Framework overlap

Does AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) cover Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct?

You hold AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) and have been told to do Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct. Here is how much overlaps, control by control.

56% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct you already have

AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 56% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, leaving 12 of 27 controls as genuinely new work.

Already covered 2 Likely covered 13 New work 12

What is genuinely new work

Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.

BMA-1
Interpretation
BMA-10
Threat Intelligence and Vulnerability Alerting
BMA-12
Board and Senior Management Oversight
BMA-13
Asset Inventory
BMA-14
IT Security Incident Management and Response Team
BMA-15
Notification of Cyber Reporting Events to the Authority
BMA-2
Proportionality Principle
BMA-20
Malicious Code Controls
BMA-23
Data Deletion, Sanitisation and Disposal
BMA-27
Cyber Insurance
BMA-5
Three Lines of Defence
BMA-7
Information Technology Audit Plan
Show the 15 you already have
BMA-4
Chief Information Security Officer
BMA-6
Risk Assessment Process
BMA-11
Information Technology Incident Management
BMA-16
Access Management and Segregation of Duties
BMA-17
Staff Cyber Risk Awareness Training
BMA-18
Data Classification and Security
BMA-19
Data Protection, Governance and Loss Prevention
BMA-21
Security Testing Programme
BMA-22
Patch Management
BMA-24
Network Security Management
BMA-25
Use of Cryptography
BMA-26
Business Continuity and Disaster Recovery Planning
BMA-3
Operational Cyber Risk Management Programme
BMA-8
Third-Party, Outsourcing and Cloud Risk
BMA-9
Information Technology Services Management

How this is calculated

Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition