Framework overlap

Does Azure Security Benchmark cover ISO 27018?

You hold Azure Security Benchmark and have been told to do ISO 27018. Here is how much overlaps, control by control.

25% of ISO 27018 you already have

Azure Security Benchmark already covers about 25% of ISO 27018, leaving 58 of 77 controls as genuinely new work.

Already covered 19 Likely covered 0 New work 58

What is genuinely new work

Nothing in Azure Security Benchmark reaches these. This is the list to scope.

A.1.1
Consent and choice
A.1.1
Consent and choice
A.10.1
Information security
A.10.1
Information security
A.10.10
User ID management
A.10.11
Contract measures
A.10.12
Sub-contracted PII processing
A.10.13
Access to data on pre-used data-storage space
A.10.2
Confidentiality obligations of personnel
A.10.2
Confidentiality obligations of personnel
A.10.3
Restriction of creation of hardcopy material
A.10.3
Restriction of creation of hardcopy material
A.10.4
Control and logging of data restoration
A.10.4
Control and logging of data restoration
A.10.5
Protection of data on storage media leaving premises
A.10.5
Protection of data on storage media leaving premises
A.10.6
PII transmission
A.10.6
PII transmission
A.10.7
Disclosure of PII
A.10.7
Disclosure of PII
A.10.8
Unique use of user IDs
A.10.9
Records of authorized users
A.11.1
Geographical location of PII
A.11.1
Geographical location of PII
A.11.2
Intended destination of PII
A.11.2
Intended destination of PII
A.11.3
Disposal of PII
A.11.4
Temporary files
A.11.5
PII transmission
A.12.1
Notification of a data breach
A.12.1
Notification of a data breach
A.12.2
Return, transfer and disposal of PII
A.12.2
Return, transfer and disposal of PII
A.12.3
Periodic audits and reviews
A.2.1
Purpose legitimacy and specification
A.2.1
Purpose legitimacy and specification
A.2.2
AI policy
A.3.1
Collection limitation
A.3.1
Collection limitation
A.4.1
Data minimization
A.4.1
Data minimization
A.5.1
Use, retention and disclosure limitation
A.5.1
Use, retention and disclosure limitation
A.5.2
AI system impact assessment process
A.6.1
Accuracy and quality
A.6.1
Accuracy and quality
A.7.1
Openness, transparency and notice
A.7.1
Openness, transparency and notice
A.8.1
Individual participation and access
A.8.1
Individual participation and access
A.9.1
Accountability
A.9.1
Accountability
ISO27018-09
Federation and single sign-on
ISO27018-10
API security and access tokens
ISO27018-13
Data residency and sovereignty
ISO27018-17
Container and serverless security
ISO27018-18
Cloud workload protection
ISO27018-25
Service level agreement management
Show the 19 you already have
ISO27018-01
Shared responsibility model definition
ISO27018-02
Cloud security policy and strategy
ISO27018-03
Cloud risk assessment
ISO27018-04
Regulatory compliance for cloud services
ISO27018-05
Cloud security roles and responsibilities
ISO27018-06
Cloud identity management
ISO27018-07
Multi-factor authentication for cloud
ISO27018-08
Privileged access in cloud environments
ISO27018-11
Data classification for cloud
ISO27018-12
Encryption of cloud-stored data
ISO27018-14
Data backup and recovery in cloud
ISO27018-15
Secure data deletion in cloud
ISO27018-16
Virtual network segmentation
ISO27018-19
Image and template hardening
ISO27018-20
Cloud configuration management
ISO27018-21
Cloud security monitoring and logging
ISO27018-22
Incident response in cloud
ISO27018-23
Cloud vulnerability management
ISO27018-24
Cloud change management

How this is calculated

Already covered means a mapping runs from a control in Azure Security Benchmark to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition