Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

NIST 800-53 - more granular mapping on control enhancement level #589

Open
balage-n opened this issue Mar 5, 2025 · 0 comments
Open

NIST 800-53 - more granular mapping on control enhancement level #589

balage-n opened this issue Mar 5, 2025 · 0 comments

Comments

@balage-n
Copy link

balage-n commented Mar 5, 2025

Regarding NIST 800-53 in OpenCRE I noticed that the mapping is created only on the control level so it does not include control enhancements e.g., AC-2 is linked to 724-770 but AC-2(5) "Inactivity logout" is not linked to any other though it could be linked to 065-782 "Ensure session timeout (soft/hard)".
Is there a plan to create a NIST 800-53 mapping at this level in the future, or would you be open to contributions regarding this granularity? I mean it's surely more maintenance and in general mapping at the right abstraction layer between different frameworks is not a trivial question but I think it would make sense to match up sub-controls/control enhancements this way due to the fact that NIST 800-53 is a widely used framework.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant