24% of ISO/IEC 23894:2023 you already have
Azure Security Benchmark already covers about 24% of ISO/IEC 23894:2023, leaving
61 of 80 controls as genuinely new work.
Already covered 7
Likely covered 12
New work 61
What is genuinely new work
Nothing in Azure Security Benchmark reaches these. This is the list to scope.
23894-4.1AI Risk Management Principles
23894-5.2Leadership and Commitment
23894-5.3Integration into Organizational Processes
23894-5.4.2AI Risk Management Policy
23894-5.4.3Roles, Authorities, Responsibilities
23894-5.4.4Allocation of Resources
23894-5.5Communication and Consultation
23894-6.3AI Risk Assessment Scope and Criteria
23894-6.4.3AI Risk Analysis
23894-6.4.4AI Risk Evaluation
23894-6.5AI Risk Treatment
23894-6.6Monitoring and Review
23894-6.7Recording and Reporting
23894-A.2AI Objectives and Risk Sources
23894-A.3Lifecycle Risk Considerations
23894-A.4AI System Impact Assessment
23894-A.5Human Oversight Controls
23894-A.6Transparency and Explainability
23894-A.7Data Quality and Provenance
23894-A.8Robustness and Resilience Testing
23894-A.9Third-Party AI Components
ISO23894-4.1Integrated AI Risk Management
ISO23894-4.2Structured and Comprehensive Approach
ISO23894-4.3Customized to AI Context
ISO23894-4.4Inclusive Stakeholder Engagement
ISO23894-4.5Dynamic and Responsive
ISO23894-4.6Best Available Information
ISO23894-4.7Human and Cultural Factors
ISO23894-4.8Continual Improvement
ISO23894-5.3AI Risk Management Design
ISO23894-5.4AI Risk Management Implementation
ISO23894-5.6Framework Improvement
ISO23894-6.1Communication and Consultation
ISO23894-6.3.2AI Risk Analysis
ISO23894-6.4AI Risk Treatment
ISO23894-6.5Monitoring and Review
ISO23894-6.6Recording and Reporting
ISO23894-A.2Model Transparency and Explainability
ISO23894-A.3Algorithmic Bias and Fairness
ISO23894-A.4AI System Robustness
ISO23894-A.7Human Oversight of AI
ISO23894-A.8AI Accountability and Governance
5.2Leadership and commitment
5.4.2Articulating risk management commitment
5.4.3Assigning organizational roles, authorities, responsibilities and
5.4.4Allocating resources
5.4.5Establishing communication and consultation
5.7.2Continually improving
6.2Communication and consultation
6.3.3External and internal context
6.3.4Defining risk criteria
6.5.2Selection of risk treatment options
6.5.3Preparing and implementing risk treatment plans
6.7Recording and reporting
Show the 19 you already have
ISO23894-1Scope of AI Risk Management
ISO23894-3AI-Specific Terminology
ISO23894-6.2Scope, Context and Criteria
ISO23894-6.3AI Risk Assessment
ISO23894-6.3.1AI Risk Identification
ISO23894-6.3.3AI Risk Evaluation
ISO23894-A.5Privacy and Data Protection in AI
23894-5.4.1Understanding Organization and Context
23894-6.4.2AI Risk Identification
ISO23894-5.1Leadership and Commitment
ISO23894-5.2AI Risk Management Integration
ISO23894-5.5Framework Evaluation
ISO23894-A.1Data Quality and Representativeness
ISO23894-A.6AI System Security
5.4.1Understanding the organization and its context
How this is calculated
Already covered means a mapping runs from a control in Azure Security Benchmark to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition