14 mapped controls · identifier-only informative references · Protect function · one implementation can answer several obligations at once.
| NIST SP 800-53 Rev. 5 | Relationship | Source tier |
|---|---|---|
| AU-16 | related | Tier A |
| CA-03 | related | Tier A |
| SC-04 | related | Tier A |
| SC-07 | related | Tier A |
| SC-08 | related | Tier A |
| SC-11 | related | Tier A |
| SC-12 | related | Tier A |
| SC-13 | related | Tier A |
| SC-16 | related | Tier A |
| SC-40 | related | Tier A |
| SC-43 | related | Tier A |
| SI-03 | related | Tier A |
| SI-04 | related | Tier A |
| SI-07 | related | Tier A |
Assessors working from either framework ask for the same thing against PR.DS-02: implementation artifacts - configuration exports or baseline snapshots, access-control records showing who approved which grant, change tickets tied to the control, and training completion records. NIST SP 800-53 is the control catalog sitting underneath CSF, so this mapping is NIST-to-NIST: the most direct of the three, and both sides are US Government publications in the public domain. Keeping one dated evidence register per control means a single artifact answers both frameworks instead of being produced twice.
Bayou Bytes