43% of Belgium CyberFundamentals you already have
ISO 26262:2018 already covers about 43% of Belgium CyberFundamentals, leaving
25 of 44 controls as genuinely new work.
Already covered 0
Likely covered 19
New work 25
No control in ISO 26262:2018
maps directly to one in Belgium CyberFundamentals. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 26262:2018 reaches these. This is the list to scope.
BE-CF-07Boundary protection and segmentation
BE-CF-09Denial-of-service protection
BE-CF-10Transmission confidentiality and integrity
BE-CF-11Session management controls
BE-CF-12Network monitoring and defense
BE-CF-16Threat intelligence integration
BE-CF-18Incident response planning and testing
BE-CF-19Incident handling and containment
BE-CF-28Audit event logging and storage
BE-CF-29Audit record review and analysis
BE-CF-30Time synchronization
BE-CF-31Audit log protection and retention
BE-CF-32Accountability and non-repudiation
BE-CF-33Asset management and data flow mapping
BE-CF-34Business environment
BE-CF-35Cybersecurity governance and policy
BE-CF-36Supply chain risk management
BE-CF-37Awareness and training
BE-CF-38System maintenance
BE-CF-39Data security lifecycle management
BE-CF-40Recovery planning
BE-CF-41Recovery improvements
BE-CF-42Recovery communications
BE-CF-43Assurance level selection and scoping
Show the 19 you already have
BE-CF-01Account management and provisioning
BE-CF-02Access enforcement and least privilege
BE-CF-03Multi-factor authentication requirements
BE-CF-04Remote access controls
BE-CF-05Wireless access restrictions
BE-CF-06Identity proofing and verification
BE-CF-08Cryptographic protection of data
BE-CF-13Risk assessment procedures
BE-CF-14Vulnerability scanning and management
BE-CF-15Security categorization
BE-CF-17Continuous monitoring strategy
BE-CF-20Incident reporting and notification
BE-CF-21Forensic analysis capabilities
BE-CF-22Lessons learned and improvement
BE-CF-23Baseline configuration establishment
BE-CF-24Configuration change control
BE-CF-25Security impact analysis
BE-CF-26System component inventory
BE-CF-27Software usage restrictions
How this is calculated
Already covered means a mapping runs from a control in ISO 26262:2018 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition