16% of BSI IT-Grundschutz you already have
ACSC Essential Eight already covers about 16% of BSI IT-Grundschutz, leaving
46 of 55 controls as genuinely new work.
Already covered 0
Likely covered 9
New work 46
No control in ACSC Essential Eight
maps directly to one in BSI IT-Grundschutz. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ACSC Essential Eight reaches these. This is the list to scope.
BSI-01Account management and provisioning
BSI-04Remote access controls
BSI-05Wireless access restrictions
BSI-06Identity proofing and verification
BSI-07Boundary protection and segmentation
BSI-08Cryptographic protection of data
BSI-09Denial-of-service protection
BSI-10Transmission confidentiality and integrity
BSI-11Session management controls
BSI-12Network monitoring and defense
BSI-16Threat intelligence integration
BSI-18Incident response planning and testing
BSI-19Incident handling and containment
BSI-20Incident reporting and notification
BSI-21Forensic analysis capabilities
BSI-22Lessons learned and improvement
BSI-25Security impact analysis
BSI-27Software usage restrictions
BSI-28Audit event logging and storage
BSI-29Audit record review and analysis
BSI-30Time synchronization
BSI-31Audit log protection and retention
BSI-32Accountability and non-repudiation
CON.8Software Development
DER.1Detection of Security-Relevant Events
DER.2.1Security Incident Handling
DER.4Business Continuity Management
ISMS.1Security Management
NET.1.1Network Architecture and Design
OPS.1.1.2Proper IT Administration
OPS.1.1.3Patch and Change Management
ORP.3Awareness and Training
ORP.4Identity and Access Management
Show the 9 you already have
BSI-02Access enforcement and least privilege
BSI-03Multi-factor authentication requirements
BSI-13Risk assessment procedures
BSI-14Vulnerability scanning and management
BSI-15Security categorization
BSI-17Continuous monitoring strategy
BSI-23Baseline configuration establishment
BSI-24Configuration change control
BSI-26System component inventory
How this is calculated
Already covered means a mapping runs from a control in ACSC Essential Eight to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition