35% of ISO 27043 you already have
IAIS Insurance Core Principles (ICPs) already covers about 35% of ISO 27043, leaving
34 of 52 controls as genuinely new work.
Already covered 1
Likely covered 17
New work 34
What is genuinely new work
Nothing in IAIS Insurance Core Principles (ICPs) reaches these. This is the list to scope.
ISO27043-01Information security policy framework
ISO27043-02Management direction and commitment
ISO27043-03Policy review and update procedures
ISO27043-05Contact with authorities and special interest groups
ISO27043-07Acceptable use of assets
ISO27043-09Asset handling procedures
ISO27043-10.1Storage and Retention of Evidence
ISO27043-10.2Evidence Disposal
ISO27043-11.1Investigator Competence and Training
ISO27043-11.2Tool Validation
ISO27043-11.3Quality Assurance for Investigations
ISO27043-12.1Continuous Improvement of Investigation Process
ISO27043-16Cryptographic policy and key management
ISO27043-21Operational procedures and responsibilities
ISO27043-26Audit considerations
ISO27043-28Network service security
ISO27043-29Segregation in networks
ISO27043-30Information transfer policies
ISO27043-31Secure messaging
ISO27043-5.1Forensic Readiness Policy
ISO27043-5.2Roles and Responsibilities for Investigations
ISO27043-5.3Forensic Capability Assessment
ISO27043-6.1Pre-incident Readiness Processes
ISO27043-6.2Identification of Potential Digital Evidence
ISO27043-7.1Incident Detection Trigger
ISO27043-7.2First Response Procedures
ISO27043-8.1Planning the Investigation
ISO27043-8.2Evidence Identification and Collection
ISO27043-8.3Chain of Custody
ISO27043-8.4Evidence Preservation
ISO27043-8.5Evidence Analysis
ISO27043-8.6Investigation Documentation
ISO27043-9.1Presentation of Findings
ISO27043-9.2Closure of Investigation
Show the 18 you already have
ISO27043-04Roles and responsibilities definition
ISO27043-06Asset inventory and ownership
ISO27043-08Information classification and labeling
ISO27043-10Media management and disposal
ISO27043-11Access control policy and enforcement
ISO27043-12User access management and provisioning
ISO27043-13Authentication and password management
ISO27043-14Privileged access management
ISO27043-15Access review and recertification
ISO27043-17Encryption of data at rest
ISO27043-18Encryption of data in transit
ISO27043-19Certificate management
ISO27043-20Key lifecycle management
ISO27043-22Protection from malware
ISO27043-23Backup and recovery procedures
ISO27043-24Logging and monitoring
ISO27043-25Technical vulnerability management
ISO27043-27Network security management
How this is calculated
Already covered means a mapping runs from a control in IAIS Insurance Core Principles (ICPs) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition