Mapping Relationships Between Documentary Standards, Regulations, Frameworks, and Guidelines
Karen A. Scarfone, Murugiah Souppaya, Michael E. Fagan · 2023
This document describes an approach that NIST would use and other parties could use for mapping the elements of documentary standards, regulations, frameworks, and guidelines to NIST publications, such as CSF Subcategories or SP 800-53r5 controls. NIST intends for this approach to be used for future mappings involving NIST cybersecurity and privacy publications that will be submitted via the NIST National Online Informative References (OLIR) process for hosting on NIST’s online Cybersecurity and Privacy Reference Tool (CPRT). By following this approach, NIST and others in the cybersecurity and privacy standards community can jointly establish a single concept system over time that links cybersecurity and privacy concepts from many sources into a cohesive, consistent set of relationship mappings within the NIST CPRT. The approach is informed by concept system and terminology standards, as well as experience with what information the cybersecurity and privacy community would find most valuable.