Framework overlap

Does ISO 15189:2022 cover IAEA Nuclear Security Series?

You hold ISO 15189:2022 and have been told to do IAEA Nuclear Security Series. Here is how much overlaps, control by control.

73% of IAEA Nuclear Security Series you already have

ISO 15189:2022 already covers about 73% of IAEA Nuclear Security Series, leaving 3 of 11 controls as genuinely new work.

Already covered 3 Likely covered 5 New work 3

What is genuinely new work

Nothing in ISO 15189:2022 reaches these. This is the list to scope.

IAEA-NSS17-Personnel-Trustworthiness-Training-Awareness
IAEA NSS-17 - Personnel Security + Trustworthiness + Training + Awareness + Cyber Hygiene
IAEA-NSS17-Physical-Lifecycle-Decommissioning-Safety-Emergency
IAEA NSS-17 - Physical Protection of Computer Systems + Lifecycle + Decommissioning + Safety + Emergency Preparedness Interface
IAEA-NSS17-Vulnerability-Patch-RemovableMedia-Portable
IAEA NSS-17 - Vulnerability Management + Patch + Removable Media + Portable Device Control
Show the 8 you already have
IAEA-NSS17-AccessControl-OT-IT-Authentication-Authorization
IAEA NSS-17 - Access Control + Authentication + Authorization + IAM + Privileged Access for OT and IT
IAEA-NSS17-Architecture-Zones-DefenceInDepth-Segmentation
IAEA NSS-17 - Computer Security Architecture + Zone Model + Defence in Depth + Network Segmentation + Boundary
IAEA-NSS17-SupplyChain-ThirdParty-OEM-Trust
IAEA NSS-17 - Supply Chain + Third Party + OEM + Vendor Security + Trustworthy Components
IAEA-NSS17-Assurance-Regulator-Inspection-Reporting-Improvement
IAEA NSS-17 - Assurance Activities + Regulator Interface + Inspection + Reporting + Information Sharing + Continuous Improvement
IAEA-NSS17-Detect-Monitor-Logging-IR-Recovery-Exercises
IAEA NSS-17 - Detection + Monitoring + Logging + Incident Response + Recovery + Computer Security Exercises
IAEA-NSS17-GradedApproach-SecurityLevels-Risk-DBT
IAEA NSS-17 - Graded Approach + Computer Security Levels + Risk-Informed Methodology + Threat Assessment + DBT Alignment + Consequence Analysis
IAEA-NSS17-Scope-NSS-Family-CSP-Establishment
IAEA NSS-17 + NSS-42-G - Scope + Nuclear Security Series Family + Computer Security Programme Establishment + Roles + Management System Integration
IAEA-NSS17-SystemIntegrity-Configuration-Change-Management
IAEA NSS-17 - System Integrity + Configuration Management + Change Management + Baseline + Hardening

How this is calculated

Already covered means a mapping runs from a control in ISO 15189:2022 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition