CONTROLSPEC · RELEASE 0.19.0 · PUBLIC GOVERNMENT SOURCES · NOTHING TO SUBMIT

CISA CPG 2.0 coverage

Which performance goals have a query you can run.

The packs here are written against NIST SP 800-53, which most small operators are never measured against. CISA's Cross-Sector Cybersecurity Performance Goals are the federal baseline written for them. This page maps one to the other — including everywhere the mapping does not reach.

A pack is not compliance

Running a pack finds a condition. Closing it is your work, and the goal may ask for more than any query can see. Nothing on this page should be presented to an auditor, a regulator, or a grant reviewer as evidence of conformance with the CPGs. The mapping exists so that somebody who knows the CPG vocabulary can find a starting point, not so that a box can be ticked.

Coverage

All 34 goals

Grouped by the NIST CSF 2.0 function CPG 2.0 organises them under. A goal marked out of scope asks for a policy, a plan, or a person — not a system condition — so no query can answer it, and it is not counted as a gap.

Method

How these mappings were made