redteam-project / sckg

Security Control Knowledge Graph
GNU General Public License v3.0
39 stars 16 forks source link

CMMC #19

Open trevorbryant opened 4 years ago

trevorbryant commented 4 years ago

I've extracted the controls in CMMC v1.02 for usability. We'll figure out what needs to be correlated from CMMC <> 800-171 <> 800-53.

https://github.com/trevorbryant/cmmc-controls

jason-callaway commented 4 years ago

Thanks, Trevor!

How are these mapped to 800-171 or 800-53 controls? I assume the "practice number" column is the unique identifier for each CMMC control?

jason-callaway commented 4 years ago

Also, could you please PR this into this repo's data/regimes directory?

trevorbryant commented 4 years ago

How are these mapped to 800-171 or 800-53 controls? I assume the "practice number" column is the unique identifier for each CMMC control?

Yes, the practice number is the unique control identifier for CMMC.

I haven't yet taken the time to map the CMMC controls to 800-53. I don't anticipate it being a level of effort considering CMMC is focused on 800-171, which derives from 800-53.

We'll see.