36% of ISO 27005:2022 you already have
ISO 37301:2021 already covers about 36% of ISO 27005:2022, leaving
25 of 39 controls as genuinely new work.
Already covered 7
Likely covered 7
New work 25
What is genuinely new work
Nothing in ISO 37301:2021 reaches these. This is the list to scope.
10.5.2Monitoring and reviewing factors influencing risks
3.1Terms related to information security risk
3.2Terms related to information security risk management
5.1Information security risk management process
5.2Information security risk management cycles
6.1Organizational considerations
6.2Identifying basic requirements of interested parties
6.3Applying risk assessment
6.4.3Criteria for performing information security risk assessments
7.2Identifying information security risks
7.2.2Identifying risk owners
7.3Analysing information security risks
7.3.3Assessing likelihood
7.4Evaluating the information security risks
7.4.1Comparing the results of risk analysis with the risk criteria
7.4.2Prioritizing the analysed risks for risk treatment
8.2Selecting appropriate information security risk treatment options
8.5Producing a Statement of Applicability
8.6Information security risk treatment plan
8.6.1Formulation of the risk treatment plan
8.6.2Approval by risk owners
8.6.3Acceptance of the residual information security risks
9.1Performing information security risk assessment process
9.2Performing information security risk treatment process
Show the 14 you already have
10.2Leadership and commitment
10.3Communication and consultation
10.4Documented information
10.4.2Documented information about processes
10.4.3Documented information about results
10.8Continual improvement
10.1Context of the organization
10.5Monitoring and review
6.4Establishing and maintaining information security risk criteria
6.4.2Risk acceptance criteria
6.5Choosing an appropriate method
7.3.2Assessing potential consequences
7.3.4Determining the levels of risk
How this is calculated
Already covered means a mapping runs from a control in ISO 37301:2021 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition