28% of ISO 27002:2022 you already have
ISO 27701:2019 already covers about 28% of ISO 27002:2022, leaving
62 of 86 controls as genuinely new work.
Already covered 7
Likely covered 17
New work 62
What is genuinely new work
Nothing in ISO 27701:2019 reaches these. This is the list to scope.
5.10Acceptable use of information and other associated assets
5.13Labelling of information
5.17Authentication information
5.20Addressing information security within supplier agreements
5.21Managing information security in the ICT supply chain
5.22Monitoring, review and change management of supplier services
5.25Assessment and decision on information security events
5.27Learning from information security incidents
5.28Collection of evidence
5.30ICT readiness for business continuity
5.31Legal, statutory, regulatory and contractual requirements
5.32Intellectual property rights
5.33Protection of records
5.36Compliance with policies, rules and standards for information security
5.37Documented operating procedures
5.5Contact with authorities
5.6Contact with special interest groups
6.2Terms and conditions of employment
6.3Information security awareness, education and training
6.5Responsibilities after termination or change of employment
6.6Confidentiality or non-disclosure agreements
7.1Physical security perimeters
7.14Secure disposal or re-use of equipment
7.3Securing offices, rooms and facilities
7.5Protecting against physical and environmental threats
7.6Working in secure areas
7.7Clear desk and clear screen
7.9Security of assets off-premises
8.12Data leakage prevention
8.14Redundancy of information processing facilities
8.16Monitoring activities
8.17Clock synchronization
8.19Installation of software on operational systems
8.21Security of network services
8.22Segregation of networks
8.25Secure development life cycle
8.26Application security requirements
8.27Secure system architecture and engineering principles
8.29Security testing in development and acceptance
8.30Outsourced development
8.31Separation of development, test and production environments
8.34Protection of information systems during audit testing
8.9Configuration management
Show the 24 you already have
5.1Policies for information security
5.12Classification of information
5.24Information security incident management planning and preparation
7.13Equipment maintenance
7.8Equipment siting and protection
5.19Information security in supplier relationships
5.2Information security roles and responsibilities
5.23Information security for use of cloud services
5.26Response to information security incidents
5.29Information security during disruption
5.34Privacy and protection of PII
5.35Independent review of information security
5.4Management responsibilities
6.8Information security event reporting
7.4Physical security monitoring
8.18Use of privileged utility programs
How this is calculated
Already covered means a mapping runs from a control in ISO 27701:2019 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition