Framework overlap

Does C2M2 cover BIMCO Cyber Security?

You hold C2M2 and have been told to do BIMCO Cyber Security. Here is how much overlaps, control by control.

73% of BIMCO Cyber Security you already have

C2M2 already covers about 73% of BIMCO Cyber Security, leaving 7 of 26 controls as genuinely new work.

Already covered 0 Likely covered 19 New work 7

No control in C2M2 maps directly to one in BIMCO Cyber Security. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in C2M2 reaches these. This is the list to scope.

BIMCO-1.3
Roles, responsibilities and tasks
BIMCO-1.5
Plans and procedures
BIMCO-10.5
Investigating cyber incidents
BIMCO-3.6
Remote access
BIMCO-3.7
System and software maintenance
BIMCO-7.2
Technical protection measures
BIMCO-8.2
Malware detection
Show the 19 you already have
BIMCO-1.2
Senior management involvement
BIMCO-1.4
Differences between IT and OT systems
BIMCO-1.8
Relationship with vendors and other external parties
BIMCO-10.2
The four phases of incident response
BIMCO-10.3
Recovery plan
BIMCO-10.4
Data recovery capability
BIMCO-2.1
Threat actors
BIMCO-2.2
Types of cyber threats
BIMCO-3.1
Common vulnerabilities
BIMCO-3.3
Typical vulnerable systems
BIMCO-3.4
Ship to shore interface
BIMCO-4
Assessing the likelihood
BIMCO-5.1
Impact assessment (CIA model)
BIMCO-6.2
The four phases of a risk assessment
BIMCO-6.3
Third party risk assessments
BIMCO-7.1
Defence in depth and in breadth
BIMCO-7.3
Procedural protection measures
BIMCO-8.1
Detection, logging, blocking and alerts
BIMCO-9
Establish contingency plans

How this is calculated

Already covered means a mapping runs from a control in C2M2 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition