feat: add NIST AI Risk Management Framework (AI RMF) 1.0 SP 800-53 Rev 5 mappings - #15
Open
felipechalegre-spec wants to merge 3 commits into
Open
Conversation
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Adds SP 800-53 Rev 5 cross-reference mappings for the NIST AI Risk Management Framework (AI RMF) 1.0.
NIST AI RMF 1.0 — AI Risk Management Framework
Coverage by function
Key SP 800-53 families mapped
Format
Follows the existing
framework-coverage.schema.jsonschema withid,title,controls[],coverage_pct,rationale, andgapsper clause, plus asummaryblock.Source
Mappings derived from NIST cross-reference publications and the NIST AI RMF Playbook (https://airc.nist.gov/Docs/1). The NIST AI RMF does not have a direct NIST-published SP 800-53 crosswalk for all subcategories; mappings are based on functional alignment between the frameworks.
Context
This PR was requested in the context of upstream-first framework architecture — mapping content originally drafted for a downstream consumer is being contributed to OSA so the community benefits and downstream consumers can import via the standard sync path.
Related PR (ISO 27017/27018): #14