Framework overlap

Does ISO 27799 cover FedRAMP High?

You hold ISO 27799 and have been told to do FedRAMP High. Here is how much overlaps, control by control.

3% of FedRAMP High you already have

ISO 27799 already covers about 3% of FedRAMP High, leaving 405 of 417 controls as genuinely new work.

Already covered 1 Likely covered 11 New work 405

What is genuinely new work

Nothing in ISO 27799 reaches these. This is the list to scope.

AC-1
Policy and Procedures
AC-10
Concurrent Session Control
AC-11
Device Lock
AC-12
Session Termination
AC-14
Permitted Actions Without Identification or Authentication
AC-17
Remote Access
AC-17(1)
Monitoring and Control
AC-17(2)
Protection of Confidentiality and Integrity Using Encryption
AC-17(3)
Managed Access Control Points
AC-17(4)
Privileged Commands and Access
AC-17(9)
Disconnect or Disable Access
AC-18
Wireless Access
AC-18(1)
Authentication and Encryption
AC-18(3)
Disable Wireless Networking
AC-18(4)
Restrict Configurations by Users
AC-18(5)
Antennas and Transmission Power Levels
AC-19(5)
Full Device or Container-Based Encryption
AC-2(1)
Automated System Account Management
AC-2(11)
Usage Conditions
AC-2(12)
Account Monitoring for Atypical Usage
AC-2(13)
Disable Accounts for High-Risk Individuals
AC-2(2)
Automated Temporary and Emergency Account Management
AC-2(3)
Disable Accounts
AC-2(4)
Automated Audit Actions
AC-2(5)
Inactivity Logout
AC-2(7)
Privileged User Accounts
AC-2(9)
Restrictions on Use of Shared and Group Accounts
AC-20
Use of External Systems
AC-20(1)
Limits on Authorized Use
AC-20(2)
Portable Storage Devices Restricted Use
AC-21
Information Sharing
AC-22
Publicly Accessible Content
AC-4
Information Flow Enforcement
AC-4(21)
Physical or Logical Separation of Information Flows
AC-4(4)
Flow Control of Encrypted Information
AC-4(8)
Security and Privacy Policy Filters
AC-5
Separation of Duties
AC-6
Least Privilege
AC-6(1)
Authorize Access to Security Functions
AC-6(10)
Prohibit Non-Privileged Users from Executing Privileged Functions
AC-6(2)
Non-Privileged Access for Nonsecurity Functions
AC-6(3)
Network Access to Privileged Commands
AC-6(5)
Privileged Accounts
AC-6(7)
Review of User Privileges
AC-6(8)
Privilege Levels for Code Execution
AC-6(9)
Log Use of Privileged Functions
AC-7
Unsuccessful Logon Attempts
AC-8
System Use Notification
AT-1
Policy and Procedures
AT-2
Literacy Training and Awareness
AT-2(2)
Insider Threat
AT-2(3)
Social Engineering and Mining
AT-3
Role-Based Training
AT-4
Training Records
AU-1
Policy and Procedures
AU-10
Non-Repudiation
AU-11
Audit Record Retention
AU-12
Audit Record Generation
AU-12(1)
System-wide and Time-correlated Audit Trail
AU-12(3)
Changes by Authorized Individuals
AU-2
Event Logging
AU-3
Content of Audit Records
AU-3(1)
Additional Audit Information
AU-4
Audit Log Storage Capacity
AU-5
Response to Audit Logging Process Failures
AU-5(1)
Storage Capacity Warning
AU-5(2)
Real-Time Alerts
AU-6
Audit Record Review, Analysis, and Reporting
AU-6(1)
Automated Process Integration
AU-6(3)
Correlate Audit Record Repositories
AU-6(4)
Central Review and Analysis
AU-6(5)
Integrated Analysis of Audit Records
AU-6(6)
Correlation with Physical Monitoring
AU-6(7)
Permitted Actions
AU-7
Audit Record Reduction and Report Generation
AU-7(1)
Automatic Processing
AU-8
Time Stamps
AU-9
Protection of Audit Information
AU-9(2)
Store on Separate Physical Systems or Components
AU-9(3)
Cryptographic Protection
AU-9(4)
Access by Subset of Privileged Users
CA-1
Policy and Procedures
CA-2
Control Assessments
CA-2(1)
Independent Assessors
CA-2(2)
Specialized Assessments
CA-2(3)
Leveraging Results from External Organizations
CA-3
Information Exchange
CA-5
Plan of Action and Milestones
CA-6
Authorization
CA-7
Continuous Monitoring
CA-7(1)
Independent Assessment
CA-7(3)
Trend Analyses
CA-8(1)
Independent Penetration Agent or Team
CA-8(2)
Red Team Exercises
CM-1
Policy and Procedures
CM-10
Software Usage Restrictions
CM-11
User-Installed Software
CM-12
Information Location
CM-12(1)
Automated Tools to Support Information Location
CM-2
Baseline Configuration
CM-2(2)
Automation Support for Accuracy and Currency
CM-2(3)
Retention of Previous Configurations
CM-2(7)
Configure Systems and Components for High-Risk Areas
CM-3
Configuration Change Control
CM-3(1)
Automated Documentation, Notification, and Prohibition
CM-3(2)
Testing, Validation, and Documentation of Changes
CM-3(4)
Security and Privacy Representatives
CM-4
Impact Analyses
CM-4(1)
Separate Test Environments
CM-5
Access Restrictions for Change
CM-5(1)
Automated Access Enforcement and Audit Records
CM-5(2)
Review System Changes
CM-5(3)
Signed Components
CM-6
Configuration Settings
CM-6(1)
Automated Management, Application, and Verification
CM-6(2)
Respond to Unauthorized Changes
CM-7
Least Functionality
CM-7(1)
Periodic Review
CM-7(2)
Prevent Program Execution
CM-7(3)
Registration Compliance
CM-7(5)
Authorized Software Allow-by-Exception
CM-8
System Component Inventory
CM-8(1)
Updates During Installation and Removal
CM-8(2)
Automated Maintenance
CM-8(3)
Automated Unauthorized Component Detection
CM-8(4)
Accountability Information
CM-9
Configuration Management Plan
CP-1
Policy and Procedures
CP-10
System Recovery and Reconstitution
CP-10(2)
Transaction Recovery
CP-10(4)
Restore Within Time Period
CP-2
Contingency Plan
CP-2(1)
Coordinate with Related Plans
CP-2(2)
Capacity Planning
CP-2(3)
Resume Mission and Business Functions
CP-2(5)
Continue Mission and Business Functions
CP-2(8)
Identify Critical Assets
CP-3
Contingency Training
CP-3(1)
Simulated Events
CP-4
Contingency Plan Testing
CP-4(1)
Coordinate with Related Plans
CP-4(2)
Alternate Processing Site
CP-6
Alternate Storage Site
CP-6(1)
Separation from Primary Site
CP-6(2)
Recovery Time and Recovery Point Objectives
CP-6(3)
Accessibility
CP-7
Alternate Processing Site
CP-7(1)
Separation from Primary Site
CP-7(2)
Accessibility
CP-7(3)
Priority of Service
CP-7(4)
Preparation for Use
CP-8
Telecommunications Services
CP-8(1)
Priority of Service Provisions
CP-8(2)
Single Points of Failure
CP-8(3)
Separation of Primary and Alternate Providers
CP-8(4)
Provider Contingency Plan
CP-9
System Backup
CP-9(1)
Testing for Reliability and Integrity
CP-9(2)
Test Restoration Using Sampling
CP-9(3)
Separate Storage for Critical Information
CP-9(5)
Transfer to Alternate Storage Site
CP-9(8)
Cryptographic Protection
IA-1
Policy and Procedures
IA-11
Re-Authentication
IA-12
Identity Proofing
IA-12(2)
Identity Evidence
IA-12(3)
Identity Evidence Validation and Verification
IA-12(4)
In-Person Validation and Verification
IA-12(5)
Address Confirmation
IA-2
Identification and Authentication (Organizational Users)
IA-2(1)
MFA to Privileged Accounts
IA-2(12)
Acceptance of PIV Credentials
IA-2(2)
MFA to Non-Privileged Accounts
IA-2(5)
Individual Authentication with Group Authentication
IA-2(6)
Access to Accounts via Separate Device
IA-2(8)
Access to Accounts Replay Resistant
IA-3
Device Identification and Authentication
IA-4
Identifier Management
IA-4(4)
Identify User Status
IA-5
Authenticator Management
IA-5(1)
Password-Based Authentication
IA-5(2)
Public Key-Based Authentication
IA-5(6)
Protection of Authenticators
IA-5(7)
No Embedded Unencrypted Static Authenticators
IA-5(8)
Multiple System Accounts
IA-6
Authentication Feedback
IA-7
Cryptographic Module Authentication
IA-8
Identification and Authentication (Non-Organizational Users)
IA-8(1)
Acceptance of PIV Credentials from Other Agencies
IA-8(2)
Acceptance of External Authenticators
IA-8(4)
Use of Defined Profiles
IR-1
Event Detection and Triage
IR-2(1)
Simulated Events
IR-2(2)
Automated Training Environments
IR-3
Continuity of Operations
IR-3(2)
Coordination with Related Plans
IR-4(1)
Automated Incident Handling Processes
IR-4(3)
Continuity of Operations
IR-4(4)
Information Correlation
IR-4(6)
Insider Threats
IR-4(8)
Correlation with External Organizations
IR-5
Incident Monitoring
IR-5(1)
Automated Tracking, Data Collection, and Analysis
IR-6
Incident Reporting
IR-6(1)
Automated Reporting
IR-6(3)
Supply Chain Coordination
IR-7
Incident Response Assistance
IR-7(1)
Automation Support for Availability of Information and Support
IR-8
Incident Response Plan
IR-8(1)
Breaches
IR-9
Information Spillage Response
IR-9(2)
Training
IR-9(3)
Post-Spill Operations
IR-9(4)
Exposure to Unauthorized Personnel
MA-1
Policy and Procedures
MA-2
Controlled Maintenance
MA-2(2)
Automated Maintenance Activities
MA-3
Maintenance Tools
MA-3(1)
Inspect Tools
MA-3(2)
Inspect Media
MA-3(3)
Prevent Unauthorized Removal
MA-4
Nonlocal Maintenance
MA-4(3)
Comparable Security and Sanitization
MA-5
Maintenance Personnel
MA-5(1)
Individuals Without Appropriate Access
MA-6
Timely Maintenance
MP-1
Policy and Procedures
MP-2
Media Access
MP-3
Media Marking
MP-4
Media Storage
MP-5
Media Transport
MP-6
Media Sanitization
MP-6(1)
Review, Approve, Track, Document, Verify
MP-6(2)
Equipment Testing
MP-6(3)
Nondestructive Techniques
MP-7
Media Use
PE-1
Policy and Procedures
PE-10
Emergency Shutoff
PE-11
Emergency Power
PE-11(1)
Alternate Power Supply Minimal Operational Capability
PE-12
Emergency Lighting
PE-13
Fire Protection
PE-13(1)
Detection Systems Automatic Activation and Notification
PE-13(2)
Suppression Systems Automatic Activation and Notification
PE-14
Environmental Controls
PE-15
Water Damage Protection
PE-15(1)
Automation Support
PE-16
Delivery and Removal
PE-17
Alternate Work Site
PE-18
Location of System Components
PE-2
Physical Access Authorizations
PE-3
Physical Access Control
PE-3(1)
System Access
PE-6
Monitoring Physical Access
PE-6(1)
Intrusion Alarms and Surveillance Equipment
PE-6(4)
Monitoring Physical Access to Systems
PE-8
Visitor Access Records
PE-8(1)
Automated Records Maintenance and Review
PE-9
Power Equipment and Cabling
PL-1
Policy and Procedures
PL-10
Baseline Selection
PL-11
Baseline Tailoring
PL-2
System Security and Privacy Plans
PL-4
Rules of Behavior
PL-4(1)
Social Media and External Site/Application Usage Restrictions
PL-8
Security and Privacy Architectures
PS-1
Policy and Procedures
PS-2
Position Risk Designation
PS-3
Personnel Screening
PS-3(3)
Information Requiring Special Protective Measures
PS-4
Personnel Termination
PS-4(2)
Automated Actions
PS-5
Personnel Transfer
PS-6
Access Agreements
PS-7
External Personnel Security
PS-8
Personnel Sanctions
PS-9
Position Descriptions
RA-2
Security Categorization
RA-3(1)
Supply Chain Risk Assessment
RA-5
Vulnerability Monitoring and Scanning
RA-5(11)
Public Disclosure Program
RA-5(2)
Update Vulnerabilities to be Scanned
RA-5(4)
Discoverable Information
RA-5(5)
Privileged Access
RA-7
Identifies and Analyzes Risk
RA-9
Identifies and Analyzes Significant Change
SA-1
Logging and Monitoring
SA-10
Developer Configuration Management
SA-10(1)
Software and Firmware Integrity Verification
SA-11
Developer Testing and Evaluation
SA-11(1)
Static Code Analysis
SA-11(2)
Threat Modeling and Vulnerability Analyses
SA-11(8)
Dynamic Code Analysis
SA-15
Development Process, Standards, and Tools
SA-16
Developer-Provided Training
SA-17
Developer Security and Privacy Architecture and Design
SA-2
Common Operating Picture
SA-21
Developer Screening
SA-22
Unsupported System Components
SA-3
System Development Life Cycle
SA-4
Acquisition Process
SA-4(1)
Functional Properties of Controls
SA-4(10)
Use of Approved PIV Products
SA-4(2)
Design and Implementation Information for Controls
SA-4(5)
System, Component, and Service Configurations
SA-4(8)
Continuous Monitoring Plan for Controls
SA-4(9)
Functions, Ports, Protocols, and Services in Use
SA-5
System Documentation
SA-8
Security and Privacy Engineering Principles
SA-9
External System Services
SA-9(1)
Risk Assessments and Organizational Approvals
SA-9(2)
Identification of Functions, Ports, Protocols, and Services
SA-9(4)
Consistent Interests of Consumers and Providers
SA-9(5)
Processing, Storage, and Service Location
SC-1
Policy and Procedures
SC-10
Network Disconnect
SC-12
Cryptographic Key Establishment and Management
SC-12(1)
Availability
SC-12(2)
Symmetric Keys
SC-12(3)
Asymmetric Keys
SC-13
Cryptographic Protection
SC-15
Collaborative Computing Devices and Applications
SC-17
Public Key Infrastructure Certificates
SC-18
Mobile Code
SC-2
Separation of System and User Functionality
SC-20
Secure Name/Address Resolution Service (Authoritative)
SC-21
Secure Name/Address Resolution Service (Recursive or Caching Resolver)
SC-22
Architecture and Provisioning for Name/Address Resolution Service
SC-23
Session Authenticity
SC-23(1)
Invalidate Session Identifiers at Logout
SC-24
Fail in Known State
SC-28
Protection of Information at Rest
SC-28(1)
Cryptographic Protection
SC-3
Security Function Isolation
SC-39
Process Isolation
SC-4
Information in Shared System Resources
SC-45
System Time Synchronization
SC-45(1)
Synchronization with Authoritative Time Source
SC-5
Denial-of-Service Protection
SC-5(1)
Restrict Ability to Attack Other Systems
SC-5(2)
Capacity, Bandwidth, and Redundancy
SC-5(3)
Detection and Monitoring
SC-6
Resource Availability
SC-7
Boundary Protection
SC-7(10)
Prevent Exfiltration
SC-7(12)
Host-Based Protection
SC-7(13)
Isolation of Security Tools, Mechanisms, and Support Components
SC-7(18)
Fail Secure
SC-7(20)
Dynamic Isolation and Segregation
SC-7(21)
Isolation of System Components
SC-7(3)
Access Points
SC-7(4)
External Telecommunications Services
SC-7(5)
Deny by Default Allow by Exception
SC-7(7)
Split Tunneling for Remote Devices
SC-7(8)
Route Traffic to Authenticated Proxy Servers
SC-8
Transmission Confidentiality and Integrity
SC-8(1)
Cryptographic Protection
SI-1
Policy and Procedures
SI-10
Information Input Validation
SI-11
Error Handling
SI-12
Information Management and Retention
SI-16
Memory Protection
SI-17
Fail-Safe Procedures
SI-2
Flaw Remediation
SI-2(1)
Central Management
SI-2(2)
Automated Flaw Remediation Status
SI-2(3)
Time to Remediate Flaws and Benchmarks for Corrective Actions
SI-3
Malicious Code Protection
SI-4
System Monitoring
SI-4(1)
System-Wide Intrusion Detection System
SI-4(10)
Visibility of Encrypted Communications
SI-4(11)
Analyze Communications Traffic Anomalies
SI-4(12)
Automated Organization-Generated Alerts
SI-4(14)
Wireless Intrusion Detection
SI-4(16)
Correlate Monitoring Information
SI-4(18)
Analyze Traffic and Covert Exfiltration
SI-4(19)
Risk for Individuals
SI-4(2)
Automated Tools and Mechanisms for Real-Time Analysis
SI-4(20)
Privileged Users
SI-4(22)
Unauthorized Network Services
SI-4(23)
Host-Based Devices
SI-4(4)
Inbound and Outbound Communications Traffic
SI-4(5)
System-Generated Alerts
SI-5
Security Alerts, Advisories, and Directives
SI-5(1)
Automated Alerts and Advisories
SI-6
Security and Privacy Function Verification
SI-7
Software, Firmware, and Information Integrity
SI-7(1)
Integrity Checks
SI-7(14)
Binary or Machine-Executable Code
SI-7(2)
Automated Notifications of Integrity Violations
SI-7(5)
Automated Response to Integrity Violations
SI-7(7)
Integration of Detection and Response
SI-8
Spam Protection
SI-8(2)
Automatic Updates
SR-1
Policy and Procedures (SR-1)
SR-10
Inspection of Systems or Components (SR-10)
SR-11
Component Authenticity (SR-11)
SR-11(1)
Anti-counterfeit Training (SR-11(1))
SR-11(2)
Configuration Control for Component Service and Repair (SR-11(2))
SR-12
Component Disposal (SR-12)
SR-2
Supply Chain Risk Management Plan (SR-2)
SR-3
Supply Chain Controls and Processes (SR-3)
SR-5
Acquisition Strategies, Tools, and Methods (SR-5)
SR-6
Supplier Assessments and Reviews (SR-6)
SR-8
Notification Agreements (SR-8)
Show the 12 you already have
RA-1
Policy and Procedures
AC-19
Access Control for Mobile Devices
AC-2
Account Management
AC-3
Access Enforcement
CA-8
Penetration Testing
CA-9
Internal System Connections
CM-3(6)
Cryptography Management
IR-2
Incident Response and Recovery
IR-4
Incident Handling
PE-4
Access Control for Transmission
PE-5
Access Control for Output Devices
RA-3
Risk Assessment

How this is calculated

Already covered means a mapping runs from a control in ISO 27799 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition