Framework overlap

Does ISO 39001:2012 cover ISO 27017?

You hold ISO 39001:2012 and have been told to do ISO 27017. Here is how much overlaps, control by control.

57% of ISO 27017 you already have

ISO 39001:2012 already covers about 57% of ISO 27017, leaving 16 of 37 controls as genuinely new work.

Already covered 2 Likely covered 19 New work 16

What is genuinely new work

Nothing in ISO 39001:2012 reaches these. This is the list to scope.

11.2.7
Secure disposal or reuse of equipment (cloud)
14.1.1
Information security requirements analysis (cloud apps)
15.1.1
Information security policy for supplier relationships (cloud)
16.1.1
Responsibilities and procedures (cloud incidents)
18.1.1
Identification of applicable legislation (cloud)
CLD.12.1.5
Administrator's operational security
CLD.12.4.5
Monitoring of cloud services
CLD.13.1.4
Alignment of security management for virtual and physical networks
CLD.6.3.1
Shared roles and responsibilities within a cloud computing environment
CLD.8.1.5
Removal of cloud service customer assets
CLD.9.5.1
Segregation in virtual computing environments
CLD.9.5.2
Virtual machine hardening
ISO27017-09
Federation and single sign-on
ISO27017-10
API security and access tokens
ISO27017-18
Cloud workload protection
ISO27017-25
Service level agreement management
Show the 21 you already have
ISO27017-01
Shared responsibility model definition
ISO27017-03
Cloud risk assessment
ISO27017-02
Cloud security policy and strategy
ISO27017-04
Regulatory compliance for cloud services
ISO27017-05
Cloud security roles and responsibilities
ISO27017-06
Cloud identity management
ISO27017-07
Multi-factor authentication for cloud
ISO27017-08
Privileged access in cloud environments
ISO27017-11
Data classification for cloud
ISO27017-12
Encryption of cloud-stored data
ISO27017-13
Data residency and sovereignty
ISO27017-14
Data backup and recovery in cloud
ISO27017-15
Secure data deletion in cloud
ISO27017-16
Virtual network segmentation
ISO27017-17
Container and serverless security
ISO27017-19
Image and template hardening
ISO27017-20
Cloud configuration management
ISO27017-21
Cloud security monitoring and logging
ISO27017-22
Incident response in cloud
ISO27017-23
Cloud vulnerability management
ISO27017-24
Cloud change management

How this is calculated

Already covered means a mapping runs from a control in ISO 39001:2012 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition