43% of ASD Strategies to Mitigate Cyber Security Incidents you already have
IATF 16949:2016 already covers about 43% of ASD Strategies to Mitigate Cyber Security Incidents, leaving
21 of 37 controls as genuinely new work.
Already covered 0
Likely covered 16
New work 21
No control in IATF 16949:2016
maps directly to one in ASD Strategies to Mitigate Cyber Security Incidents. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in IATF 16949:2016 reaches these. This is the list to scope.
ASD37-01Application control (Essential)
ASD37-02Patch applications (Essential)
ASD37-03Configure Microsoft Office macro settings (Essential)
ASD37-05Automated dynamic analysis of email and web content (Excellent)
ASD37-06Email content filtering (Excellent)
ASD37-07Web content filtering (Excellent)
ASD37-08Deny direct internet connectivity (Excellent)
ASD37-09OS generic exploit mitigation (Excellent)
ASD37-12Antivirus software with heuristics (Very Good)
ASD37-13Control removable storage media (Very Good)
ASD37-14Block spoofed emails (Very Good)
ASD37-15User education (Limited)
ASD37-16Antivirus software with signatures (Limited)
ASD37-19Patch operating systems (Essential)
ASD37-21Disable local administrator accounts (Excellent)
ASD37-22Network segmentation (Excellent)
ASD37-24Non-persistent virtualised sandboxed environment (Very Good)
ASD37-25Software firewall - inbound (Very Good)
ASD37-26Software firewall - outbound (Very Good)
ASD37-28Continuous incident detection and response (Excellent)
ASD37-30Endpoint detection and response (Very Good)
Show the 16 you already have
ASD37-04User application hardening (Essential)
ASD37-10Server application hardening (Very Good)
ASD37-11Operating system hardening (Very Good)
ASD37-17TLS encryption between email servers (Limited)
ASD37-18Restrict administrative privileges (Essential)
ASD37-20Multi-factor authentication (Essential)
ASD37-23Protect authentication credentials (Excellent)
ASD37-27Outbound data loss prevention (Very Good)
ASD37-29Host-based IDS/IPS (Very Good)
ASD37-31Hunt to discover incidents (Very Good)
ASD37-32Network-based IDS/IPS (Limited)
ASD37-33Capture network traffic (Limited)
ASD37-34Regular backups (Essential)
ASD37-35Business continuity and disaster recovery plans (Very Good)
ASD37-36System recovery capabilities (Very Good)
ASD37-37Personnel management (Very Good)
How this is calculated
Already covered means a mapping runs from a control in IATF 16949:2016 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition