21% of FFIEC IT Examination Handbook you already have
ISO/IEC 25012:2008 already covers about 21% of FFIEC IT Examination Handbook, leaving
62 of 78 controls as genuinely new work.
Already covered 4
Likely covered 12
New work 62
What is genuinely new work
Nothing in ISO/IEC 25012:2008 reaches these. This is the list to scope.
FFIEC-01Information security program management
FFIEC-02Board and management oversight
FFIEC-04Security policy framework
FFIEC-13Third-party dependency management
FFIEC-15Communication and escalation procedures
FFIEC-16Due diligence and onboarding
FFIEC-17Contractual security requirements
FFIEC-19Concentration risk management
FFIEC-21Incident detection and classification
FFIEC-22Incident response and containment
IS-II.A.1Board Oversight of Information Security
IS-II.A.2Senior Management Responsibilities
IS-II.B.1Information Security Culture
IS-II.C.1Information Security Roles and Responsibilities
IS-III.A.1Information Security Risk Management Framework
IS-III.B.2Risk Measurement and Analysis
IS-III.B.3Risk Mitigation Strategy
IS-III.C.1Risk Monitoring and Reporting
IS-III.D.1Information Security Strategy
IS-IV.A.1Inventory and Classification of Information Assets
IS-IV.A.2Data Flow Diagrams
IS-IV.B.1Identity and Access Management Program
IS-IV.B.2Authentication Controls
IS-IV.B.3Privileged Access Management
IS-IV.B.4Access Reviews and Recertification
IS-IV.B.5Joiner Mover Leaver Process
IS-IV.C.1Network Security Architecture
IS-IV.C.2Firewall Configuration and Review
IS-IV.C.3Wireless Network Security
IS-IV.C.4Remote Access Security
IS-IV.D.1Endpoint Security Controls
IS-IV.D.2Mobile Device Management
IS-IV.D.3Removable Media Controls
IS-IV.E.1Secure Software Development Lifecycle
IS-IV.E.2Application Security Testing
IS-IV.E.3Application Change Management
IS-IV.F.1Encryption Standards and Key Management
IS-IV.F.2Data in Transit Encryption
IS-IV.F.3Data at Rest Encryption
IS-IX.A.1Third Party Risk Management
IS-IX.A.2Cloud Service Provider Oversight
IS-V.A.1IT Operations Management
IS-V.A.2Configuration Management
IS-V.B.1Vulnerability Management Program
IS-V.B.2Penetration Testing
IS-V.C.1Physical and Environmental Security
IS-VI.A.1Security Logging Standards
IS-VI.A.2Security Monitoring and SIEM
IS-VI.A.3Threat Intelligence
IS-VI.B.1User Behavior Analytics
IS-VII.A.1Incident Response Program
IS-VII.A.2Incident Detection and Classification
IS-VII.A.3Incident Response Testing and Exercises
IS-VII.A.4Notification of Customers Regulators and Law Enforcement
IS-VIII.A.1Business Continuity Integration
IS-VIII.A.2Backup and Recovery
IS-X.A.1Security Awareness Training
IS-X.B.1Independent Information Security Audit
IS-X.B.2Cybersecurity Assessment and Maturity
IS-XI.A.1Architecture and Operations Alignment
IS-XI.A.2Management Booklet Governance Alignment
Show the 16 you already have
FFIEC-05Roles and responsibilities definition
FFIEC-11Business continuity planning and testing
FFIEC-12Disaster recovery procedures
FFIEC-14Critical service identification
FFIEC-03Risk appetite and tolerance for IT risk
FFIEC-06Network security and segmentation
FFIEC-07Endpoint protection and detection
FFIEC-08Application security controls
FFIEC-09Encryption and key management
FFIEC-10Secure configuration standards
FFIEC-18Ongoing monitoring and assessment
FFIEC-20Exit strategy and transition planning
FFIEC-23Regulatory reporting requirements
FFIEC-24Customer notification procedures
FFIEC-25Post-incident review and improvement
IS-III.B.1Risk Identification
How this is calculated
Already covered means a mapping runs from a control in ISO/IEC 25012:2008 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition