9% of ISO 19650 you already have
Belgium CyberFundamentals already covers about 9% of ISO 19650, leaving
40 of 44 controls as genuinely new work.
Already covered 0
Likely covered 4
New work 40
No control in Belgium CyberFundamentals
maps directly to one in ISO 19650. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Belgium CyberFundamentals reaches these. This is the list to scope.
GEN.1Naming Convention for Information Containers
ISO-19650-1-5Delivery team and task team concepts
ISO-19650-1-6Information delivery planning
ISO-19650-1-8Information model concepts (PIM and AIM)
ISO-19650-2-5.1Assessment and need
ISO-19650-2-5.2Invitation to tender
ISO-19650-2-5.3Tender response
ISO-19650-2-5.4Appointment
ISO-19650-2-5.5Mobilization
ISO-19650-2-5.6Collaborative production of information
ISO-19650-2-5.8Project close-out
ISO-19650-3-5.1Assessment and need for operational information
ISO-19650-3-5.2Information model maintenance
ISO-19650-3-5.4Transition from delivery to operational phase
ISO-19650-5-5Establishing sensitivity of information
ISO-19650-5-6Security triage process
ISO-19650-5-7Security management of information
ISO-19650-5-8Security breach management
P1.5Information Management Process
P1.6Common Data Environment
P1.7Information Containers
P2.5.1Assessment and Need
P2.5.2Information Requirements
P2.5.3Information Standards and Methods
P2.5.4Invitation to Tender
P2.5.8Collaborative Production of Information
P2.5.9Information Model Delivery
P3.5.1Asset Information Triggers
P3.5.2Asset Information Requirements (AIR)
P3.5.4Appointment for Asset Information Updates
P3.5.5Information Production for Asset
P3.5.6Asset Information Model Maintenance
P5.5Security-Minded Approach
P5.7Built Asset Security Information Requirements
P5.8Incident Management for Built Assets
Show the 4 you already have
ISO-19650-1-4Information management concepts
ISO-19650-1-7Common Data Environment (CDE) concept
ISO-19650-2-5.7Information model delivery
ISO-19650-3-5.3Trigger events for information exchange
How this is calculated
Already covered means a mapping runs from a control in Belgium CyberFundamentals to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition