73% of BIMCO Cyber Security you already have
Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct already covers about 73% of BIMCO Cyber Security, leaving
7 of 26 controls as genuinely new work.
Already covered 0
Likely covered 19
New work 7
No control in Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct
maps directly to one in BIMCO Cyber Security. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct reaches these. This is the list to scope.
BIMCO-1.3Roles, responsibilities and tasks
BIMCO-1.5Plans and procedures
BIMCO-10.5Investigating cyber incidents
BIMCO-2.2Types of cyber threats
BIMCO-3.7System and software maintenance
BIMCO-8.1Detection, logging, blocking and alerts
Show the 19 you already have
BIMCO-1.2Senior management involvement
BIMCO-1.4Differences between IT and OT systems
BIMCO-1.8Relationship with vendors and other external parties
BIMCO-10.2The four phases of incident response
BIMCO-10.4Data recovery capability
BIMCO-3.1Common vulnerabilities
BIMCO-3.3Typical vulnerable systems
BIMCO-3.4Ship to shore interface
BIMCO-4Assessing the likelihood
BIMCO-5.1Impact assessment (CIA model)
BIMCO-6.2The four phases of a risk assessment
BIMCO-6.3Third party risk assessments
BIMCO-7.1Defence in depth and in breadth
BIMCO-7.2Technical protection measures
BIMCO-7.3Procedural protection measures
BIMCO-8.2Malware detection
BIMCO-9Establish contingency plans
How this is calculated
Already covered means a mapping runs from a control in Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition