Framework overlap

Does AWS Well-Architected Security Pillar cover ISO 22739:2024?

You hold AWS Well-Architected Security Pillar and have been told to do ISO 22739:2024. Here is how much overlaps, control by control.

15% of ISO 22739:2024 you already have

AWS Well-Architected Security Pillar already covers about 15% of ISO 22739:2024, leaving 33 of 39 controls as genuinely new work.

Already covered 6 Likely covered 0 New work 33

What is genuinely new work

Nothing in AWS Well-Architected Security Pillar reaches these. This is the list to scope.

ISO-22739-3.1.1
Distributed ledger
ISO-22739-3.1.2
Distributed ledger technology (DLT)
ISO-22739-3.1.3
DLT node
ISO-22739-3.1.4
Consensus mechanism
ISO-22739-3.1.5
Transaction
ISO-22739-3.2.1
Blockchain
ISO-22739-3.2.2
Block
ISO-22739-3.2.3
Genesis block
ISO-22739-3.2.5
Smart contract
ISO-22739-3.3.2
Permissionless DLT system
ISO-22739-3.3.3
Public DLT system
ISO-22739-3.3.4
Private DLT system
ISO-22739-3.3.5
DLT governance
ISO22739-3.1
Distributed Ledger Definition
ISO22739-3.10
Finality Definition
ISO22739-3.11
Oracle Terminology
ISO22739-3.12
Interoperability and Bridge Terms
ISO22739-3.13
Governance Terminology
ISO22739-3.14
Identity and Self Sovereign Terms
ISO22739-3.15
Privacy Preserving Technique Terms
ISO22739-3.16
Audit Trail Vocabulary
ISO22739-3.17
Token Economics Terms
ISO22739-3.18
Stablecoin and Pegged Asset Terms
ISO22739-3.19
Layer Terminology
ISO22739-3.2
Shared Ledger Node Terminology
ISO22739-3.20
Vocabulary Conformance
ISO22739-3.3
Tokenized Record Terminology
ISO22739-3.4
Consensus Mechanism Definitions
ISO22739-3.5
Smart Contract Terminology
ISO22739-3.6
Wallet and Key Management Terms
ISO22739-3.7
Permissioned vs Permissionless Networks
ISO22739-3.8
Block and Transaction Structure
ISO22739-3.9
Immutability Terminology
Show the 6 you already have
ISO-22739-3.2.4
Hash function
ISO-22739-3.3.1
Permissioned DLT system
ISO-22739-3.4.1
Token
ISO-22739-3.4.2
Tokenization
ISO-22739-3.4.3
Digital asset
ISO-22739-3.4.4
Interoperability

How this is calculated

Already covered means a mapping runs from a control in AWS Well-Architected Security Pillar to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition