Skip to content

feat: add NIST AI Risk Management Framework (AI RMF) 1.0 SP 800-53 Rev 5 mappings - #15

Open
felipechalegre-spec wants to merge 3 commits into
opensecurityarchitecture:mainfrom
felipechalegre-spec:feat/nist-ai-rmf
Open

feat: add NIST AI Risk Management Framework (AI RMF) 1.0 SP 800-53 Rev 5 mappings#15
felipechalegre-spec wants to merge 3 commits into
opensecurityarchitecture:mainfrom
felipechalegre-spec:feat/nist-ai-rmf

Conversation

@felipechalegre-spec

Copy link
Copy Markdown

Summary

Adds SP 800-53 Rev 5 cross-reference mappings for the NIST AI Risk Management Framework (AI RMF) 1.0.

NIST AI RMF 1.0 — AI Risk Management Framework

  • 49 subcategories across 3 functions: GOVERN (19), MAP (17), MANAGE (13)
  • Functions cover the full AI risk lifecycle: governance policies, context mapping, impact assessment, risk treatment, monitoring, and continual improvement
  • Mappings derived from NIST cross-reference publications linking AI RMF subcategories to SP 800-53 Rev 5 controls
  • Average SP 800-53 coverage: 59.4% (lower than ISO standards by design — AI-specific controls like team diversity, human-AI configuration, and societal impact assessment have no direct SP 800-53 equivalent)

Coverage by function

Function Subcategories Avg Coverage
GOVERN 19 ~58%
MAP 17 ~55%
MANAGE 13 ~64%

Key SP 800-53 families mapped

  • PM-* (Program Management) — GOVERN policies and accountability
  • RA-* (Risk Assessment) — MAP risk identification and measurement
  • CA-* (Assessment & Authorization) — MANAGE monitoring and improvement
  • IR-* (Incident Response) — MANAGE incident documentation
  • SA-* (System & Services Acquisition) — third-party AI system management
  • AT-* (Awareness & Training) — team training and awareness

Format

Follows the existing framework-coverage.schema.json schema with id, title, controls[], coverage_pct, rationale, and gaps per clause, plus a summary block.

Source

Mappings derived from NIST cross-reference publications and the NIST AI RMF Playbook (https://airc.nist.gov/Docs/1). The NIST AI RMF does not have a direct NIST-published SP 800-53 crosswalk for all subcategories; mappings are based on functional alignment between the frameworks.

Context

This PR was requested in the context of upstream-first framework architecture — mapping content originally drafted for a downstream consumer is being contributed to OSA so the community benefits and downstream consumers can import via the standard sync path.

Related PR (ISO 27017/27018): #14

@sonarqubecloud

sonarqubecloud Bot commented Jun 3, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant