{
  "canonicalClaimUrl": "https://xn--mwe.com/questions/does-a-control-mapping-prove-compliance/#clm-k05-q-002",
  "claimStatus": "PROJECT DOCTRINE",
  "correctionStatus": "CURRENT K05 RECORD",
  "id": "CLM-K05-Q-002",
  "lastReviewed": "2026-08-15",
  "machineRecordUrl": "https://xn--mwe.com/data/claims/clm-k05-q-002.json",
  "name": "Does a control mapping prove compliance?",
  "ownerAnchor": "clm-k05-q-002",
  "ownerId": "K05-Q-002",
  "ownerRoute": "/questions/does-a-control-mapping-prove-compliance/",
  "ownerType": "question",
  "proposition": "No. A mapping shows a documented relationship between a control and a source requirement or guidance element. Compliance requires the applicable authority, current text, facility scope, implemented control, operating evidence, exceptions, and an authorized determination.",
  "qualification": "The answer is bounded by the cited source status, facility applicability, competent authority, and the distinction between architecture, testing, deployment, and operation.",
  "releaseId": "K12-2026-08-16",
  "releaseVersion": "2.1.0",
  "researchCutoff": "2026-08-15",
  "scope": "K05 direct answer for Does a control mapping prove compliance?",
  "slug": "clm-k05-q-002",
  "sourceIds": [
    "SRC-NIST-800-82R3",
    "SRC-NIST-800-207",
    "SRC-NRC-10CFR-73-SUBPART-J-2026",
    "SRC-NERC-CIP-CATALOG-2026"
  ],
  "sourceSections": [
    {
      "section": "Abstract",
      "sourceId": "SRC-NIST-800-82R3",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The guide addresses OT security, threats, vulnerabilities, topologies, and countermeasures while recognizing unique performance, reliability, and safety needs.",
      "url": "https://csrc.nist.gov/pubs/sp/800/82/r3/final"
    },
    {
      "section": "Abstract",
      "sourceId": "SRC-NIST-800-207",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "Zero trust shifts protection away from static network perimeters, assumes no implicit trust by location or ownership, and requires discrete authentication and authorization.",
      "url": "https://csrc.nist.gov/pubs/sp/800/207/final"
    },
    {
      "section": "73.100",
      "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "Technology-inclusive physical-protection requirements are available for qualifying Part 53 licensees that elect the section.",
      "url": "https://www.ecfr.gov/current/title-10/chapter-I/part-73/section-73.100"
    },
    {
      "section": "73.110",
      "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "Technology-inclusive protection requirements address covered digital computer and communication systems and networks.",
      "url": "https://www.ecfr.gov/current/title-10/chapter-I/part-73/section-73.110"
    },
    {
      "section": "73.120",
      "sourceId": "SRC-NRC-10CFR-73-SUBPART-J-2026",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "The Subpart J framework includes an access-authorization program for covered commercial nuclear plants.",
      "url": "https://www.ecfr.gov/current/title-10/chapter-I/part-73/section-73.120"
    },
    {
      "section": "CIP standards catalog",
      "sourceId": "SRC-NERC-CIP-CATALOG-2026",
      "supportRelationship": "QUALIFIES OR SUPPORTS WITHIN STATED SCOPE",
      "supports": "NERC maintains the official catalog of CIP reliability standards; exact obligations require the current standard text and a facility-specific applicability analysis.",
      "url": "https://www.nerc.com/standards/reliability-standards/cip"
    }
  ],
  "type": "ClaimRecord"
}
