28% of ISO 27799 you already have
FedRAMP Moderate already covers about 28% of ISO 27799, leaving
33 of 46 controls as genuinely new work.
Already covered 1
Likely covered 12
New work 33
What is genuinely new work
Nothing in FedRAMP Moderate reaches these. This is the list to scope.
ISO27799-10Contingency planning for ePHI
ISO27799-10.1Operational Procedures for Clinical Systems
ISO27799-10.2Backup of Health Records
ISO27799-10.3Audit Logging in Clinical Systems
ISO27799-10.4Anti-malware on Clinical Endpoints
ISO27799-11Business associate management
ISO27799-11.2User Authentication for Clinicians
ISO27799-11.3Remote Access to Clinical Systems
ISO27799-12.1Cryptography for Health Information
ISO27799-13Automatic logoff and session management
ISO27799-13.1Communications Security and Health Interfaces
ISO27799-14Audit controls and monitoring
ISO27799-14.1Secure Development of Clinical Applications
ISO27799-15Integrity controls for ePHI
ISO27799-15.1Supplier Relationships for Health IT
ISO27799-16.1Incident Management for Health Data Breach
ISO27799-17.1Continuity of Clinical Operations
ISO27799-18Workstation security and use policies
ISO27799-18.1Compliance with Health Sector Regulations
ISO27799-19Device and media controls
ISO27799-20Disposal and re-use procedures
ISO27799-21Security and privacy policies
ISO27799-22Documentation and record retention
ISO27799-23Compliance evaluation and review
ISO27799-24Incident reporting procedures
ISO27799-6.1Health Information Security Policy
ISO27799-6.2Health Information Governance Committee
ISO27799-7.1Asset Inventory for Health Records
ISO27799-7.2Classification of Health Information
ISO27799-8.1Workforce Security in Healthcare
ISO27799-8.2Health Information Awareness Training
ISO27799-9.1Physical Security in Healthcare Facilities
ISO27799-9.2Equipment Security and Medical Devices
Show the 13 you already have
ISO27799-06Security management process and risk analysis
ISO27799-01ePHI access controls and authorization
ISO27799-02ePHI encryption at rest and in transit
ISO27799-03Minimum necessary standard enforcement
ISO27799-04Patient data de-identification procedures
ISO27799-05Audit trail for ePHI access
ISO27799-07Workforce security and clearance procedures
ISO27799-08Information access management
ISO27799-09Security awareness and training program
ISO27799-11.1Access Control to Health Records
ISO27799-12Unique user identification and authentication
ISO27799-16Transmission security and encryption
ISO27799-17Facility access controls
How this is calculated
Already covered means a mapping runs from a control in FedRAMP Moderate to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition