MITRE DEFEND mapping to NIST 800-53 rev 5 #203
Replies: 3 comments 1 reply
-
It is important to use this mapping with care. The mapping of a control enhancement like AC-02(1) without the basic control AC-02 makes no sense in the context of a system since AC-02(1) cannot be implemented without implementing first AC-02. A very large number of 800-53 controls listed in this mapping are enhancements. All latest 800-53 rev 5.1.1 controls can be found here, presented in a human-friendly format So to implement AC-02(1) that reads: SP 800-53 Control Enhancement Control Statement Discussion: you will need first AC-02: ACCOUNT MANAGEMENT ~ ~ ~ Control Statement |
Beta Was this translation helpful? Give feedback.
-
In my humble opinion and per my past experience, this kind of mapping can only be done at the implementation layer (per CSP technology/implementation). And Peter and I discussed it in the past outside of this effort. Fancy meeting you her, Peter :) |
Beta Was this translation helpful? Give feedback.
-
@mlysaght2017 - are we okay to close this out? |
Beta Was this translation helpful? Give feedback.
-
@jared-lambert @eddie-knight @robmoffat - another mitre-nist mapping:
https://d3fend.mitre.org/mappings/nist/5/
Beta Was this translation helpful? Give feedback.
All reactions