Framework overlap

Does AS9100D cover ISO/IEC 27003:2017?

You hold AS9100D and have been told to do ISO/IEC 27003:2017. Here is how much overlaps, control by control.

86% of ISO/IEC 27003:2017 you already have

AS9100D already covers about 86% of ISO/IEC 27003:2017, leaving 10 of 72 controls as genuinely new work.

Already covered 13 Likely covered 49 New work 10

What is genuinely new work

Nothing in AS9100D reaches these. This is the list to scope.

27003-4.2
Interested Parties and Their Requirements
27003-4.3
Determining ISMS Scope
27003-5.2
Information Security Policy
27003-6.2
Information Security Objectives
27003-8.2
Risk Assessment Performance
27003-8.3
Risk Treatment Implementation
AS9100D-10.1
General Improvement
AS9100D-4.3
Determining the Scope of the QMS
ISO27003-5.2
Information Security Policy
ISO27003-6.2
Information Security Objectives and Planning to Achieve Them
Show the 62 you already have
8.3
Statement of Applicability linkage
AS9100D-10.2
Nonconformity and Corrective Action
AS9100D-5.1
Leadership and Commitment
AS9100D-8.1
Operational Planning and Control
AS9100D-8.4
Control of Externally Provided Processes, Products, Services
AS9100D-8.5
Production and Service Provision
ISO27003-10.1
Continual Improvement
ISO27003-10.2
Nonconformity and Corrective Action
ISO27003-4.2
Understanding Needs and Expectations of Interested Parties
ISO27003-6.1
Actions to Address Risks and Opportunities
ISO27003-8.1
Operational Planning and Control
ISO27003-8.2
Information Security Risk Assessment
ISO27003-8.3
Information Security Risk Treatment
27003-10.1
Nonconformity and Corrective Action
27003-10.2
Continual Improvement
27003-4.1
Understanding the Organization and Its Context
27003-5.1
Leadership and Commitment
27003-5.3
Roles, Responsibilities, Authorities
27003-6.1.1
Actions to Address Risks and Opportunities
27003-6.1.2
Information Security Risk Assessment
27003-6.1.3
Information Security Risk Treatment
27003-7.1
Resources
27003-7.2
Competence
27003-7.3
Awareness
27003-7.4
Communication
27003-7.5
Documented Information
27003-8.1
Operational Planning and Control
27003-9.1
Monitoring, Measurement, Analysis, Evaluation
27003-9.2
Internal Audit
27003-9.3
Management Review
8.5
Control effectiveness review
AS9100D-10.3
Continual Improvement
AS9100D-4.1
Understanding the Organization and Its Context
AS9100D-4.2
Understanding Needs and Expectations of Interested Parties
AS9100D-4.4
Quality Management System and Its Processes
AS9100D-5.2
Quality Policy
AS9100D-5.3
Organizational Roles, Responsibilities, and Authorities
AS9100D-6.1
Risk-Based Thinking and Operational Risk
AS9100D-6.2
Quality Objectives and Planning to Achieve Them
AS9100D-6.3
Planning of Changes
AS9100D-7.1
Resources
AS9100D-7.2
Competence
AS9100D-7.3
Awareness
AS9100D-7.5
Documented Information
AS9100D-8.3
Design and Development of Products
AS9100D-8.7
Control of Nonconforming Outputs
AS9100D-9.1
Monitoring, Measurement, Analysis, Evaluation
AS9100D-9.2
Internal Audit
AS9100D-9.3
Management Review
ISO27003-4.1
Understanding the Organization and Its Context
ISO27003-4.3
Determining the Scope of the ISMS
ISO27003-4.4
Information Security Management System
ISO27003-5.1
Leadership and Commitment
ISO27003-5.3
Organizational Roles, Responsibilities, and Authorities
ISO27003-7.1
Resources
ISO27003-7.2
Competence
ISO27003-7.3
Awareness
ISO27003-7.4
Communication
ISO27003-7.5
Documented Information
ISO27003-9.1
Monitoring, Measurement, Analysis and Evaluation
ISO27003-9.2
Internal Audit
ISO27003-9.3
Management Review

How this is calculated

Already covered means a mapping runs from a control in AS9100D to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition