73% of IAEA Nuclear Security Series you already have
ASD Strategies to Mitigate Cyber Security Incidents already covers about 73% of IAEA Nuclear Security Series, leaving
3 of 11 controls as genuinely new work.
Already covered 2
Likely covered 6
New work 3
What is genuinely new work
Nothing in ASD Strategies to Mitigate Cyber Security Incidents reaches these. This is the list to scope.
IAEA-NSS17-Personnel-Trustworthiness-Training-AwarenessIAEA NSS-17 - Personnel Security + Trustworthiness + Training + Awareness + Cyber Hygiene
IAEA-NSS17-Physical-Lifecycle-Decommissioning-Safety-EmergencyIAEA NSS-17 - Physical Protection of Computer Systems + Lifecycle + Decommissioning + Safety + Emergency Preparedness Interface
IAEA-NSS17-Vulnerability-Patch-RemovableMedia-PortableIAEA NSS-17 - Vulnerability Management + Patch + Removable Media + Portable Device Control
Show the 8 you already have
IAEA-NSS17-Detect-Monitor-Logging-IR-Recovery-ExercisesIAEA NSS-17 - Detection + Monitoring + Logging + Incident Response + Recovery + Computer Security Exercises
IAEA-NSS17-SystemIntegrity-Configuration-Change-ManagementIAEA NSS-17 - System Integrity + Configuration Management + Change Management + Baseline + Hardening
IAEA-NSS17-AccessControl-OT-IT-Authentication-AuthorizationIAEA NSS-17 - Access Control + Authentication + Authorization + IAM + Privileged Access for OT and IT
IAEA-NSS17-Architecture-Zones-DefenceInDepth-SegmentationIAEA NSS-17 - Computer Security Architecture + Zone Model + Defence in Depth + Network Segmentation + Boundary
IAEA-NSS17-Assurance-Regulator-Inspection-Reporting-ImprovementIAEA NSS-17 - Assurance Activities + Regulator Interface + Inspection + Reporting + Information Sharing + Continuous Improvement
IAEA-NSS17-GradedApproach-SecurityLevels-Risk-DBTIAEA NSS-17 - Graded Approach + Computer Security Levels + Risk-Informed Methodology + Threat Assessment + DBT Alignment + Consequence Analysis
IAEA-NSS17-Scope-NSS-Family-CSP-EstablishmentIAEA NSS-17 + NSS-42-G - Scope + Nuclear Security Series Family + Computer Security Programme Establishment + Roles + Management System Integration
IAEA-NSS17-SupplyChain-ThirdParty-OEM-TrustIAEA NSS-17 - Supply Chain + Third Party + OEM + Vendor Security + Trustworthy Components
How this is calculated
Already covered means a mapping runs from a control in ASD Strategies to Mitigate Cyber Security Incidents to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition