7% of ISO 41001:2018 you already have
AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 7% of ISO 41001:2018, leaving
155 of 167 controls as genuinely new work.
Already covered 4
Likely covered 8
New work 155
What is genuinely new work
Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.
ISO-22313-10.1Nonconformity and corrective action
ISO-22313-10.2Continual improvement
ISO-22313-4.1Understanding the organization and its context
ISO-22313-4.2Understanding the needs and expectations of interested parties
ISO-22313-4.3Determining the scope of the BCMS
ISO-22313-4.4Business continuity management system
ISO-22313-5.1Leadership and commitment
ISO-22313-5.3Organizational roles, responsibilities and authorities
ISO-22313-6.1Actions to address risks and opportunities
ISO-22313-7.4Communication
ISO-22313-7.5Documented information
ISO-22313-8.1Operational planning and control
ISO-22313-8.3Business continuity strategies and solutions
ISO-22313-8.4Business continuity plans and procedures
ISO-22313-8.5Exercise programme
ISO-22313-9.1Monitoring, measurement, analysis and evaluation
ISO-22313-9.2Internal audit
ISO-22313-9.3Management review
ISO-37002-10.1Nonconformity and corrective action
ISO-37002-10.2Continual improvement
ISO-37002-4.1Understanding the organization and its context
ISO-37002-4.2Understanding the needs and expectations of interested parties
ISO-37002-4.3Determining the scope of the whistleblowing management system
ISO-37002-4.4Whistleblowing management system
ISO-37002-5.1Leadership and commitment
ISO-37002-5.2Whistleblowing policy
ISO-37002-5.3Organizational roles, responsibilities and authorities
ISO-37002-6.1Actions to address risks and opportunities
ISO-37002-6.2Whistleblowing management system objectives and planning
ISO-37002-7.3Awareness and training
ISO-37002-7.4Communication
ISO-37002-7.5Documented information
ISO-37002-9.1Monitoring, measurement, analysis and evaluation
ISO-37002-9.2Internal audit
ISO-37002-9.3Management review
ISO-39001-10.2Continual improvement
ISO-39001-4.1Understanding the organization and its context
ISO-39001-4.2Understanding the needs and expectations of interested parties
ISO-39001-4.3Determining the scope of the RTS management system
ISO-39001-4.4RTS management system
ISO-39001-5.1Leadership and commitment
ISO-39001-5.3Organizational roles, responsibilities and authorities
ISO-39001-6.1Actions to address risks and opportunities
ISO-39001-6.2RTS performance factors
ISO-39001-6.3RTS objectives and planning to achieve them
ISO-39001-7.4Communication
ISO-39001-7.5Documented information
ISO-39001-8.1Operational planning and control
ISO-39001-8.2Emergency preparedness and response
ISO-39001-9.1Monitoring, measurement, analysis and evaluation
ISO-39001-9.2Internal audit
ISO-39001-9.3Management review
ISO-41001-10.2Continual improvement
ISO-41001-4.2Understanding the needs and expectations of interested parties
ISO-41001-4.4Facility management system
ISO-41001-5.1Leadership and commitment
ISO-41001-5.2Facility management policy
ISO-41001-5.3Organizational roles, responsibilities and authorities
ISO-41001-6.1Actions to address risks and opportunities
ISO-41001-6.2Facility management objectives and planning to achieve them
ISO-41001-6.3Planning of changes
ISO-41001-7.4Communication
ISO-41001-7.5Documented information
ISO-41001-7.6Organizational knowledge
ISO-41001-8.1Operational planning and control
ISO-41001-8.2Coordination with stakeholders
ISO-41001-8.3Integration of services
ISO-41001-9.1Monitoring, measurement, analysis and evaluation
ISO-41001-9.2Internal audit
ISO-41001-9.3Management review
ISO-50001-10.1Nonconformity and corrective action
ISO-50001-10.2Continual improvement
ISO-50001-4.1Understanding the organization and its context
ISO-50001-4.2Understanding the needs and expectations of interested parties
ISO-50001-4.3Determining the scope of the EnMS
ISO-50001-4.4Energy management system
ISO-50001-5.1Leadership and commitment
ISO-50001-5.2Energy policy
ISO-50001-5.3Organizational roles, responsibilities and authorities
ISO-50001-6.1Actions to address risks and opportunities
ISO-50001-6.2Objectives, energy targets and planning to achieve them
ISO-50001-6.3Energy review
ISO-50001-6.4Energy performance indicators (EnPIs)
ISO-50001-6.5Energy baseline (EnB)
ISO-50001-6.6Planning for the collection of energy data
ISO-50001-7.4Communication
ISO-50001-7.5Documented information
ISO-50001-8.1Operational planning and control
ISO-50001-9.1Monitoring, measurement, analysis and evaluation of energy performance
ISO-50001-9.2Evaluation of compliance with legal and other requirements
ISO-50001-9.3Internal audit
ISO-50001-9.4Management review
ISO-56002-10.3Continual improvement
ISO-56002-4.1Understanding the organization and its context
ISO-56002-4.2Understanding the needs and expectations of interested parties
ISO-56002-4.4Establishing the innovation management system
ISO-56002-5.1Leadership and commitment
ISO-56002-5.2Innovation policy
ISO-56002-5.3Innovation vision and strategy
ISO-56002-5.4Organizational roles, responsibilities and authorities
ISO-56002-5.5Organizational culture
ISO-56002-6.1Actions to address opportunities and risks
ISO-56002-6.2Innovation objectives and planning to achieve them
ISO-56002-6.3Organizational structures
ISO-56002-6.4Innovation portfolios
ISO-56002-7.4Communication
ISO-56002-7.5Documented information
ISO-56002-7.6Tools and methods
ISO-56002-7.7Strategic intelligence management
ISO-56002-7.8Intellectual property management
ISO-56002-9.1Monitoring, measurement, analysis and evaluation
ISO-56002-9.2Internal audit
ISO-56002-9.3Management review
ISO41001-10.1Nonconformity and Corrective Action
ISO41001-10.2Continual Improvement
ISO41001-4.1Understanding the Organization and Its Context
ISO41001-4.2Needs and Expectations of Interested Parties
ISO41001-4.3Scope of FM System
ISO41001-5.1Leadership and Commitment
ISO41001-5.3Roles, Responsibilities, and Authorities
ISO41001-6.1Actions to Address Risks and Opportunities
ISO41001-6.2FM Objectives and Planning
ISO41001-7.4Communication
ISO41001-7.5Documented Information
ISO41001-8.1Operational Planning and Control
ISO41001-8.2Coordination with Interested Parties
ISO41001-8.3Integration of Services
ISO41001-8.4Procurement of FM Services
ISO41001-8.5Emergency Preparedness and Response
ISO41001-9.1Monitoring, Measurement, Analysis, and Evaluation
ISO41001-9.2Internal Audit
ISO41001-9.3Management Review
Show the 12 you already have
ISO-22313-8.2Business impact analysis and risk assessment
ISO-41001-4.1Understanding the organization and its context
ISO-41001-4.3Determining the scope of the FM management system
ISO-56002-4.3Determining the scope of the innovation management system
ISO-22313-6.2Business continuity objectives and plans to achieve them
ISO-22313-6.3Planning changes to the BCMS
ISO-39001-10.1Nonconformity and corrective action
ISO-41001-10.1Nonconformity and corrective action
ISO-41001-8.4Control of outsourced processes and services
ISO-56002-10.2Deviation, nonconformity and corrective action
How this is calculated
Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition