Framework overlap

Does ISO 31000:2018 cover SANS Incident Handler's Handbook and PICERL Methodology?

You hold ISO 31000:2018 and have been told to do SANS Incident Handler's Handbook and PICERL Methodology. Here is how much overlaps, control by control.

20% of SANS Incident Handler's Handbook and PICERL Methodology you already have

ISO 31000:2018 already covers about 20% of SANS Incident Handler's Handbook and PICERL Methodology, leaving 32 of 40 controls as genuinely new work.

Already covered 2 Likely covered 6 New work 32

What is genuinely new work

Nothing in ISO 31000:2018 reaches these. This is the list to scope.

PICERL-C-01
Containment: Short Term Containment Strategy
PICERL-C-02
Containment: System Backup Before Remediation
PICERL-C-03
Containment: Long Term Containment
PICERL-C1
Short-Term Containment
PICERL-E-01
Eradication: Root Cause Analysis
PICERL-E-02
Eradication: Removal of Threat Actor Artefacts
PICERL-E-03
Eradication: Credential Reset and Identity Hygiene
PICERL-E2
Root Cause Analysis
PICERL-E3
Backdoor Elimination
PICERL-I-01
Identification: Detection Sources and Alert Triage
PICERL-I-02
Identification: Incident Declaration and Notification
PICERL-I-03
Identification: Evidence Collection and Chain of Custody
PICERL-I-04
Identification: Scope Determination
PICERL-I1
Monitoring and Detection
PICERL-I2
Evidence Collection
PICERL-I3
Incident Classification
PICERL-L-01
Lessons Learned: Post Incident Review
PICERL-L-02
Lessons Learned: Control Improvements and Detection Engineering
PICERL-L-03
Lessons Learned: Metrics and Reporting to Executives
PICERL-L1
Post-Incident Review
PICERL-L2
Documentation and Reporting
PICERL-P-01
Preparation: Incident Response Policy and Charter
PICERL-P-02
Preparation: Incident Response Team Roles and Skills
PICERL-P-03
Preparation: Jump Kit and Tooling Readiness
PICERL-P-04
Preparation: Logging, Detection, and Telemetry Baseline
PICERL-P-05
Preparation: Tabletop Exercises and Drills
PICERL-P1
Security Policy Review
PICERL-P4
Tools and Documentation
PICERL-R-01
Recovery: Restoration Planning and Sequencing
PICERL-R-02
Recovery: Validation and Monitoring
PICERL-R-03
Recovery: Communications and Stakeholder Updates
PICERL-R3
Enhanced Monitoring
Show the 8 you already have
PICERL-P2
Risk Assessment
PICERL-P3
CSIRT Formation
PICERL-C2
System Backup
PICERL-C3
Long-Term Containment
PICERL-E1
Threat Removal
PICERL-L3
Plan Improvement
PICERL-R1
System Restoration
PICERL-R2
Security Verification

How this is calculated

Already covered means a mapping runs from a control in ISO 31000:2018 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition