Framework overlap

Does Azure Security Benchmark cover Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct?

You hold Azure Security Benchmark and have been told to do Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct. Here is how much overlaps, control by control.

48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct you already have

Azure Security Benchmark already covers about 48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, leaving 14 of 27 controls as genuinely new work.

Already covered 3 Likely covered 10 New work 14

What is genuinely new work

Nothing in Azure Security Benchmark reaches these. This is the list to scope.

BMA-1
Interpretation
BMA-10
Threat Intelligence and Vulnerability Alerting
BMA-12
Board and Senior Management Oversight
BMA-13
Asset Inventory
BMA-14
IT Security Incident Management and Response Team
BMA-15
Notification of Cyber Reporting Events to the Authority
BMA-17
Staff Cyber Risk Awareness Training
BMA-2
Proportionality Principle
BMA-20
Malicious Code Controls
BMA-21
Security Testing Programme
BMA-23
Data Deletion, Sanitisation and Disposal
BMA-27
Cyber Insurance
BMA-5
Three Lines of Defence
BMA-7
Information Technology Audit Plan
Show the 13 you already have
BMA-4
Chief Information Security Officer
BMA-6
Risk Assessment Process
BMA-8
Third-Party, Outsourcing and Cloud Risk
BMA-11
Information Technology Incident Management
BMA-16
Access Management and Segregation of Duties
BMA-18
Data Classification and Security
BMA-19
Data Protection, Governance and Loss Prevention
BMA-22
Patch Management
BMA-24
Network Security Management
BMA-25
Use of Cryptography
BMA-26
Business Continuity and Disaster Recovery Planning
BMA-3
Operational Cyber Risk Management Programme
BMA-9
Information Technology Services Management

How this is calculated

Already covered means a mapping runs from a control in Azure Security Benchmark to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition