Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-04-2022 09:29 AM
Sounds like an incredible amount of effort. Don't know whether you're using ISO27002, or NIST 800-53, but each has over a 1,000 controls each.
Not as detailed as you're considering, but NIST 800-53B (Chapter 3 - Control Baselines), has all their Controls listed by Family, both Base and Enhancements, with an overall indicator of Low, Medium, and High. But the indicator is an aggregate of CIA, not broken out individually by C, I, and A.