Framework overlap

Does ISO 27017 cover IEC 62443?

You hold ISO 27017 and have been told to do IEC 62443. Here is how much overlaps, control by control.

21% of IEC 62443 you already have

ISO 27017 already covers about 21% of IEC 62443, leaving 64 of 81 controls as genuinely new work.

Already covered 10 Likely covered 7 New work 64

What is genuinely new work

Nothing in ISO 27017 reaches these. This is the list to scope.

62443-2-1-AC
Account Management and Access Control for IACS
62443-2-1-BCP
Business Continuity and Disaster Recovery for IACS
62443-2-1-CSMS
Cyber Security Management System (CSMS) for IACS
62443-2-1-IR
Incident Planning and Response for IACS
62443-2-1-MOC
Management of Change for IACS Security
62443-2-1-NSEG
Network Segmentation and Zone/Conduit Implementation
62443-2-1-PHY
Physical and Environmental Security of IACS Assets
62443-2-1-PM
Patch Management and System Update for IACS
62443-2-1-RA
IACS Risk Identification, Classification and Assessment
62443-2-1-TRN
Personnel Security Awareness and Training for IACS
62443-2-4-SP-01
Service Provider Security Program
62443-2-4-SP-02
Service Provider Solution Staffing and Assurance
62443-2-4-SP-03
Service Provider Architecture and Design Practices
62443-2-4-SP-04
Service Provider Wireless and Remote Access Practices
62443-2-4-SP-05
Service Provider Malware Protection Practices
62443-2-4-SP-06
Service Provider Backup and Restore Practices
62443-3-2-CRS
Document Cybersecurity Requirements Specification (CRS)
62443-3-2-ZCR-1
Identify System Under Consideration
62443-3-2-ZCR-2
High-Level Risk Assessment
62443-3-2-ZCR-3
Partition the SUC into Zones and Conduits
62443-3-2-ZCR-4
Detailed Cybersecurity Risk Assessment per Zone and Conduit
62443-3-3-FR1-SR-1-1
Human User Identification and Authentication (FR1)
62443-3-3-FR1-SR-1-11
Unsuccessful Login Attempts
62443-3-3-FR1-SR-1-2
Software Process and Device Identification and Authentication
62443-3-3-FR1-SR-1-5
Authenticator Management
62443-3-3-FR1-SR-1-7
Strength of Password-Based Authentication
62443-3-3-FR2-SR-2-1
Authorisation Enforcement (FR2 Use Control)
62443-3-3-FR2-SR-2-4
Mobile Code Restriction
62443-3-3-FR2-SR-2-5
Session Lock and Termination
62443-3-3-FR2-SR-2-8
Auditable Events
62443-3-3-FR3-SR-3-1
Communication Integrity (FR3 System Integrity)
62443-3-3-FR3-SR-3-2
Protection from Malicious Code
62443-3-3-FR3-SR-3-3
Security Functionality Verification
62443-3-3-FR3-SR-3-4
Software and Information Integrity
62443-3-3-FR3-SR-3-8
Session Integrity
62443-3-3-FR4-SR-4-1
Information Confidentiality (FR4 Data Confidentiality)
62443-3-3-FR4-SR-4-2
Information Persistence and Sanitisation
62443-3-3-FR5-SR-5-1
Network Segmentation (FR5 Restricted Data Flow)
62443-3-3-FR5-SR-5-2
Zone Boundary Protection
62443-3-3-FR5-SR-5-3
General-Purpose Person-to-Person Communication Restrictions
62443-3-3-FR6-SR-6-1
Audit Log Accessibility (FR6 Timely Response to Events)
62443-3-3-FR6-SR-6-2
Continuous Monitoring
62443-3-3-FR7-SR-7-1
Denial-of-Service Protection (FR7 Resource Availability)
62443-3-3-FR7-SR-7-3
Control System Backup
62443-3-3-FR7-SR-7-6
Network and Security Configurations
62443-4-1-DM
Defect Management and Vulnerability Handling
62443-4-1-SD
Secure by Design
62443-4-1-SG
Security Guidelines for Asset Owner
62443-4-1-SI
Secure Implementation
62443-4-1-SM
Security Management (Product Development)
62443-4-1-SR
Specification of Security Requirements
62443-4-1-SUM
Security Update Management
62443-4-1-SVV
Security Verification and Validation
62443-4-2-CR-1-1
Component Identification and Authentication of Users
62443-4-2-CR-3-1
Component Communication Integrity
62443-4-2-CR-7-1
Component Denial-of-Service Protection
62443-4-2-EDR-3-10
Embedded Device Support for Updates
IEC62443-01
Critical asset identification and inventory
IEC62443-03
Security governance structure
IEC62443-04
Roles and responsibilities for critical systems
IEC62443-06
Physical and logical access controls
IEC62443-09
Interactive remote access security
IEC62443-15
Ports and services management
IEC62443-19
Coordination with sector-specific agencies
Show the 17 you already have
IEC62443-02
System security categorization
IEC62443-07
Personnel risk assessment
IEC62443-13
Network security monitoring
IEC62443-14
System security hardening
IEC62443-16
Incident response plan for operational disruptions
IEC62443-17
Recovery plan for critical systems
IEC62443-20
Exercises and drills for OT incidents
IEC62443-22
Configuration management for OT systems
IEC62443-23
Change management procedures
IEC62443-24
Vulnerability assessment for critical systems
IEC62443-05
Security policy for operational technology
IEC62443-08
Electronic access perimeter management
IEC62443-10
Revocation of access procedures
IEC62443-11
Security patch management for OT
IEC62443-12
Malware prevention for operational systems
IEC62443-18
Reporting obligations to authorities
IEC62443-21
Supply chain risk management for critical components

How this is calculated

Already covered means a mapping runs from a control in ISO 27017 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition