36% of ISO/IEC 27011:2024 you already have
ISO 26262:2018 already covers about 36% of ISO/IEC 27011:2024, leaving
25 of 39 controls as genuinely new work.
Already covered 0
Likely covered 14
New work 25
No control in ISO 26262:2018
maps directly to one in ISO/IEC 27011:2024. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in ISO 26262:2018 reaches these. This is the list to scope.
27011-4Structure of this document
27011-5.1Policies for Information Security in Telecoms
27011-5.10Acceptable Use of Customer Data
27011-5.15Access Control for Network Elements
27011-5.22Monitoring of Supplier Services
27011-5.23Cloud and Hosted Telecoms Services
27011-5.30ICT Readiness for Continuity
27011-5.4Threat intelligence for telecom
27011-5.5Information security in project management
27011-5.7Threat Intelligence for Telecoms
27011-6.1Screening of Telecoms Personnel
27011-6.2Terms and conditions of employment
27011-7.10Storage Media Handling in Telecoms
27011-7.2Physical entry and securing offices
27011-8.12Data Leakage Prevention for Telecoms
27011-8.15Logging of Network and Service Events
27011-8.16Monitoring Activities
27011-8.20Network Security for Telecoms Core
27011-8.21Security of Network Services
27011-8.22Segregation of Networks
27011-8.24Use of Cryptography
27011-8.27Secure System Architecture
27011-8.7Protection Against Malware
27400-4IoT overview and concepts
Show the 14 you already have
27011-5.2Information Security Roles in Telecoms
27011-5.3Segregation of duties
27011-5.6Supplier relationships and telecom supply chain
27011-6.3Awareness and Training
27011-7.1Physical security perimeters
27011-7.3Equipment protection
27011-7.4Physical Security of Network Sites
27011-8.1User Endpoint Devices
27011-8.2Network security and segregation
27011-8.3Cryptography and key management
27011-8.32Change Management for Network
27011-8.4Logging and monitoring
27011-8.5Vulnerability and malware management
27011-8.6Data protection and backup
How this is calculated
Already covered means a mapping runs from a control in ISO 26262:2018 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition