Skip to main content
All answers

How do CIS benchmarks map to NIST 800-53?

CISGuard maps CIS benchmark results to 50 NIST 800-53 Rev. 5 controls. Primary coverage spans Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), System and Communications Protection (SC), and System and Information Integrity (SI). CISGuard tags each CIS control with its corresponding NIST 800-53 control IDs for one-scan multi-framework reporting.

The longer answer.

The 50 mapped controls sit in 13 of the 20 NIST 800-53 control families. Most coverage is in Access Control (9 controls), Audit and Accountability (7), System and Communications Protection (7), Configuration Management (6), Identification and Authentication (6) and System and Information Integrity (5), with smaller coverage in Media Protection, Contingency Planning, Incident Response, Risk Assessment, Assessment and Monitoring, Physical and Environmental Protection, and System and Services Acquisition.

Families that are mostly organizational, such as Planning, Program Management and Personnel Security, cannot be evidenced by a configuration scan and are not mapped. The NIST 800-53 Framework Coverage Report shows each mapped control with its pass or fail status and drills down to the CIS checks and assets behind it.

More questions on Framework Mapping?

Our compliance engineers can show you exactly how CISGuard handles Framework Mapping in a briefing scoped to your environment.