30% of Azure Security Benchmark you already have
ASIC Cyber Resilience Good Practices already covers about 30% of Azure Security Benchmark, leaving
38 of 54 controls as genuinely new work.
Already covered 0
Likely covered 16
New work 38
No control in ASIC Cyber Resilience Good Practices
maps directly to one in Azure Security Benchmark. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ASIC Cyber Resilience Good Practices reaches these. This is the list to scope.
AM-3Ensure Security of Asset Lifecycle Management
ASB-01Shared responsibility model definition
ASB-02Cloud security policy and strategy
ASB-04Regulatory compliance for cloud services
ASB-05Cloud security roles and responsibilities
ASB-06Cloud identity management
ASB-09Federation and single sign-on
ASB-10API security and access tokens
ASB-11Data classification for cloud
ASB-15Secure data deletion in cloud
ASB-17Container and serverless security
ASB-18Cloud workload protection
ASB-21Cloud security monitoring and logging
ASB-24Cloud change management
ASB-25Service level agreement management
BR-1Ensure Regular Automated Backups
BR-2Protect Backup and Recovery Data
DP-2Monitor Anomalies and Threats Targeting Sensitive Data
DS-2Ensure Inventory of Software Components in Code
DS-6Enforce Security of Workload Throughout DevOps Lifecycle
ES-1Use Endpoint Detection and Response (EDR)
ES-2Use Modern Anti-Malware Software
IM-1Use Centralised Identity and Authentication System
IM-3Manage Application Identities Securely
IM-4Authenticate Server and Services
IM-6Use Strong Authentication Controls
IM-7Restrict Resource Access Based on Conditions
LT-4Enable Network Logging for Investigation
LT-5Centralise Security Log Management and Analysis
NS-1Establish Network Segmentation Boundaries
NS-2Secure Cloud Services with Network Controls
NS-3Deploy Firewall at Edge of Enterprise Network
NS-5Deploy DDoS Protection
PA-1Separate and Limit Highly Privileged Users
PA-2Avoid Standing Access for User Accounts and Permissions
PA-3Manage Lifecycle of Identities and Entitlements
PV-2Audit and Enforce Secure Configurations
PV-5Perform Vulnerability Assessments
Show the 16 you already have
AM-2Use Only Approved Services
ASB-03Cloud risk assessment
ASB-07Multi-factor authentication for cloud
ASB-08Privileged access in cloud environments
ASB-12Encryption of cloud-stored data
ASB-13Data residency and sovereignty
ASB-14Data backup and recovery in cloud
ASB-16Virtual network segmentation
ASB-19Image and template hardening
ASB-20Cloud configuration management
ASB-22Incident response in cloud
ASB-23Cloud vulnerability management
DP-3Encrypt Sensitive Data in Transit
DP-4Encrypt Data at Rest by Default
GS-1Align Organisation Roles, Responsibilities and Accountabilities
LT-3Enable Logging for Investigation
How this is calculated
Already covered means a mapping runs from a control in ASIC Cyber Resilience Good Practices to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition