Framework overlap

Does ASD Strategies to Mitigate Cyber Security Incidents cover IACS Unified Requirements E26/E27?

You hold ASD Strategies to Mitigate Cyber Security Incidents and have been told to do IACS Unified Requirements E26/E27. Here is how much overlaps, control by control.

53% of IACS Unified Requirements E26/E27 you already have

ASD Strategies to Mitigate Cyber Security Incidents already covers about 53% of IACS Unified Requirements E26/E27, leaving 9 of 19 controls as genuinely new work.

Already covered 6 Likely covered 4 New work 9

What is genuinely new work

Nothing in ASD Strategies to Mitigate Cyber Security Incidents reaches these. This is the list to scope.

IACS-UR-E26-Implementation-Training-Supplier-OEM-OnboardTraining
IACS UR E26 Implementation - Training + Awareness + Supplier + OEM Management + Cyber Hygiene
IACS-UR-E26-Protect-Malware-Patch-VulnMgmt-Hardening
IACS UR E26 Protect Goal - Malware Defence + Patch + Vulnerability Management + Hardening + Whitelisting
IACS-UR-E26-Scope-Applicability-2024-IMO-MSC-428
IACS UR E26 - Scope + Applicability + Effective 1 July 2024 + Coordination IMO MSC.428(98) + Member Societies
IACS-UR-E26-Survey-Approval-Documentation-OwnerPackage
IACS UR E26 - Class Society Survey + Approval + Owner Documentation + Periodic Review
IACS-UR-E27-Documentation-Owner-Package-Coordination-IMO-IEC-NIST
IACS UR E27 - Documentation Package for Owner + Coordination IMO + IEC 62443 + NIST CSF + 2024-2025 Pipeline
IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrity
IACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity
IACS-UR-E27-Scope-System-Categorization-CategoryI-II-III
IACS UR E27 - Scope + System-Level Applicability + Category I/II/III Classification + IEC 62443 Security Levels
IACS-UR-E27-SecurityCapabilities-IEC62443-CategoryProfile
IACS UR E27 - Security Capabilities by Category + IEC 62443-4-2 Foundational Requirements + Component Requirements
IACS-UR-E27-Updates-Patch-Mechanisms-Maintenance
IACS UR E27 - Equipment Update + Patch Mechanisms + Maintenance + Lifecycle Support
Show the 10 you already have
IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-Boundary
IACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes
IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-Boundary
IACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection
IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons
IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned
IACS-UR-E27-Equipment-Hardening-SecureConfig-Communications
IACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography
IACS-UR-E27-Equipment-UserAuth-Authentication-Authorization
IACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access
IACS-UR-E27-Logging-Forensics-EventCapture
IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection
IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting
IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM
IACS-UR-E26-Identify-AssetInventory-CBS-NetworkArchitecture-Risk
IACS UR E26 Identify Goal - Asset Inventory of Computer Based Systems + Network Architecture Documentation + Risk-Assessable Scope
IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation
IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation
IACS-UR-E26-Protect-AccessControl-Authentication-IAM-Roles
IACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management

How this is calculated

Already covered means a mapping runs from a control in ASD Strategies to Mitigate Cyber Security Incidents to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition