Framework overlap

Does FFIEC Cybersecurity Assessment Tool (CAT) cover ISO/IEC 27007:2020?

You hold FFIEC Cybersecurity Assessment Tool (CAT) and have been told to do ISO/IEC 27007:2020. Here is how much overlaps, control by control.

7% of ISO/IEC 27007:2020 you already have

FFIEC Cybersecurity Assessment Tool (CAT) already covers about 7% of ISO/IEC 27007:2020, leaving 26 of 28 controls as genuinely new work.

Already covered 1 Likely covered 1 New work 26

What is genuinely new work

Nothing in FFIEC Cybersecurity Assessment Tool (CAT) reaches these. This is the list to scope.

27007-4.1
Auditing principles overview
27007-4.2
Integrity and ethical conduct
27007-4.3
Evidence-based approach
27007-5.1
Establishing the Audit Programme
27007-5.3
Audit Programme Risks
27007-5.5
Implementing the Audit Programme
27007-5.6
Monitoring the Audit Programme
27007-5.7
Reviewing and Improving the Programme
27007-6.1
Initiating the Audit
27007-6.2
Preparing Audit Activities
27007-6.3
Conducting Audit Activities
27007-6.4
Preparing and Distributing the Audit Report
27007-6.5
Completing the Audit
27007-6.6
Audit Follow Up
27007-7.1
Determining Auditor Competence
27007-7.2
Auditor Evaluation Criteria
27007-7.3
Selection of Auditor Evaluation Method
27007-7.4
Conducting Auditor Evaluation
27007-7.5
Maintaining and Improving Auditor Competence
27007-A.1
Generic Competence
27007-A.2
Discipline Specific Competence
27007-A.4
Auditing context of the organization (Clause 4)
27007-A.5
Auditing leadership (Clause 5)
27007-A.6
Auditing planning (Clause 6)
27007-A.7-10
Auditing support through improvement (Clauses 7-10)
27007-B.1
Practical Guidance Examples
Show the 2 you already have
27007-5.4
Establishing the Programme Resources
27007-5.2
Audit Programme Objectives

How this is calculated

Already covered means a mapping runs from a control in FFIEC Cybersecurity Assessment Tool (CAT) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition