53% of IACS Unified Requirements E26/E27 you already have
ISO 15189:2022 already covers about 53% of IACS Unified Requirements E26/E27, leaving
9 of 19 controls as genuinely new work.
Already covered 2
Likely covered 8
New work 9
What is genuinely new work
Nothing in ISO 15189:2022 reaches these. This is the list to scope.
IACS-UR-E26-Implementation-Training-Supplier-OEM-OnboardTrainingIACS UR E26 Implementation - Training + Awareness + Supplier + OEM Management + Cyber Hygiene
IACS-UR-E26-Protect-Malware-Patch-VulnMgmt-HardeningIACS UR E26 Protect Goal - Malware Defence + Patch + Vulnerability Management + Hardening + Whitelisting
IACS-UR-E26-Scope-Applicability-2024-IMO-MSC-428IACS UR E26 - Scope + Applicability + Effective 1 July 2024 + Coordination IMO MSC.428(98) + Member Societies
IACS-UR-E26-Survey-Approval-Documentation-OwnerPackageIACS UR E26 - Class Society Survey + Approval + Owner Documentation + Periodic Review
IACS-UR-E27-Documentation-Owner-Package-Coordination-IMO-IEC-NISTIACS UR E27 - Documentation Package for Owner + Coordination IMO + IEC 62443 + NIST CSF + 2024-2025 Pipeline
IACS-UR-E27-SBOM-SecureDev-TypeApproval-SoftwareIntegrityIACS UR E27 - Software Bill of Materials + Secure Development Lifecycle + Type Approval + Software Integrity
IACS-UR-E27-Scope-System-Categorization-CategoryI-II-IIIIACS UR E27 - Scope + System-Level Applicability + Category I/II/III Classification + IEC 62443 Security Levels
IACS-UR-E27-SecurityCapabilities-IEC62443-CategoryProfileIACS UR E27 - Security Capabilities by Category + IEC 62443-4-2 Foundational Requirements + Component Requirements
IACS-UR-E27-Updates-Patch-Mechanisms-MaintenanceIACS UR E27 - Equipment Update + Patch Mechanisms + Maintenance + Lifecycle Support
Show the 10 you already have
IACS-UR-E26-Protect-RemoteAccess-Wireless-Physical-BoundaryIACS UR E26 Protect Goal - Remote Access + Wireless + Physical Security + Boundary Protection
IACS-UR-E27-Equipment-UserAuth-Authentication-AuthorizationIACS UR E27 - Equipment User Authentication + Authorization + Session Management + Privileged Access
IACS-UR-E26-Detect-Logging-Monitoring-Audit-AlertingIACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM
IACS-UR-E26-Identify-AssetInventory-CBS-NetworkArchitecture-RiskIACS UR E26 Identify Goal - Asset Inventory of Computer Based Systems + Network Architecture Documentation + Risk-Assessable Scope
IACS-UR-E26-Identify-Plan-Risk-Survey-DocumentationIACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation
IACS-UR-E26-Protect-AccessControl-Authentication-IAM-RolesIACS UR E26 Protect Goal - Access Control + Identity + Authentication + Authorization + User Management
IACS-UR-E26-Protect-NetworkSegmentation-Zones-Conduits-BoundaryIACS UR E26 Protect Goal - Network Segmentation + Zones + Conduits + Boundary Defence + Data Diodes
IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-LessonsIACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned
IACS-UR-E27-Equipment-Hardening-SecureConfig-CommunicationsIACS UR E27 - Equipment Hardening + Secure Configuration + Secure Communications + Cryptography
IACS-UR-E27-Logging-Forensics-EventCaptureIACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection
How this is calculated
Already covered means a mapping runs from a control in ISO 15189:2022 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition