35% of ISO 27002:2022 you already have
ISO 27001:2022 already covers about 35% of ISO 27002:2022, leaving
56 of 86 controls as genuinely new work.
Already covered 19
Likely covered 11
New work 56
What is genuinely new work
Nothing in ISO 27001:2022 reaches these. This is the list to scope.
5.10Acceptable use of information and other associated assets
5.20Addressing information security within supplier agreements
5.21Managing information security in the ICT supply chain
5.22Monitoring, review and change management of supplier services
5.24Information security incident management planning and preparation
5.25Assessment and decision on information security events
5.26Response to information security incidents
5.27Learning from information security incidents
5.30ICT readiness for business continuity
5.31Legal, statutory, regulatory and contractual requirements
5.34Privacy and protection of PII
5.36Compliance with policies, rules and standards for information security
5.37Documented operating procedures
5.6Contact with special interest groups
6.3Information security awareness, education and training
6.5Responsibilities after termination or change of employment
7.13Equipment maintenance
7.14Secure disposal or re-use of equipment
7.3Securing offices, rooms and facilities
7.5Protecting against physical and environmental threats
7.6Working in secure areas
7.7Clear desk and clear screen
7.8Equipment siting and protection
7.9Security of assets off-premises
8.12Data leakage prevention
8.14Redundancy of information processing facilities
8.17Clock synchronization
8.19Installation of software on operational systems
8.21Security of network services
8.22Segregation of networks
8.25Secure development life cycle
8.26Application security requirements
8.27Secure system architecture and engineering principles
8.29Security testing in development and acceptance
8.30Outsourced development
8.31Separation of development, test and production environments
8.34Protection of information systems during audit testing
8.9Configuration management
Show the 30 you already have
5.12Classification of information
5.13Labelling of information
5.17Authentication information
5.28Collection of evidence
5.32Intellectual property rights
5.33Protection of records
5.4Management responsibilities
5.5Contact with authorities
7.1Physical security perimeters
7.4Physical security monitoring
5.1Policies for information security
5.19Information security in supplier relationships
5.2Information security roles and responsibilities
5.23Information security for use of cloud services
5.29Information security during disruption
5.35Independent review of information security
6.2Terms and conditions of employment
6.6Confidentiality or non-disclosure agreements
6.8Information security event reporting
8.16Monitoring activities
8.18Use of privileged utility programs
How this is calculated
Already covered means a mapping runs from a control in ISO 27001:2022 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition