Skip to content

DORANIST 800-171 crosswalk

A control-by-control mapping between Digital Operational Resilience Act (EU 2022/2554) and NIST SP 800-171 Rev. 2. 6 mappings.

DORANIST 800-171RelationshipNotes
Art. 10
Detection
3.3.1
Create and retain audit logs
PartialCurated
Logging, monitoring & detection
Art. 17
ICT-related incident management process
3.6.1
Establish an incident-handling capability
PartialCurated
Incident response & breach notification
Art. 19
Reporting of major ICT-related incidents
3.6.1
Establish an incident-handling capability
PartialCurated
Incident response & breach notification
Art. 6
ICT risk management framework
3.11.1
Periodically assess risk
RelatedCurated
Risk assessment & management
Art. 9
Protection and prevention
3.1.1
Limit system access to authorized users
PartialCurated
Access control & identity
Art. 9
Protection and prevention
3.13.11
Employ FIPS-validated cryptography
PartialCurated
Cryptography & data protection

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.