Framework overlap

Does ISO 27701:2019 cover ISO 27017:2015?

You hold ISO 27701:2019 and have been told to do ISO 27017:2015. Here is how much overlaps, control by control.

85% of ISO 27017:2015 you already have

ISO 27701:2019 already covers about 85% of ISO 27017:2015, leaving 6 of 40 controls as genuinely new work.

Already covered 30 Likely covered 4 New work 6

What is genuinely new work

Nothing in ISO 27701:2019 reaches these. This is the list to scope.

17.2
Redundancies
2.1
Identical Recommendations | International Standards
2.2
Additional References
3.1
Terms defined elsewhere
4.3
Relationships between cloud service customers and cloud service providers
4.5
Structure of this standard
Show the 34 you already have
10.1
Cryptographic controls
11.1
Secure areas
12.1
Operational procedures and responsibilities
12.2
Protection from malware
12.4
Logging and monitoring
12.5
Control of operational software
12.6
Technical vulnerability management
12.7
Information systems audit considerations
13.1
Network security management
13.2
Information transfer
14.1
Security requirements of information systems
14.2
Security in development and support processes
14.3
Test data
15.2
Supplier service delivery management
16.1
Management of information security incidents and improvements
17.1
Information security continuity
18.1
Compliance with legal and contractual requirements
18.2
Information security reviews
4.2
Supplier relationships in cloud services
5.1
Management direction for information security
6.1
Internal organization
6.2
Mobile devices and teleworking
7.1
Prior to employment
7.2
During employment
8.1
Responsibility for assets
8.2
Information classification
9.1
Business requirements of access control
9.2
User access management
9.3
User responsibilities
9.4
System and application access control
11.2
Equipment
12.3
Backup
15.1
Information security in supplier relationships
4.4
Managing information security risks in cloud services

How this is calculated

Already covered means a mapping runs from a control in ISO 27701:2019 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition