Framework overlap

Does ISO 27018:2019 cover ISO 27017:2015?

You hold ISO 27018:2019 and have been told to do ISO 27017:2015. Here is how much overlaps, control by control.

63% of ISO 27017:2015 you already have

ISO 27018:2019 already covers about 63% of ISO 27017:2015, leaving 15 of 40 controls as genuinely new work.

Already covered 21 Likely covered 4 New work 15

What is genuinely new work

Nothing in ISO 27018:2019 reaches these. This is the list to scope.

14.1
Security requirements of information systems
14.2
Security in development and support processes
14.3
Test data
15.2
Supplier service delivery management
17.2
Redundancies
2.1
Identical Recommendations | International Standards
2.2
Additional References
3.1
Terms defined elsewhere
4.2
Supplier relationships in cloud services
4.3
Relationships between cloud service customers and cloud service providers
4.5
Structure of this standard
6.2
Mobile devices and teleworking
7.2
During employment
8.1
Responsibility for assets
8.2
Information classification
Show the 25 you already have
10.1
Cryptographic controls
11.1
Secure areas
11.2
Equipment
12.1
Operational procedures and responsibilities
12.2
Protection from malware
12.4
Logging and monitoring
12.5
Control of operational software
12.6
Technical vulnerability management
12.7
Information systems audit considerations
13.1
Network security management
13.2
Information transfer
16.1
Management of information security incidents and improvements
18.1
Compliance with legal and contractual requirements
18.2
Information security reviews
5.1
Management direction for information security
6.1
Internal organization
7.1
Prior to employment
9.1
Business requirements of access control
9.2
User access management
9.3
User responsibilities
9.4
System and application access control
12.3
Backup
15.1
Information security in supplier relationships
17.1
Information security continuity
4.4
Managing information security risks in cloud services

How this is calculated

Already covered means a mapping runs from a control in ISO 27018:2019 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition