27% of ISO 27018 you already have
ISO 15189:2022 already covers about 27% of ISO 27018, leaving
56 of 77 controls as genuinely new work.
Already covered 6
Likely covered 15
New work 56
What is genuinely new work
Nothing in ISO 15189:2022 reaches these. This is the list to scope.
A.10.1Information security
A.10.1Information security
A.10.10User ID management
A.10.12Sub-contracted PII processing
A.10.13Access to data on pre-used data-storage space
A.10.3Restriction of creation of hardcopy material
A.10.3Restriction of creation of hardcopy material
A.10.4Control and logging of data restoration
A.10.4Control and logging of data restoration
A.10.5Protection of data on storage media leaving premises
A.10.5Protection of data on storage media leaving premises
A.10.8Unique use of user IDs
A.10.9Records of authorized users
A.11.1Geographical location of PII
A.11.1Geographical location of PII
A.11.2Intended destination of PII
A.11.2Intended destination of PII
A.12.1Notification of a data breach
A.12.1Notification of a data breach
A.12.2Return, transfer and disposal of PII
A.12.2Return, transfer and disposal of PII
A.12.3Periodic audits and reviews
A.2.1Purpose legitimacy and specification
A.2.1Purpose legitimacy and specification
A.3.1Collection limitation
A.3.1Collection limitation
A.5.1Use, retention and disclosure limitation
A.5.1Use, retention and disclosure limitation
A.5.2AI system impact assessment process
A.6.1Accuracy and quality
A.6.1Accuracy and quality
A.7.1Openness, transparency and notice
A.7.1Openness, transparency and notice
A.8.1Individual participation and access
A.8.1Individual participation and access
ISO27018-09Federation and single sign-on
ISO27018-10API security and access tokens
ISO27018-13Data residency and sovereignty
ISO27018-17Container and serverless security
ISO27018-18Cloud workload protection
ISO27018-25Service level agreement management
Show the 21 you already have
A.10.2Confidentiality obligations of personnel
A.10.2Confidentiality obligations of personnel
ISO27018-01Shared responsibility model definition
ISO27018-07Multi-factor authentication for cloud
ISO27018-08Privileged access in cloud environments
ISO27018-12Encryption of cloud-stored data
ISO27018-02Cloud security policy and strategy
ISO27018-03Cloud risk assessment
ISO27018-04Regulatory compliance for cloud services
ISO27018-05Cloud security roles and responsibilities
ISO27018-06Cloud identity management
ISO27018-11Data classification for cloud
ISO27018-14Data backup and recovery in cloud
ISO27018-15Secure data deletion in cloud
ISO27018-16Virtual network segmentation
ISO27018-19Image and template hardening
ISO27018-20Cloud configuration management
ISO27018-21Cloud security monitoring and logging
ISO27018-22Incident response in cloud
ISO27018-23Cloud vulnerability management
ISO27018-24Cloud change management
How this is calculated
Already covered means a mapping runs from a control in ISO 15189:2022 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition