Cross-Framework Mappings

Every mapping in this explorer carries a source, a mapping type, and a confidence level — a mapping is never shown as authoritative unless it actually is. Where no sourced crosswalk exists, that's stated plainly instead of guessed at.

Populated

SP 800-82r3 OT/ICS Overlay

Baseline tailoring for 228 controls, diffed against the standard SP 800-53 baselines.

AUTHORITATIVE
Source
NIST SP 800-82r3, Appendix F, Table 22
Mapping type
Authoritative
Confidence
High
Version
SP 800-82 Rev. 3
View the overlay →

Not Yet Populated

The data model (FrameworkMapping in src/lib/security-controls/types.ts) is ready to receive these, versioned with source/mapping-type/confidence/last-updated metadata per entry — but nothing is shown for them until real crosswalk data is sourced and loaded.

NIST Cybersecurity Framework (CSF)

No sourced NIST 800-53-to-CSF crosswalk data is loaded.

CIS Controls

No sourced CIS Controls crosswalk data is loaded.

ISO/IEC 27001

No sourced ISO 27001 Annex A crosswalk data is loaded.

CMMC

No sourced CMMC level/practice mapping data is loaded.

FedRAMP

No sourced FedRAMP baseline delta data is loaded (distinct from the standard SP 800-53 baselines already shown per control).

DISA STIG / CCI

See the dedicated STIGs page — no STIG/CCI dataset is loaded.

ACSC Information Security Manual (ISM)

This site has a separate ISM Explorer with real ISM data, but no control-to-control NIST↔ISM crosswalk is loaded yet.