Cyber Resilience

NIST 800-53 r5 — cumulative coverage

Our cross-walks give NIST 800-53 r5 at least partial inbound coverage on 7.1% of its 324 base controls, mostly or better on 0.3%. Each control's verdict is the strongest single inbound mapping; the bar shows the spread and the row shows how many sources (and from which frameworks) contribute. Authoritative mappings only.

← All cross-walks

Methodology update (2026-07-25). A policy control that mandates a technical control is no longer counted as partial coverage of it: a policy analyzes and blocks nothing, so it provides none of that control's protective effect. Those cross-layer links are re-authored as a distinct governs / implements governance relation, off the coverage scale. Coverage numbers for policy-heavy families drop accordingly — the honest correction, not a regression. Explore both on the framework map (governance toggle).
Configuration Management
3/14 · 21.4% ≥partial · 7.1% ≥mostly
CM-6Configuration SettingsMostly1 src · OWASP Web Top 10 (2025) 1
CM-14Signed ComponentsPartial1 src · OWASP Web Top 10 (2025) 1
CM-3Configuration Change ControlPartial1 src · OWASP Web Top 10 (2025) 1
Access Control
1/25 · 4.0% ≥partial · 0.0% ≥mostly
AC-24Access Control DecisionsPartial1 src · OWASP Web Top 10 (2025) 1
AC-3.3Mandatory Access ControlPartial1 src · OWASP Web Top 10 (2025) 1
Awareness and Training
0/6 · 0.0% ≥partial · 0.0% ≥mostly
Audit and Accountability
3/16 · 18.8% ≥partial · 0.0% ≥mostly
AU-12Audit Record GenerationPartial1 src · OWASP Web Top 10 (2025) 1
AU-2Event LoggingPartial1 src · OWASP Web Top 10 (2025) 1
AU-5Response to Audit Logging Process FailuresPartial1 src · OWASP Web Top 10 (2025) 1
Assessment, Authorization, and Monitoring
0/9 · 0.0% ≥partial · 0.0% ≥mostly
Contingency Planning
0/13 · 0.0% ≥partial · 0.0% ≥mostly
Identification and Authentication
2/13 · 15.4% ≥partial · 0.0% ≥mostly
IA-13Identity Providers and Authorization ServersPartial2 src · OWASP Web Top 10 (2025) 2
IA-5Authenticator ManagementPartial1 src · OWASP Web Top 10 (2025) 1
IA-5.1Password-based AuthenticationPartial1 src · OWASP Web Top 10 (2025) 1
IA-5.2Public Key-based AuthenticationPartial1 src · OWASP Web Top 10 (2025) 1
Incident Response
0/10 · 0.0% ≥partial · 0.0% ≥mostly
Maintenance
0/7 · 0.0% ≥partial · 0.0% ≥mostly
Media Protection
0/8 · 0.0% ≥partial · 0.0% ≥mostly
Physical and Environmental Protection
0/23 · 0.0% ≥partial · 0.0% ≥mostly
Planning
1/11 · 9.1% ≥partial · 0.0% ≥mostly
PL-8Security and Privacy ArchitecturesPartial1 src · OWASP Web Top 10 (2025) 1
Program Management
0/32 · 0.0% ≥partial · 0.0% ≥mostly
Personnel Security
0/9 · 0.0% ≥partial · 0.0% ≥mostly
Personally Identifiable Information Processing and Transparency
0/8 · 0.0% ≥partial · 0.0% ≥mostly
Risk Assessment
0/10 · 0.0% ≥partial · 0.0% ≥mostly
System and Services Acquisition
6/24 · 25.0% ≥partial · 0.0% ≥mostly
SA-17Developer Security and Privacy Architecture and DesignPartial2 src · OWASP Web Top 10 (2025) 2
SA-8Security and Privacy Engineering PrinciplesPartial2 src · OWASP Web Top 10 (2025) 2
SA-22Unsupported System ComponentsPartial1 src · OWASP Web Top 10 (2025) 1
SA-24Design For Cyber ResiliencyPartial1 src · OWASP Web Top 10 (2025) 1
SA-3System Development Life CyclePartial1 src · OWASP Web Top 10 (2025) 1
SA-4Acquisition ProcessPartial1 src · OWASP Web Top 10 (2025) 1
System and Communications Protection
1/51 · 2.0% ≥partial · 0.0% ≥mostly
SC-12Cryptographic Key Establishment and ManagementPartial1 src · OWASP Web Top 10 (2025) 1
System and Information Integrity
4/23 · 17.4% ≥partial · 0.0% ≥mostly
SI-2Flaw RemediationPartial3 src · OWASP Web Top 10 (2025) 3
SI-11Error HandlingPartial1 src · OWASP Web Top 10 (2025) 1
SI-3Malicious Code ProtectionPartial1 src · OWASP Web Top 10 (2025) 1
SI-7Software, Firmware, and Information IntegrityPartial1 src · OWASP Web Top 10 (2025) 1
Supply Chain Risk Management
2/12 · 16.7% ≥partial · 0.0% ≥mostly
SR-11Component AuthenticityPartial1 src · OWASP Web Top 10 (2025) 1
SR-3Supply Chain Controls and ProcessesPartial1 src · OWASP Web Top 10 (2025) 1

"Cumulative" here means breadth of corroboration, not summed coverage: overlapping partial mappings are NOT added up into "full". The headline per control is the best-attested single mapping, shown alongside the count and source frameworks behind it.