Framework overlap

Does ISO 15189:2022 cover NIST SP 800-124 Revision 2?

You hold ISO 15189:2022 and have been told to do NIST SP 800-124 Revision 2. Here is how much overlaps, control by control.

29% of NIST SP 800-124 Revision 2 you already have

ISO 15189:2022 already covers about 29% of NIST SP 800-124 Revision 2, leaving 24 of 34 controls as genuinely new work.

Already covered 7 Likely covered 3 New work 24

What is genuinely new work

Nothing in ISO 15189:2022 reaches these. This is the list to scope.

800-124r2-2.1
Mobile Device Threat Model
800-124r2-2.2
Mobile Device Policy
800-124r2-3.1
Enterprise Mobility Management Deployment
800-124r2-3.2
Device Authentication and Enrollment
800-124r2-3.3
Device Hardening Baselines
800-124r2-3.4
Mobile Application Vetting
800-124r2-3.5
Mobile Application Allow and Deny Lists
800-124r2-4.1
Data Protection on Mobile Devices
800-124r2-4.2
Data Communication Protection
800-124r2-4.3
Lost or Stolen Device Procedures
800-124r2-5.1
Mobile Threat Defense Monitoring
800-124r2-5.2
Mobile Operating System Updates
800-124r2-5.3
User Awareness for Mobile Risks
800-124r2-6.1
BYOD Considerations
800-124r2-6.2
Corporate Owned Device Models
800-124r2-7.1
Mobile Device Lifecycle Management
800-124r2-7.2
Mobile Device Decommissioning
800-124r2-8.1
Identity and Access Integration
800-124r2-8.2
Continuous Compliance Reporting
MD124-CTL-03
Remote Wipe Capability
MD124-CTL-05
Jailbreak/Root Detection
MD124-TECH-01
Enterprise Mobility Management (EMM)
MD124-TECH-02
Mobile Threat Defense (MTD)
MD124-TECH-04
Mobile Application Management (MAM)
Show the 10 you already have
MD124-CTL-01
Device Authentication and Lock
MD124-CTL-02
Device Encryption
MD124-CTL-04
OS and Application Updates
MD124-POL-02
BYOD Policy
MD124-POL-03
Mobile Data Protection Policy
MD124-POL-04
Mobile Device Lifecycle Management
MD124-TECH-05
VPN and Secure Communication
MD124-CTL-06
Network Security for Mobile
MD124-POL-01
Mobile Device Security Policy
MD124-TECH-03
Mobile Application Vetting

How this is calculated

Already covered means a mapping runs from a control in ISO 15189:2022 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition