Framework overlap

Does ASD Strategies to Mitigate Cyber Security Incidents cover ISO 19650?

You hold ASD Strategies to Mitigate Cyber Security Incidents and have been told to do ISO 19650. Here is how much overlaps, control by control.

11% of ISO 19650 you already have

ASD Strategies to Mitigate Cyber Security Incidents already covers about 11% of ISO 19650, leaving 39 of 44 controls as genuinely new work.

Already covered 1 Likely covered 4 New work 39

What is genuinely new work

Nothing in ASD Strategies to Mitigate Cyber Security Incidents reaches these. This is the list to scope.

GEN.1
Naming Convention for Information Containers
GEN.2
Federation Strategy
ISO-19650-1-6
Information delivery planning
ISO-19650-1-8
Information model concepts (PIM and AIM)
ISO-19650-2-5.1
Assessment and need
ISO-19650-2-5.2
Invitation to tender
ISO-19650-2-5.3
Tender response
ISO-19650-2-5.4
Appointment
ISO-19650-2-5.5
Mobilization
ISO-19650-2-5.6
Collaborative production of information
ISO-19650-2-5.8
Project close-out
ISO-19650-3-5.1
Assessment and need for operational information
ISO-19650-3-5.2
Information model maintenance
ISO-19650-3-5.4
Transition from delivery to operational phase
ISO-19650-5-5
Establishing sensitivity of information
ISO-19650-5-6
Security triage process
ISO-19650-5-7
Security management of information
ISO-19650-5-8
Security breach management
P1.5
Information Management Process
P1.6
Common Data Environment
P1.7
Information Containers
P2.5.1
Assessment and Need
P2.5.10
Project Close-out
P2.5.2
Information Requirements
P2.5.3
Information Standards and Methods
P2.5.4
Invitation to Tender
P2.5.5
Tender Response
P2.5.6
Appointment
P2.5.7
Mobilisation
P2.5.8
Collaborative Production of Information
P2.5.9
Information Model Delivery
P3.5.1
Asset Information Triggers
P3.5.2
Asset Information Requirements (AIR)
P3.5.4
Appointment for Asset Information Updates
P3.5.5
Information Production for Asset
P3.5.6
Asset Information Model Maintenance
P5.5
Security-Minded Approach
P5.7
Built Asset Security Information Requirements
P5.8
Incident Management for Built Assets
Show the 5 you already have
ISO-19650-2-5.7
Information model delivery
ISO-19650-1-4
Information management concepts
ISO-19650-1-5
Delivery team and task team concepts
ISO-19650-1-7
Common Data Environment (CDE) concept
ISO-19650-3-5.3
Trigger events for information exchange

How this is calculated

Already covered means a mapping runs from a control in ASD Strategies to Mitigate Cyber Security Incidents to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition