18% of ISO 26000:2010 you already have
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 18% of ISO 26000:2010, leaving
47 of 57 controls as genuinely new work.
Already covered 1
Likely covered 9
New work 47
What is genuinely new work
Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.
ISO-26000-4.2Accountability
ISO-26000-4.3Transparency
ISO-26000-4.4Ethical behaviour
ISO-26000-4.5Respect for stakeholder interests
ISO-26000-4.6Respect for the rule of law
ISO-26000-4.7Respect for international norms of behaviour
ISO-26000-4.8Respect for human rights
ISO-26000-5.2Recognizing social responsibility
ISO-26000-5.3Stakeholder identification and engagement
ISO-26000-6.2Organizational governance
ISO-26000-6.3.4Resolving grievances
ISO-26000-6.3.5Discrimination and vulnerable groups
ISO-26000-6.4.1Employment and employment relationships
ISO-26000-6.4.2Conditions of work and social protection
ISO-26000-6.4.3Social dialogue
ISO-26000-6.4.5Human development and training in the workplace
ISO-26000-6.5.2Sustainable resource use
ISO-26000-6.8Community involvement and development
ISO-26000-7.2Understanding the social responsibility of the organization
ISO-26000-7.3Integrating social responsibility throughout an organization
ISO-26000-7.4Communication on social responsibility
ISO-26000-7.5Enhancing credibility regarding social responsibility
ISO-26000-7.6Reviewing and improving social responsibility actions
ISO26000-6.2Organizational Governance
ISO26000-6.3.3Human Rights Due Diligence
ISO26000-6.3.4Human Rights Risk Situations
ISO26000-6.3.5Avoidance of Complicity
ISO26000-6.3.6Resolving Grievances
ISO26000-6.3.7Discrimination and Vulnerable Groups
ISO26000-6.4.3Employment and Employment Relationships
ISO26000-6.4.4Conditions of Work and Social Protection
ISO26000-6.4.5Social Dialogue
ISO26000-6.4.6Health and Safety at Work
ISO26000-6.4.7Human Development and Training
ISO26000-6.5.3Prevention of Pollution
ISO26000-6.5.4Sustainable Resource Use
ISO26000-6.5.5Climate Change Mitigation and Adaptation
ISO26000-6.5.6Protection of the Environment and Biodiversity
ISO26000-6.6.3Anti Corruption
ISO26000-6.6.4Responsible Political Involvement
ISO26000-6.6.5Fair Competition
ISO26000-6.6.6Promoting Social Responsibility in the Value Chain
ISO26000-6.7.3Fair Marketing and Contractual Practices
ISO26000-6.7.4Protecting Consumers Health and Safety
ISO26000-6.7.6Consumer Service, Support, and Complaint Resolution
ISO26000-6.8.3Community Involvement
ISO26000-6.8.9Social Investment
Show the 10 you already have
ISO-26000-6.7Consumer issues
ISO-26000-6.3.1Due diligence
ISO-26000-6.3.2Human rights risk situations
ISO-26000-6.3.3Avoidance of complicity
ISO-26000-6.4.4Health and safety at work
ISO-26000-6.5.1Prevention of pollution
ISO-26000-6.5.3Climate change mitigation and adaptation
ISO-26000-6.5.4Protection of the environment and biodiversity
ISO-26000-6.6Fair operating practices
ISO26000-6.7.7Consumer Data Protection and Privacy
How this is calculated
Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition