24% of AS9100D:2016 you already have
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 already covers about 24% of AS9100D:2016, leaving
32 of 42 controls as genuinely new work.
Already covered 3
Likely covered 7
New work 32
What is genuinely new work
Nothing in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 reaches these. This is the list to scope.
AS9100D-5.2Quality Policy
AS9100D-5.3Organizational Roles, Responsibilities, and Authorities
AS9100D-8.3Design and Development of Products
AS9100D-8.7Control of Nonconforming Outputs
AS9100D2016-10.1Improvement
AS9100D2016-10.2Nonconformity and Corrective Action
AS9100D2016-4.4QMS and Its Processes
AS9100D2016-5.1Leadership and Commitment
AS9100D2016-5.2Quality Policy
AS9100D2016-5.3Roles, Responsibilities, Authorities
AS9100D2016-6.1Actions to Address Risks and Opportunities
AS9100D2016-6.2Quality Objectives and Planning
AS9100D2016-7.5Documented Information
AS9100D2016-8.1Operational Planning and Control
AS9100D2016-8.1.1Operational Risk Management
AS9100D2016-8.1.2Configuration Management
AS9100D2016-8.1.3Product Safety
AS9100D2016-8.1.4Prevention of Counterfeit Parts
AS9100D2016-8.2Requirements for Products and Services
AS9100D2016-8.3.4Design and Development Controls
AS9100D2016-8.4.1Supplier Selection and Approval
AS9100D2016-8.4.2Type and Extent of Control of Suppliers
AS9100D2016-8.4.3Information for External Providers (Flowdown)
AS9100D2016-8.5.2Identification and Traceability
AS9100D2016-8.5.3Property Belonging to Customers/External Providers
AS9100D2016-8.5.5Post-Delivery Activities
AS9100D2016-9.1.2Customer Satisfaction
AS9100D2016-9.2Internal Audit Program
ISO27003-5.1Leadership and Commitment
ISO27003-5.2Information Security Policy
ISO27003-5.3Organizational Roles, Responsibilities, and Authorities
Show the 10 you already have
9.1Risk communication and consultation
AS9100D-8.4Control of Externally Provided Processes, Products, Services
ISO27003-8.1Operational Planning and Control
8.3Statement of Applicability linkage
8.5Control effectiveness review
AS9100D-5.1Leadership and Commitment
AS9100D-8.1Operational Planning and Control
AS9100D-8.5Production and Service Provision
ISO27003-8.2Information Security Risk Assessment
ISO27003-8.3Information Security Risk Treatment
How this is calculated
Already covered means a mapping runs from a control in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition