Framework overlap

Does Australian Energy Sector Cyber Security Framework (AESCSF) cover Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct?

You hold Australian Energy Sector Cyber Security Framework (AESCSF) and have been told to do Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct. Here is how much overlaps, control by control.

48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct you already have

Australian Energy Sector Cyber Security Framework (AESCSF) already covers about 48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, leaving 14 of 27 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 14

No control in Australian Energy Sector Cyber Security Framework (AESCSF) maps directly to one in Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Australian Energy Sector Cyber Security Framework (AESCSF) reaches these. This is the list to scope.

BMA-1
Interpretation
BMA-10
Threat Intelligence and Vulnerability Alerting
BMA-12
Board and Senior Management Oversight
BMA-14
IT Security Incident Management and Response Team
BMA-18
Data Classification and Security
BMA-19
Data Protection, Governance and Loss Prevention
BMA-20
Malicious Code Controls
BMA-23
Data Deletion, Sanitisation and Disposal
BMA-24
Network Security Management
BMA-25
Use of Cryptography
BMA-27
Cyber Insurance
BMA-4
Chief Information Security Officer
BMA-5
Three Lines of Defence
BMA-7
Information Technology Audit Plan
Show the 13 you already have
BMA-11
Information Technology Incident Management
BMA-13
Asset Inventory
BMA-15
Notification of Cyber Reporting Events to the Authority
BMA-16
Access Management and Segregation of Duties
BMA-17
Staff Cyber Risk Awareness Training
BMA-2
Proportionality Principle
BMA-21
Security Testing Programme
BMA-22
Patch Management
BMA-26
Business Continuity and Disaster Recovery Planning
BMA-3
Operational Cyber Risk Management Programme
BMA-6
Risk Assessment Process
BMA-8
Third-Party, Outsourcing and Cloud Risk
BMA-9
Information Technology Services Management

How this is calculated

Already covered means a mapping runs from a control in Australian Energy Sector Cyber Security Framework (AESCSF) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition