48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct you already have
Australian Energy Sector Cyber Security Framework (AESCSF) already covers about 48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, leaving
14 of 27 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 14
No control in Australian Energy Sector Cyber Security Framework (AESCSF)
maps directly to one in Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Australian Energy Sector Cyber Security Framework (AESCSF) reaches these. This is the list to scope.
BMA-10Threat Intelligence and Vulnerability Alerting
BMA-12Board and Senior Management Oversight
BMA-14IT Security Incident Management and Response Team
BMA-18Data Classification and Security
BMA-19Data Protection, Governance and Loss Prevention
BMA-20Malicious Code Controls
BMA-23Data Deletion, Sanitisation and Disposal
BMA-24Network Security Management
BMA-25Use of Cryptography
BMA-4Chief Information Security Officer
BMA-5Three Lines of Defence
BMA-7Information Technology Audit Plan
Show the 13 you already have
BMA-11Information Technology Incident Management
BMA-15Notification of Cyber Reporting Events to the Authority
BMA-16Access Management and Segregation of Duties
BMA-17Staff Cyber Risk Awareness Training
BMA-2Proportionality Principle
BMA-21Security Testing Programme
BMA-26Business Continuity and Disaster Recovery Planning
BMA-3Operational Cyber Risk Management Programme
BMA-6Risk Assessment Process
BMA-8Third-Party, Outsourcing and Cloud Risk
BMA-9Information Technology Services Management
How this is calculated
Already covered means a mapping runs from a control in Australian Energy Sector Cyber Security Framework (AESCSF) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition