26% of AS9100D:2016 you already have
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 26% of AS9100D:2016, leaving
31 of 42 controls as genuinely new work.
Already covered 3
Likely covered 8
New work 31
What is genuinely new work
Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.
AS9100D-5.2Quality Policy
AS9100D-5.3Organizational Roles, Responsibilities, and Authorities
AS9100D-8.3Design and Development of Products
AS9100D-8.7Control of Nonconforming Outputs
AS9100D2016-10.1Improvement
AS9100D2016-10.2Nonconformity and Corrective Action
AS9100D2016-4.4QMS and Its Processes
AS9100D2016-5.1Leadership and Commitment
AS9100D2016-5.2Quality Policy
AS9100D2016-5.3Roles, Responsibilities, Authorities
AS9100D2016-6.1Actions to Address Risks and Opportunities
AS9100D2016-6.2Quality Objectives and Planning
AS9100D2016-7.5Documented Information
AS9100D2016-8.1Operational Planning and Control
AS9100D2016-8.1.1Operational Risk Management
AS9100D2016-8.1.3Product Safety
AS9100D2016-8.1.4Prevention of Counterfeit Parts
AS9100D2016-8.2Requirements for Products and Services
AS9100D2016-8.3.4Design and Development Controls
AS9100D2016-8.4.1Supplier Selection and Approval
AS9100D2016-8.4.2Type and Extent of Control of Suppliers
AS9100D2016-8.4.3Information for External Providers (Flowdown)
AS9100D2016-8.5.2Identification and Traceability
AS9100D2016-8.5.3Property Belonging to Customers/External Providers
AS9100D2016-8.5.5Post-Delivery Activities
AS9100D2016-9.1.2Customer Satisfaction
AS9100D2016-9.2Internal Audit Program
ISO27003-5.1Leadership and Commitment
ISO27003-5.2Information Security Policy
ISO27003-5.3Organizational Roles, Responsibilities, and Authorities
Show the 11 you already have
9.1Risk communication and consultation
AS9100D-8.1Operational Planning and Control
ISO27003-8.2Information Security Risk Assessment
8.3Statement of Applicability linkage
8.5Control effectiveness review
AS9100D-5.1Leadership and Commitment
AS9100D-8.4Control of Externally Provided Processes, Products, Services
AS9100D-8.5Production and Service Provision
AS9100D2016-8.1.2Configuration Management
ISO27003-8.1Operational Planning and Control
ISO27003-8.3Information Security Risk Treatment
How this is calculated
Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition