NIST SP 800-172CIS Controls v8

NIST SP 800-172 covers 20.9% of CIS Controls v8

32 of the 153 controls in CIS Controls v8 are already satisfied by evidence you collected for NIST SP 800-172. 121 are genuine gaps. Every claim below was judged against both control sets and then argued against; the ones that did not survive are published further down with the reason each failed.

20.9%
of the target already covered
32
controls evidenced
121
genuine gaps
8
claims rejected in review

This number is directional. It says how much of CIS Controls v8 your NIST SP 800-172 evidence satisfies. The reverse pair is a different number, often very different, because a security standard has enormous depth for access control and almost none for lawful basis or data subject rights.

73 candidate mappings were examined and 8 were removed. Signed off 2026-08-19, review level machine verified. Mappings were judged by Claude Code rather than read line by line by a practitioner. Every claim shows its reasoning so you can check it. Ask and a practitioner will review this pair.

Where the gaps are

Coverage is never evenly spread. A source standard usually satisfies one part of a target almost completely and barely touches another, and which part is which is the thing worth knowing before you plan the work.

CIS Control 2: Inventory and Control of Software Assets5 of 7 evidenced, 2 to do
CIS Control 1: Inventory and Control of Enterprise Assets3 of 5 evidenced, 2 to do
CIS Control 18: Penetration Testing3 of 5 evidenced, 2 to do
CIS Control 14: Security Awareness and Skills Training4 of 9 evidenced, 5 to do
CIS Control 17: Incident Response Management4 of 9 evidenced, 5 to do
CIS Control 15: Service Provider Management3 of 7 evidenced, 4 to do
CIS Control 13: Network Monitoring and Defense4 of 11 evidenced, 7 to do
CIS Control 5: Account Management1 of 6 evidenced, 5 to do
CIS Control 16: Application Software Security2 of 14 evidenced, 12 to do
CIS Control 3: Data Protection2 of 14 evidenced, 12 to do
CIS Control 12: Network Infrastructure Management1 of 8 evidenced, 7 to do
CIS Control 10: Malware Defenses0 of 7 evidenced, 7 to do
CIS Control 11: Data Recovery0 of 5 evidenced, 5 to do
CIS Control 4: Secure Configuration of Enterprise Assets and Software0 of 12 evidenced, 12 to do
CIS Control 6: Access Control Management0 of 8 evidenced, 8 to do
CIS Control 7: Continuous Vulnerability Management0 of 7 evidenced, 7 to do
CIS Control 8: Audit Log Management0 of 12 evidenced, 12 to do
CIS Control 9: Email and Web Browser Protections0 of 7 evidenced, 7 to do

Theme level, not control level, deliberately. The per-control list of what is evidenced and what is a gap is the report itself, so publishing it here would be publishing the thing being sold.

Claims that held

A sample. Each one names the control whose evidence does the work, the control it satisfies, and why.

3.4.3eCIS-1.1argued against and upheld
Establish and Maintain Detailed Enterprise Asset Inventory

Automated tools maintaining an up to date, complete and accurate component inventory is this safeguard.

3.4.2eCIS-1.2argued against and upheld
Address Unauthorized Assets

Automated detection of unauthorized components then removal or quarantine addresses unauthorized assets.

3.4.3eCIS-1.3argued against and upheld
Utilize an Active Discovery Tool

Automated discovery tools identifying connected components is an active discovery capability.

3.5.1eCIS-12.6argued against and upheld
Use of Secure Network Management and Communication Protocols

Bidirectional cryptographic replay resistant authentication before connection is the secure protocol this safeguard names.

3.14.2eCIS-13.2argued against and upheld
Deploy a Host-Based Intrusion Detection Solution

Advanced detection capabilities monitoring components for anomalous behaviour is host based intrusion detection.

3.14.2eCIS-13.3argued against and upheld
Deploy a Network Intrusion Detection Solution

Ongoing monitoring of systems with specialized detection capabilities is network intrusion detection.

3.1.3eCIS-13.4argued against and upheld
Perform Traffic Filtering Between Network Segments

Secure transfer solutions enforce what may cross between network segments.

3.5.1eCIS-13.9argued against and upheld
Deploy Port-Level Access Control

Authenticating a device cryptographically before the network connection is established is port level access control.

Claims that did not hold

8 proposed mappings for this pair were rejected. They are kept in the graph rather than deleted, so what was thrown out is as inspectable as what survived. A crosswalk that never rejects anything is not being judged.

3.13.1eCIS-12.2
Establish and Maintain a Secure Network Architecture

control identity corrected 2026-08-19: issued 3.13.1e is component diversity to limit malicious code propagation; these mappings are boundary protection and segmentation, judged against 3.1.3e's content which this control was wrongly carrying

Claimed at high confidence before it was rejected.

3.13.1eCIS-13.4
Perform Traffic Filtering Between Network Segments

control identity corrected 2026-08-19: issued 3.13.1e is component diversity to limit malicious code propagation; these mappings are boundary protection and segmentation, judged against 3.1.3e's content which this control was wrongly carrying

Claimed at high confidence before it was rejected.

3.13.2eCIS-16.10
Apply Secure Design Principles in Application Architectures

control identity corrected 2026-08-19: issued 3.13.2e is introducing unpredictability into operations; these mappings are least privilege and secure engineering, a subject that appears nowhere in the issued 800-172

Claimed at high confidence before it was rejected.

3.14.3eCIS-16.5
Use Up-to-Date and Trusted Third-Party Software Components

control identity corrected 2026-08-19: issued 3.14.3e is scope inclusion or segregation into purpose-specific networks; these mappings are supply chain provenance, a subject absent from the issued 800-172

Claimed at high confidence before it was rejected.

3.13.1eCIS-3.12
Segment Data Processing and Storage Based on Sensitivity

control identity corrected 2026-08-19: issued 3.13.1e is component diversity to limit malicious code propagation; these mappings are boundary protection and segmentation, judged against 3.1.3e's content which this control was wrongly carrying

Claimed at high confidence before it was rejected.

3.5.3eCIS-6.3
Require MFA for Externally-Exposed Applications

corrected 2026-08-19: judged from a title claiming multifactor authentication, while the control carried 3.5.2e password-management text. Issued 800-172 3.5.3e is comply-to-connect: prohibit connection of unknown or unverified components. Authentication evidence does not satisfy it.

Claimed at high confidence before it was rejected.

3.5.3eCIS-6.4
Require MFA for Remote Network Access

corrected 2026-08-19: judged from a title claiming multifactor authentication, while the control carried 3.5.2e password-management text. Issued 800-172 3.5.3e is comply-to-connect: prohibit connection of unknown or unverified components. Authentication evidence does not satisfy it.

Claimed at high confidence before it was rejected.

3.5.3eCIS-6.5
Require MFA for Administrative Access

corrected 2026-08-19: judged from a title claiming multifactor authentication, while the control carried 3.5.2e password-management text. Issued 800-172 3.5.3e is comply-to-connect: prohibit connection of unknown or unverified components. Authentication evidence does not satisfy it.

Claimed at high confidence before it was rejected.

The full report

Everything above is a sample. The report is every evidenced control and every gap, with the reasoning and the source document behind each one, in a form you can hand to an assessor. $299, emailed immediately.

Buy this crosswalk