28% of APRA CPS 230 Operational Risk Management you already have
ISO 26262:2018 already covers about 28% of APRA CPS 230 Operational Risk Management, leaving
34 of 47 controls as genuinely new work.
Already covered 1
Likely covered 12
New work 34
What is genuinely new work
Nothing in ISO 26262:2018 reaches these. This is the list to scope.
CPS230-10Operational Risk Management Policy
CPS230-12Internal Controls and Systems
CPS230-14Senior Management Roles
CPS230-15Operational Risk Framework
CPS230-17Critical Operations Identification
CPS230-18Critical Operations Register
CPS230-19Critical Operation Tolerance Levels
CPS230-20Capability to Remain Within Tolerance
CPS230-24Internal Controls
CPS230-29Communication Plans
CPS230-31Escalation Procedures
CPS230-32Dependencies Identification
CPS230-34Tailored Testing Programs
CPS230-36Tolerance Levels for Disruption
CPS230-38Business Continuity Plan
CPS230-39Material Service Provider Identification
CPS230-42APRA Classification Power
CPS230-44Service Provider Risk Identification
CPS230-45APRA Access Provisions
CPS230-47Monitoring and Reporting
CPS230-48Service Provider Due Diligence
CPS230-50Service Provider Contracts
CPS230-53Service Provider Monitoring
CPS230-57Concentration Risk
CPS230-60APRA Notification of Provider Arrangements
CPS230-63Operational Risk Reporting
CPS230-66Independent Review
CPS230-7Board Responsibility
CPS230-8Board Tolerance Levels
CPS230-9Senior Management Accountability
Show the 13 you already have
CPS230-11Risk Identification and Assessment
CPS230-13Board Accountability
CPS230-16Internal Audit Review
CPS230-22Vulnerability and Gap Identification
CPS230-25Business Continuity Policy
CPS230-26Business Continuity Plans
CPS230-27Incident Management
CPS230-28Recovery Objectives
CPS230-37Service Provider Management Policy
CPS230-40Material Classification
CPS230-46Ongoing Risk Management
CPS230-49Internal Audit of Service Providers
CPS230-70Change Management
How this is calculated
Already covered means a mapping runs from a control in ISO 26262:2018 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition