48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct you already have
Azure Security Benchmark already covers about 48% of Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, leaving
14 of 27 controls as genuinely new work.
Already covered 3
Likely covered 10
New work 14
What is genuinely new work
Nothing in Azure Security Benchmark reaches these. This is the list to scope.
BMA-10Threat Intelligence and Vulnerability Alerting
BMA-12Board and Senior Management Oversight
BMA-14IT Security Incident Management and Response Team
BMA-15Notification of Cyber Reporting Events to the Authority
BMA-17Staff Cyber Risk Awareness Training
BMA-2Proportionality Principle
BMA-20Malicious Code Controls
BMA-21Security Testing Programme
BMA-23Data Deletion, Sanitisation and Disposal
BMA-5Three Lines of Defence
BMA-7Information Technology Audit Plan
Show the 13 you already have
BMA-4Chief Information Security Officer
BMA-6Risk Assessment Process
BMA-8Third-Party, Outsourcing and Cloud Risk
BMA-11Information Technology Incident Management
BMA-16Access Management and Segregation of Duties
BMA-18Data Classification and Security
BMA-19Data Protection, Governance and Loss Prevention
BMA-24Network Security Management
BMA-25Use of Cryptography
BMA-26Business Continuity and Disaster Recovery Planning
BMA-3Operational Cyber Risk Management Programme
BMA-9Information Technology Services Management
How this is calculated
Already covered means a mapping runs from a control in Azure Security Benchmark to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition