Framework overlap

Does AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) cover ISO/IEC 38500:2024?

You hold AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) and have been told to do ISO/IEC 38500:2024. Here is how much overlaps, control by control.

11% of ISO/IEC 38500:2024 you already have

AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) already covers about 11% of ISO/IEC 38500:2024, leaving 34 of 38 controls as genuinely new work.

Already covered 1 Likely covered 3 New work 34

What is genuinely new work

Nothing in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) reaches these. This is the list to scope.

38500-3.1
Principle 1: Responsibility
38500-3.10
Information Security Governance
38500-3.11
Data Governance
38500-3.12
Third-Party and Supply Chain Governance
38500-3.13
Innovation and Emerging Technology
38500-3.14
Sustainability and ESG of IT
38500-3.15
Resilience and Continuity
38500-3.16
Value and Benefits Realisation
38500-3.17
Stakeholder Engagement and Transparency
38500-3.18
Governance Review and Continuous Improvement
38500-3.2
Principle 2: Strategy
38500-3.3
Principle 3: Acquisition
38500-3.4
Principle 4: Performance
38500-3.5
Principle 5: Conformance
38500-3.6
Principle 6: Human Behaviour
38500-3.7
Evaluate Task
38500-3.8
Direct Task
38500-3.9
Monitor Task
38500-4.1
Governance model overview
38500-4.2
Evaluate
38500-4.3
Direct
38500-4.4
Monitor
38500-5.12
Ethical behaviour
38500-5.2
Value generation
38500-5.3
Strategy
38500-5.4
Oversight
38500-5.5
Accountability
38500-5.6
Stakeholder engagement
38500-5.7
Leadership
38500-5.8
Data and decisions
38500-6.2
Acquisition principle application
38500-6.3
Performance principle application
38500-6.4
Conformance principle application
38500-6.5
Human behaviour principle application
Show the 4 you already have
38500-6.1
Responsibility principle application
38500-5.10
Social responsibility
38500-5.11
Viability and performance over time
38500-5.9
Risk governance

How this is calculated

Already covered means a mapping runs from a control in AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition