risk Management | GV.SC-07, ID.IM-01, ID.IM-02 | CIS-15, CIS-15.6 |
| SR-6(1)Testing and Analysis | SRSupply Chain Risk Management | GV.SC-07, ID.IM-01, ID.IM-02 | CIS-15, CIS-15.6 |
| SR-7Supply Chain Operations Security | SRSupply Chain Risk Management | GV.SC-01, GV.SC-03, GV.SC-05, GV.SC-09, GV.SC-10 | CIS-15.2 |
Source and method
Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.
Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.
Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.
Related pairings
- NIST CSF 2.0 to NIST SP 800-53 Rev 5 control mapping233 shared controls
- SOC 2 Type II to NIST CSF 2.0 control mapping175 shared controls
- PCI DSS v4.0.1 to NIST CSF 2.0 control mapping166 shared controls
- NIST CSF 2.0 to NIST SP 800-171 Rev 2 control mapping100 shared controls
- ISO/IEC 27001:2022 (ISMS clauses) to NIST CSF 2.0 control mapping47 shared controls