Framework overlap

Does ISO 27019 cover ISMAP (Japan)?

You hold ISO 27019 and have been told to do ISMAP (Japan). Here is how much overlaps, control by control.

63% of ISMAP (Japan) you already have

ISO 27019 already covers about 63% of ISMAP (Japan), leaving 3 of 8 controls as genuinely new work.

Already covered 0 Likely covered 5 New work 3

No control in ISO 27019 maps directly to one in ISMAP (Japan). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in ISO 27019 reaches these. This is the list to scope.

ISMAP-Assessment-ExternalAuditor-AnnualReview-CustomerTransparency-Coord-FedRAMP-IRAP-GCloud-PIPA-ISO27017
ISMAP Assessment - External ISMAP-Approved Auditor + Annual Review + Customer Information and Transparency + Coordination FedRAMP/UK G-Cloud/Australia IRAP/Singapore MTCS + ISO 270
ISMAP-Personnel-BackgroundChecks-Resilience-BCP-DR-SupplyChain-ThirdParty-Subcontractor-FlowDown
ISMAP Personnel Security + Background Checks + Business Continuity + Disaster Recovery + Resilience + Supply Chain Risk Management + Third Party + Subcontractor Flow-Down + Japanes
ISMAP-Scope-2020Launch-MIC-METI-NISC-ISMAP-LIU-Standard-Critical-Tiers-CloudServiceList-Registration
ISMAP Scope + 2020 Launch + MIC/METI/NISC Tri-Ministry Governance + Cloud Service List + 3 Tiers (LIU + Standard + Critical) + ISMAP-LIU Simplified Assurance + Government Procureme
Show the 5 you already have
ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities
ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities
ISMAP-CloudInfrastructure-NetworkSegmentation-Container-Serverless-WorkloadProtection-Hardening-ConfigManagement
ISMAP Cloud Infrastructure - VPC Network Segmentation + Container/Serverless Security + Cloud Workload Protection (CWPP) + Image/Template Hardening + CIS Benchmarks + Configuration
ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA
ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Manage
ISMAP-DataProtection-Classification-Encryption-DataResidencyJapan-Backup-SecureDeletion-Cryptography-FIPS
ISMAP Data Protection - Data Classification + AES-256 Encryption At Rest + TLS 1.3 In Transit + Data Residency Japan + Backup + Secure Deletion + Cryptography per FIPS 140-3 + CRYP
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO
ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Go

How this is calculated

Already covered means a mapping runs from a control in ISO 27019 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition