15 mapped controls · identifier-only informative references · Identify function · one implementation can answer several obligations at once.
| NIST SP 800-53 Rev. 5 | Relationship | Source tier |
|---|---|---|
| CM-09 | related | Tier A |
| CM-13 | related | Tier A |
| MA-02 | related | Tier A |
| MA-06 | related | Tier A |
| PL-02 | related | Tier A |
| PM-22 | related | Tier A |
| PM-23 | related | Tier A |
| SA-03 | related | Tier A |
| SA-04 | related | Tier A |
| SA-08 | related | Tier A |
| SA-22 | related | Tier A |
| SI-12 | related | Tier A |
| SI-18 | related | Tier A |
| SR-05 | related | Tier A |
| SR-12 | related | Tier A |
Assessors working from either framework ask for the same thing against ID.AM-08: inventory and assessment artifacts - asset and data registers with owners and dates, risk assessment output, vendor and dependency lists, and the criticality ratings that justify scope decisions. NIST SP 800-53 is the control catalog sitting underneath CSF, so this mapping is NIST-to-NIST: the most direct of the three, and both sides are US Government publications in the public domain. Keeping one dated evidence register per control means a single artifact answers both frameworks instead of being produced twice.
Bayou Bytes