NIST 800-53 r5 — cumulative coverage
Our cross-walks give NIST 800-53 r5 at least partial inbound coverage on 7.1% of its 324 base controls, mostly or better on 0.3%. Each control's verdict is the strongest single inbound mapping; the bar shows the spread and the row shows how many sources (and from which frameworks) contribute. Authoritative mappings only.
Methodology update (2026-07-25). A policy control that mandates a technical control is
no longer counted as partial coverage of it: a policy analyzes and blocks nothing, so it
provides none of that control's protective effect. Those cross-layer links are re-authored as a
distinct governs / implements governance relation, off the coverage scale. Coverage numbers for
policy-heavy families drop accordingly — the honest correction, not a regression. Explore both on
the framework map (governance toggle).
Configuration Management 3/14 · 21.4% ≥partial · 7.1% ≥mostly
Access Control 1/25 · 4.0% ≥partial · 0.0% ≥mostly
Awareness and Training 0/6 · 0.0% ≥partial · 0.0% ≥mostly
Audit and Accountability 3/16 · 18.8% ≥partial · 0.0% ≥mostly
Assessment, Authorization, and Monitoring 0/9 · 0.0% ≥partial · 0.0% ≥mostly
Contingency Planning 0/13 · 0.0% ≥partial · 0.0% ≥mostly
Identification and Authentication 2/13 · 15.4% ≥partial · 0.0% ≥mostly
Incident Response 0/10 · 0.0% ≥partial · 0.0% ≥mostly
Maintenance 0/7 · 0.0% ≥partial · 0.0% ≥mostly
Media Protection 0/8 · 0.0% ≥partial · 0.0% ≥mostly
Physical and Environmental Protection 0/23 · 0.0% ≥partial · 0.0% ≥mostly
Planning 1/11 · 9.1% ≥partial · 0.0% ≥mostly
Program Management 0/32 · 0.0% ≥partial · 0.0% ≥mostly
Personnel Security 0/9 · 0.0% ≥partial · 0.0% ≥mostly
Personally Identifiable Information Processing and Transparency 0/8 · 0.0% ≥partial · 0.0% ≥mostly
Risk Assessment 0/10 · 0.0% ≥partial · 0.0% ≥mostly
System and Services Acquisition 6/24 · 25.0% ≥partial · 0.0% ≥mostly
System and Communications Protection 1/51 · 2.0% ≥partial · 0.0% ≥mostly
System and Information Integrity 4/23 · 17.4% ≥partial · 0.0% ≥mostly
Supply Chain Risk Management 2/12 · 16.7% ≥partial · 0.0% ≥mostly
"Cumulative" here means breadth of corroboration, not summed coverage: overlapping partial mappings are NOT added up into "full". The headline per control is the best-attested single mapping, shown alongside the count and source frameworks behind it.