Framework overlap

Does ISO 27019 cover SSAE 18?

You hold ISO 27019 and have been told to do SSAE 18. Here is how much overlaps, control by control.

25% of SSAE 18 you already have

ISO 27019 already covers about 25% of SSAE 18, leaving 50 of 67 controls as genuinely new work.

Already covered 10 Likely covered 7 New work 50

What is genuinely new work

Nothing in ISO 27019 reaches these. This is the list to scope.

SSAE-01
Common Attestation Concepts (AT-C 105)
SSAE-02
Examination Engagements (AT-C 205)
SSAE-03
Review Engagements (AT-C 210)
SSAE-04
Agreed-Upon Procedures (AT-C 215)
SSAE-05
SOC 1 Engagements (AT-C 320)
SSAE-06
SOC 2 Engagements (AT-C 205 with TSC)
SSAE-07
SOC 3 General Use Reports
SSAE-08
Preconditions for Attestation Engagement
SSAE-09
Independence and Ethics
SSAE-10
Engagement Risk Assessment
SSAE-11
Materiality in Attestation
SSAE-12
Written Representations
SSAE-13
Other Information in Reports
SSAE-14
Reporting on Pro Forma Financial Information (AT-C 310)
SSAE-15
Reporting on Compliance (AT-C 315)
SSAE-16
Examinations of Prospective Financial Information (AT-C 305)
SSAE-17
Engagement Documentation
SSAE-18
Quality Management at Firm and Engagement Level
SSAE-19
Modifications to the Standard Report
SSAE-20
Use by Specified Parties and Restricted Distribution
SSAE18-C1.1
C1.1 - Confidential Information Identification
SSAE18-C1.2
C1.2 - Confidential Information Disposal
SSAE18-CC1.1
CC1.1 - COSO Principle 1: Integrity and Ethical Values
SSAE18-CC1.2
CC1.2 - COSO Principle 2: Board Independence and Oversight
SSAE18-CC1.3
CC1.3 - COSO Principle 3: Management Structure and Authority
SSAE18-CC1.4
CC1.4 - COSO Principle 4: Commitment to Competence
SSAE18-CC1.5
CC1.5 - COSO Principle 5: Accountability
SSAE18-CC2.1
CC2.1 - COSO Principle 13: Quality Information
SSAE18-CC2.2
CC2.2 - COSO Principle 14: Internal Communication
SSAE18-CC2.3
CC2.3 - COSO Principle 15: External Communication
SSAE18-CC3.3
CC3.3 - COSO Principle 8: Fraud Risk Assessment
SSAE18-CC5.1
CC5.1 - COSO Principle 10: Control Activity Selection
SSAE18-CC5.2
CC5.2 - COSO Principle 11: Technology General Controls
SSAE18-CC5.3
CC5.3 - COSO Principle 12: Control Activity Policies
SSAE18-CC6.1
CC6.1 - Logical Access Security Software
SSAE18-CC6.3
CC6.3 - Access Removal
SSAE18-CC6.5
CC6.5 - Logical Access to Protected Assets
SSAE18-CC6.6
CC6.6 - External Threats and Security Measures
SSAE18-CC6.7
CC6.7 - Data Transmission Restrictions
SSAE18-CC6.8
CC6.8 - Unauthorized Software Prevention
SSAE18-CC7.1
CC7.1 - Infrastructure and Software Monitoring
SSAE18-CC7.2
CC7.2 - Anomaly Monitoring in Operations
SSAE18-CC7.3
CC7.3 - Security Event Evaluation
SSAE18-CC9.1
CC9.1 - Risk Mitigation Activities
SSAE18-PI1.2
PI1.2 - System Processing Completeness and Accuracy
SSAE18-PI1.3
PI1.3 - Processing Error Handling
SSAE18-SOC1-01
Control Environment
SSAE18-SOC1-03
Information and Communication
SSAE18-SOC1-04
Monitoring Activities
SSAE18-SOC1-05
Control Activities for Financial Processing
Show the 17 you already have
SSAE18-A1.2
A1.2 - Environmental Protections and Recovery
SSAE18-A1.3
A1.3 - Recovery Plan Testing
SSAE18-CC3.1
CC3.1 - COSO Principle 6: Risk Identification
SSAE18-CC3.2
CC3.2 - COSO Principle 7: Risk Analysis
SSAE18-CC3.4
CC3.4 - COSO Principle 9: Change Management
SSAE18-CC7.4
CC7.4 - Incident Response
SSAE18-CC7.5
CC7.5 - Incident Recovery
SSAE18-CC8.1
CC8.1 - Infrastructure and Software Change Management
SSAE18-CC9.2
CC9.2 - Vendor and Business Partner Risk Management
SSAE18-SOC1-02
Risk Assessment
SSAE18-A1.1
A1.1 - Availability Commitments and Requirements
SSAE18-CC6.2
CC6.2 - New User Registration and Authorization
SSAE18-CC6.4
CC6.4 - Physical Access Restrictions
SSAE18-P1.1
P1.1 - Privacy Notice
SSAE18-P1.2
P1.2 - Choice and Consent
SSAE18-PI1.1
PI1.1 - Processing Integrity Definition
SSAE18-SOC1-06
Transaction Processing Controls

How this is calculated

Already covered means a mapping runs from a control in ISO 27019 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition