ASOM-Fedv6.1Open the explorer
Obligations crosswalk

What This Framework Owes You, and What It Does Not.

A federal reader does not arrive holding a control id. They arrive holding an obligation — a Detect function they are thin on, an SP 800-53 control an assessor has queried, an RMF step with a date attached. This section answers from that direction, for 7 regimes, and is at least as specific about the parts it leaves alone.

7Regimes crosswalkedEach with what it does not cover stated first
223External identifiers inverted93 CSF citations and 130 SP 800-53 identifiers, read out of the catalog
93/106CSF 2.0 subcategories claimedThe other 13 are listed by identifier rather than left as a gap
26Stated boundariesThings this framework does not do, said out loud
How to Read It

A Crosswalk Is Only Worth Reading If It Can Say No.

The mappings themselves are cheap — they already sit in the published catalog. What is expensive, and what this section is for, is stating precisely how far each one goes.

Inverted, never restated

Every edge on this page is a mapping the control catalog already carries, turned round. Nothing is written down a second time, so a crosswalk and a control sheet cannot disagree.

A denominator, not a list

Coverage is stated against the regime’s own published set. “93 of 106 subcategories” is a claim a reader can check; “93 subcategories” is a boast.

Every regime states a boundary

There are 26 of them, and none of the seven regimes is allowed fewer than two. A crosswalk that claims full coverage of a regime it only partly touches is the fastest way to lose a federal reader.

Citations resolve or the build fails

Every control id, artifact and terrain layer named here is resolved against the real data when the site is built. A reference to something that does not exist is a red build, not a dead link.

At a Glance

7 regimes, 3 of them computed rather than authored.

Where a regime publishes an identifier scheme, the crosswalk is the catalog’s own mapping inverted. Where it does not — a statute, a program, a memorandum — the edges are authored, and the table says so rather than presenting the two as equally solid.

RegimeWhat the regime isWhat this framework reachesHow the crosswalk is computed
CSF 2.0National Institute of Standards and TechnologyOutcome index93 of 106 subcategories cited, carried by 78 of the 78 controls.Derived. Every edge is the inverse of a `csf` array in the published catalog; the denominator is the CSF 2.0 subcategory register below.
SP 800-53 Rev. 5National Institute of Standards and TechnologyControl catalog130 identifiers inherited from, carried by 78 of the 78 controls.Derived. Every edge is the inverse of an `inherits` array in the published catalog. Family names come from the provenance register, which the same catalog is checked against.
RMF · SP 800-37National Institute of Standards and TechnologyLifecycle7 of 7 lifecycle steps fed, carried by 37 of the 78 controls.Half derived. The artifacts feeding each RMF step are authored citations; where each artifact is produced, and which controls produce it, is read from the products index and the control chain.
CISA ZTMMCybersecurity and Infrastructure Security AgencyMaturity model5 of 5 pillars carried verbatim, carried by 75 of the 78 controls.Derived. Pillars, additions and the cross-cutting layer come from the terrain model’s own `origin` field; the justification for each addition is the layer’s own, read from the terrain reference.
FISMAUnited States statute · 44 U.S.C. ch. 35Statute8 of 8 obligations addressed, carried by 21 of the 78 controls.Authored edges, derived resolution. Each statutory program element cites control ids; the controls, their families and their accountable roles are read from the catalog.
TIC 3.0Cybersecurity and Infrastructure Security AgencyProgram4 of 4 obligations addressed, carried by 9 of the 78 controls.Authored edges, derived resolution. Each program element cites control ids and, where the ground is specific, the terrain layer it sits on.
OMB M-22-09Office of Management and Budget · 2022Policy5 of 5 obligations addressed, carried by 20 of the 78 controls.Authored edges, derived resolution. Each goal area cites a terrain layer and control ids; the sub-towers, their maturity ladders and the controls are read from the terrain reference and the catalog.

CSF 2.0

National Institute of Standards and Technology

What the regime is
Outcome index
What this framework reaches
93 of 106 subcategories cited, carried by 78 of the 78 controls.
How the crosswalk is computed
Derived. Every edge is the inverse of a `csf` array in the published catalog; the denominator is the CSF 2.0 subcategory register below.

SP 800-53 Rev. 5

National Institute of Standards and Technology

What the regime is
Control catalog
What this framework reaches
130 identifiers inherited from, carried by 78 of the 78 controls.
How the crosswalk is computed
Derived. Every edge is the inverse of an `inherits` array in the published catalog. Family names come from the provenance register, which the same catalog is checked against.

RMF · SP 800-37

National Institute of Standards and Technology

What the regime is
Lifecycle
What this framework reaches
7 of 7 lifecycle steps fed, carried by 37 of the 78 controls.
How the crosswalk is computed
Half derived. The artifacts feeding each RMF step are authored citations; where each artifact is produced, and which controls produce it, is read from the products index and the control chain.

CISA ZTMM

Cybersecurity and Infrastructure Security Agency

What the regime is
Maturity model
What this framework reaches
5 of 5 pillars carried verbatim, carried by 75 of the 78 controls.
How the crosswalk is computed
Derived. Pillars, additions and the cross-cutting layer come from the terrain model’s own `origin` field; the justification for each addition is the layer’s own, read from the terrain reference.

FISMA

United States statute · 44 U.S.C. ch. 35

What the regime is
Statute
What this framework reaches
8 of 8 obligations addressed, carried by 21 of the 78 controls.
How the crosswalk is computed
Authored edges, derived resolution. Each statutory program element cites control ids; the controls, their families and their accountable roles are read from the catalog.

TIC 3.0

Cybersecurity and Infrastructure Security Agency

What the regime is
Program
What this framework reaches
4 of 4 obligations addressed, carried by 9 of the 78 controls.
How the crosswalk is computed
Authored edges, derived resolution. Each program element cites control ids and, where the ground is specific, the terrain layer it sits on.

OMB M-22-09

Office of Management and Budget · 2022

What the regime is
Policy
What this framework reaches
5 of 5 obligations addressed, carried by 20 of the 78 controls.
How the crosswalk is computed
Authored edges, derived resolution. Each goal area cites a terrain layer and control ids; the sub-towers, their maturity ladders and the controls are read from the terrain reference and the catalog.
Regime by Regime

What Each One Gets, and Where It Stops.

The contributions below are specific on purpose. “Supports zero trust” is not a contribution; a rung on a maturity ladder with an observable attached is.

CSF 2.0
NIST Cybersecurity Framework 2.0Outcome index · National Institute of Standards and Technology

93 of 106subcategories cited78 of 78 controls13 subcategories are claimed by nothing in the catalog, and every one of them is listed.

The strongest crosswalk on this page and still a partial one: the catalog cites just over half the subcategory set, and the half it does not cite is listed by identifier rather than left as a gap the reader has to find.

Six functions, twenty-two categories and 106 subcategories, each stating an outcome rather than a mechanism. Its subcategory identifiers have become the shared index agencies and vendors describe security outcomes in.

What it does not do
  • Coverage of the Respond function.
  • Tiers and Profiles.
  • Any claim that a cited subcategory is satisfied.
  • Implementation Examples and Informative References.
SP 800-53 Rev. 5
Security and Privacy Controls for Information Systems and OrganizationsControl catalog · National Institute of Standards and Technology

130identifiers inherited from78 of 78 controlsAcross 20 of the 20 families — a small fraction of Rev. 5, and lineage rather than implementation.

Lineage, not compliance. Each control here names the 800-53 controls it derives from so a reviewer can see what is genuinely new and what is a re-framing — and so nobody mistakes the second for the first.

The federal control catalog, and the identifier scheme every federal security program is already expressed in. Twenty families, and a great many more controls and enhancements than any one framework draws on.

What it does not do
  • Baselines and tailoring.
  • Implementation of anything cited.
  • Coverage of the catalog.
  • Enhancement-level rigour beyond what is cited.
RMF · SP 800-37
Risk Management Framework for Information Systems and OrganizationsLifecycle · National Institute of Standards and Technology

7 of 7lifecycle steps fed37 of 78 controlsEvery step receives an artifact. Not one receives the document the step is graded on.

The framework feeds RMF and produces none of its artifacts. Every step below receives something; not one of them receives the document the step is actually graded on.

The seven-step lifecycle — prepare, categorize, select, implement, assess, authorize, monitor — that governs how a federal system is authorized to operate and kept under continuous monitoring.

What it does not do
  • The authorization package.
  • Security categorization.
  • Control selection and tailoring.
  • The reauthorization calendar.
CISA ZTMM
CISA Zero Trust Maturity ModelMaturity model · Cybersecurity and Infrastructure Security Agency

5 of 5pillars carried verbatim75 of 78 controls4 further layers are added, which is why a coverage number computed here is not a maturity stage.

The deepest inheritance in the framework and the one that most needs a boundary drawn round it. Five pillars are carried verbatim as terrain; four further layers are added, and an average taken across all nine is not a ZTMM score.

The federal zero-trust maturity model: five pillars, three cross-cutting capabilities, and four maturity stages from traditional to optimal.

What it does not do
  • A ZTMM assessment or submission.
  • The model’s per-pillar functions.
  • The pillar set as a complete map of a federal estate.
  • Comparability of the rollup.
FISMA
Federal Information Security Modernization ActStatute · United States statute · 44 U.S.C. ch. 35

8 of 8obligations addressed21 of 78 controlsEvery one of them carries a stated gap; none of them is claimed as satisfied.

The framework supplies substance against most of the statutory program elements and none of the reporting the statute is enforced through. Both halves of that sentence matter.

The statutory basis for federal information security programs: the elements an agency-wide program must contain, the annual independent evaluation, and the reporting that follows from both.

What it does not do
  • The FISMA metrics submission.
  • Incident reporting to CISA.
  • The independent evaluation.
  • Compliance as the objective.
TIC 3.0
Trusted Internet Connections 3.0Program · Cybersecurity and Infrastructure Security Agency

4 of 4obligations addressed9 of 78 controlsEvery one of them carries a stated gap; none of them is claimed as satisfied.

The framework borrows TIC’s boundary vocabulary and contributes nothing to its capability catalog. It draws the zones an agency already documents and then asks what can cross them.

The federal program that replaced a single physical internet gateway with trust zones and distributed policy enforcement, together with a capability catalog and a set of use cases.

What it does not do
  • A mapping to the TIC capability catalog.
  • Use case selection.
  • Telemetry to CISA.
OMB M-22-09
Moving the U.S. Government Toward Zero Trust Cybersecurity PrinciplesPolicy · Office of Management and Budget · 2022

5 of 5obligations addressed20 of 78 controlsEvery one of them carries a stated gap; none of them is claimed as satisfied.

The memorandum states end states; this framework states whether you are positioned to reach them. It produces no implementation plan and meets no deadline.

The federal zero-trust strategy memorandum: specific end states across identity, devices, networks, applications and data, with dates attached and an agency implementation plan required against them.

What it does not do
  • The agency implementation plan and budget submission.
  • The deadlines.
  • Enterprise procurement.
The Boundary That Covers All Seven

Three Things This Section Is Not.

Stated here as well as on each page, because the misreadings below are the ones that would cause an agency real damage, and they are the ones a crosswalk invites.

Lineage Is Not Compliance

A control that derives from IR-4 is not an implementation of IR-4. It asks a different question — where the thing sits, what can reach it, how fast the defense can act — and answering it well leaves the original obligation exactly where it was.

A Citation Is Not a Satisfaction

Naming a CSF subcategory says a control bears on that outcome. Whether the outcome is achieved is an assessment result, produced by the agency against its own estate, and no page here can produce it.

No Regime Here Is Fully Covered

Not one. The closest is the maturity model, whose five pillars are carried verbatim — and even there four further layers are added, which is exactly why a coverage figure computed under this framework is not a maturity stage.

Where each mapping comes from, what the framework takes from each source and what it deliberately declines to take, is set out in sources and provenance. The controls themselves, each with the full lineage on its own sheet, are in the reference manual.