Framework overlap

Does Azure Security Benchmark cover ISO/IEC 29115:2023?

You hold Azure Security Benchmark and have been told to do ISO/IEC 29115:2023. Here is how much overlaps, control by control.

11% of ISO/IEC 29115:2023 you already have

Azure Security Benchmark already covers about 11% of ISO/IEC 29115:2023, leaving 34 of 38 controls as genuinely new work.

Already covered 4 Likely covered 0 New work 34

What is genuinely new work

Nothing in Azure Security Benchmark reaches these. This is the list to scope.

29115-10.1
Enrollment and identity proofing criteria
29115-10.2
Credential management criteria
29115-10.3
Entity authentication criteria
29115-10.4
Federation and assertion criteria
29115-5.1
Entity authentication assurance framework overview
29115-5.2
Authentication lifecycle phases
29115-6.1
Authentication context
29115-7.1
Level of Assurance 1 (LoA1)
29115-7.2
Level of Assurance 2 (LoA2)
29115-7.3
Level of Assurance 3 (LoA3)
29115-9.1
Threat analysis overview
29115-9.2
Enrollment and identity proofing threats
29115-9.3
Credential management threats
29115-9.4
Authentication mechanism threats
ISO29115-10.1
Audit and Accountability
ISO29115-10.2
Independent Assessment
ISO29115-11.1
Cross LoA Federation
ISO29115-11.2
Privacy in Authentication
ISO29115-12.1
Documented Operating Procedures
ISO29115-5.1
Authentication Assurance Level Selection
ISO29115-5.2
Enrolment Phase Controls
ISO29115-5.3
Identity Proofing at LoA 1
ISO29115-5.4
Identity Proofing at LoA 2
ISO29115-5.5
Identity Proofing at LoA 3
ISO29115-5.6
Identity Proofing at LoA 4
ISO29115-6.1
Credential Lifecycle Management
ISO29115-6.2
Authenticator Binding
ISO29115-7.1
Authentication Protocol Requirements
ISO29115-7.2
Multi Factor Authentication
ISO29115-7.3
Session Management
ISO29115-8.1
Credential Service Provider Assurance
ISO29115-8.2
Registration Authority Operations
ISO29115-9.1
Threat Mitigation Mapping
ISO29115-9.2
Fraud Detection and Response
Show the 4 you already have
29115-11
Mapping other authentication schemes
29115-12.1
Exchanging authentication results
29115-12.2
Controls for mitigating threats
29115-7.4
Level of Assurance 4 (LoA4)

How this is calculated

Already covered means a mapping runs from a control in Azure Security Benchmark to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition