Framework overlap

Does ACSC Essential Eight cover ISO 27019?

You hold ACSC Essential Eight and have been told to do ISO 27019. Here is how much overlaps, control by control.

17% of ISO 27019 you already have

ACSC Essential Eight already covers about 17% of ISO 27019, leaving 38 of 46 controls as genuinely new work.

Already covered 0 Likely covered 8 New work 38

No control in ACSC Essential Eight maps directly to one in ISO 27019. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in ACSC Essential Eight reaches these. This is the list to scope.

ISO27019-01
Critical asset identification and inventory
ISO27019-02
System security categorization
ISO27019-03
Security governance structure
ISO27019-04
Roles and responsibilities for critical systems
ISO27019-05
Security policy for operational technology
ISO27019-06
Physical and logical access controls
ISO27019-08
Electronic access perimeter management
ISO27019-09
Interactive remote access security
ISO27019-10
Revocation of access procedures
ISO27019-11
Security patch management for OT
ISO27019-11.1.1
Physical Security for Substations and Plants
ISO27019-11.2.4
Maintenance of Process Control Equipment
ISO27019-12
Malware prevention for operational systems
ISO27019-12.1.2
Change Management for Control Systems
ISO27019-12.2.1
Malware Protection in OT
ISO27019-12.3.1
Backup of Control System Configurations
ISO27019-12.4.1
Event Logging in Control Systems
ISO27019-12.6.1
Vulnerability Management for OT
ISO27019-13.1.1
Network Security for Energy Operations
ISO27019-13.1.3
Segregation of Networks
ISO27019-14.2.1
Secure Development of Control Applications
ISO27019-15
Ports and services management
ISO27019-15.1.1
Supplier Relationships in Energy
ISO27019-16.1.1
Incident Management for Energy Operations
ISO27019-17
Recovery plan for critical systems
ISO27019-17.1.2
Business Continuity for Energy Supply
ISO27019-18.1.1
Compliance with Energy Sector Regulations
ISO27019-19
Coordination with sector-specific agencies
ISO27019-21
Supply chain risk management for critical components
ISO27019-23
Change management procedures
ISO27019-6.1.1
Information Security Roles for Energy Operations
ISO27019-6.1.5
Information Security in Project Management for Energy
ISO27019-7.1.1
Screening of Personnel with OT Access
ISO27019-8.1.1
Inventory of Process Control Assets
ISO27019-8.2.1
Classification of Energy Sector Information
ISO27019-9.1.1
Access Control Policy for Control Systems
ISO27019-9.2.3
Privileged Access in Control Environments
ISO27019-ENR.1
Safety and Security Integration
Show the 8 you already have
ISO27019-07
Personnel risk assessment
ISO27019-13
Network security monitoring
ISO27019-14
System security hardening
ISO27019-16
Incident response plan for operational disruptions
ISO27019-18
Reporting obligations to authorities
ISO27019-20
Exercises and drills for OT incidents
ISO27019-22
Configuration management for OT systems
ISO27019-24
Vulnerability assessment for critical systems

How this is calculated

Already covered means a mapping runs from a control in ACSC Essential Eight to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition