Framework overlap

Does Belgium CyberFundamentals cover ISO 22317?

You hold Belgium CyberFundamentals and have been told to do ISO 22317. Here is how much overlaps, control by control.

14% of ISO 22317 you already have

Belgium CyberFundamentals already covers about 14% of ISO 22317, leaving 31 of 36 controls as genuinely new work.

Already covered 0 Likely covered 5 New work 31

No control in Belgium CyberFundamentals maps directly to one in ISO 22317. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Belgium CyberFundamentals reaches these. This is the list to scope.

ISO22317-01
Business continuity policy
ISO22317-02
BCM program scope and objectives
ISO22317-03
Resource allocation for BCM
ISO22317-04
BCM roles and responsibilities
ISO22317-05
Management commitment to BCM
ISO22317-06
Business impact analysis methodology
ISO22317-07
Critical activity identification
ISO22317-09
Resource requirements assessment
ISO22317-10
Interdependency mapping
ISO22317-13
Alternate site and resource planning
ISO22317-16
Exercise program development
ISO22317-17
Tabletop and simulation exercises
ISO22317-18
Full-scale testing procedures
ISO22317-19
Post-exercise review and improvement
ISO22317-20
Plan maintenance and update
ISO22317-4.1
BIA Programme Establishment
ISO22317-4.2
BIA Methodology and Approach
ISO22317-5.1
Prioritized Activities Identification
ISO22317-5.2
Impact Categories and Tolerances
ISO22317-5.3
Maximum Tolerable Period of Disruption (MTPD)
ISO22317-5.4
Recovery Time Objective (RTO)
ISO22317-5.5
Recovery Point Objective (RPO)
ISO22317-5.6
Minimum Business Continuity Objective (MBCO)
ISO22317-5.7
Resource Requirements Analysis
ISO22317-5.8
Interdependencies and Single Points of Failure
ISO22317-6.1
BIA Data Collection
ISO22317-6.2
BIA Validation and Sign Off
ISO22317-7.1
BIA Outputs Reporting
ISO22317-7.2
Linking BIA to Continuity Strategy
ISO22317-8.1
BIA Maintenance and Refresh
ISO22317-8.2
BIA Programme Assurance
Show the 5 you already have
ISO22317-08
Recovery time and point objectives
ISO22317-11
Continuity strategy development
ISO22317-12
Recovery strategy for critical activities
ISO22317-14
Supply chain continuity
ISO22317-15
Communication strategy during disruption

How this is calculated

Already covered means a mapping runs from a control in Belgium CyberFundamentals to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition