Framework overlap

Does ASD Strategies to Mitigate Cyber Security Incidents cover ISO/IEC 23837?

You hold ASD Strategies to Mitigate Cyber Security Incidents and have been told to do ISO/IEC 23837. Here is how much overlaps, control by control.

8% of ISO/IEC 23837 you already have

ASD Strategies to Mitigate Cyber Security Incidents already covers about 8% of ISO/IEC 23837, leaving 33 of 36 controls as genuinely new work.

Already covered 3 Likely covered 0 New work 33

What is genuinely new work

Nothing in ASD Strategies to Mitigate Cyber Security Incidents reaches these. This is the list to scope.

23837-1.4.1
QKD module structural analysis
23837-1.4.2
Classification of QKD protocols
23837-1.4.3
Security problems analysis
23837-1.5.1
Network component SFRs overview
23837-1.6.1
Quantum optical component SFRs
23837-1.6.2
Photon source security
23837-1.6.3
Quantum channel security
23837-1.7.1
Protocol implementation SFRs
23837-1.7.2
Key distillation process security
23837-2.1
Evaluation activities for protocol implementation
23837-2.2
Evaluation activities for quantum optical components
23837-2.3
Evaluation activities for conventional network components
23837-2.4
Evaluation assurance levels
23837-CHAN
Channel Integrity and Authentication
23837-DEV
Development Process Assurance
23837-EC
Error Correction Parameters
23837-GUI
Guidance Documentation
23837-INC
Incident Handling
23837-KEYMGT
Output Key Management
23837-LCM
Life-cycle Management
23837-MON
Operational Monitoring
23837-NET
Network Integration
23837-PA
Privacy Amplification
23837-PHY
Physical Security of Modules
23837-PROOF
Security Proof Mapping
23837-RNG
Random Number Generation
23837-SAR
Security Assurance Requirements
23837-SFR
Security Functional Requirements
23837-SIDE
Side-channel Resistance
23837-SRC
Source and Detector Characterisation
23837-TEST
Test Methods and Evaluation
23837-TOE
Target of Evaluation Definition
23837-VULN
Vulnerability Analysis
Show the 3 you already have
23837-1.5.2
Cryptographic module requirements
23837-1.5.3
Network device testing requirements
23837-1.7.3
Authentication and classical post-processing

How this is calculated

Already covered means a mapping runs from a control in ASD Strategies to Mitigate Cyber Security Incidents to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition