Contribution: Standard Mapping to OpenCRE
I am contributing a mapping of selected controls from NIST SP 800-53 Rev.5 to existing CREs.
Scope
- Initial mapping of 7 controls
- Focused on development, configuration, cryptography, input validation, authentication, and auditing
Notes
- Mappings are based on semantic alignment between control intent and CRE definitions
- Some mappings (e.g., SI-10, IA-5) are partial where CRE scope is narrower or broader
- No new CREs were proposed in this batch
Attached
- Mapping spreadsheet (CSV format)
Looking forward to feedback and suggestions for improvement.
myopencre_mapping.xlsx