Framework overlap

Does ISO/IEC 27010:2015 cover FFIEC Cybersecurity Assessment Tool (CAT)?

You hold ISO/IEC 27010:2015 and have been told to do FFIEC Cybersecurity Assessment Tool (CAT). Here is how much overlaps, control by control.

27% of FFIEC Cybersecurity Assessment Tool (CAT) you already have

ISO/IEC 27010:2015 already covers about 27% of FFIEC Cybersecurity Assessment Tool (CAT), leaving 36 of 49 controls as genuinely new work.

Already covered 3 Likely covered 10 New work 36

What is genuinely new work

Nothing in ISO/IEC 27010:2015 reaches these. This is the list to scope.

CAT-D1-1
Governance
CAT-D1-3
Resources
CAT-D2-3
Information sharing
CAT-D4-1
Connections
CAT-D4-2
Relationship management
CAT-D5-2
Detection, response, and mitigation
CAT-D5-3
Escalation and reporting
CAT-IRP-1
Technologies and connection types
CAT-IRP-2
Delivery channels
CAT-IRP-3
Online/mobile products and technology services
CAT-ML-1
Baseline
CAT-ML-3
Intermediate
CAT-ML-4
Advanced
CAT-ML-5
Innovative
FFIEC-CAT-CC-1
Cybersecurity Controls - Preventive Controls Infrastructure Management
FFIEC-CAT-CC-2
Cybersecurity Controls - Access and Data Management
FFIEC-CAT-CC-3
Cybersecurity Controls - Detective Controls
FFIEC-CAT-CC-4
Cybersecurity Controls - Corrective Controls Patch Management
FFIEC-CAT-CRI-1
Migration Path to CRI Profile
FFIEC-CAT-CRMO-1
Cyber Risk Management and Oversight - Governance
FFIEC-CAT-CRMO-2
Risk Management Program
FFIEC-CAT-CRMO-3
Resources and Training
FFIEC-CAT-CRMO-4
Culture and Accountability
FFIEC-CAT-EDM-1
External Dependency Management - Connections
FFIEC-CAT-EDM-2
External Dependency Management - Relationship Management
FFIEC-CAT-IM-1
Incident Management - Incident Resilience Planning and Strategy
FFIEC-CAT-IM-2
Incident Management - Detection, Response, and Mitigation
FFIEC-CAT-IM-3
Incident Management - Escalation and Reporting
FFIEC-CAT-IRP-1
Inherent Risk Profile - Technologies and Connection Types
FFIEC-CAT-IRP-2
Inherent Risk Profile - Delivery Channels
FFIEC-CAT-IRP-3
Online or Mobile Products and Technology Services
FFIEC-CAT-IRP-4
Organizational Characteristics
FFIEC-CAT-IRP-5
External Threats
FFIEC-CAT-TI-1
Threat Intelligence - Intelligence and Information
FFIEC-CAT-TI-2
Threat Intelligence - Monitoring and Analyzing
FFIEC-CAT-TI-3
Threat Intelligence - Information Sharing
Show the 13 you already have
CAT-D3-1
Preventative controls
CAT-D4-3
Third-party access controls
CAT-D5-1
Incident planning and strategy
CAT-D1-2
Risk management
CAT-D1-4
Training and culture
CAT-D2-1
Threat intelligence
CAT-D2-2
Monitoring and analyzing
CAT-D3-2
Detective controls
CAT-D3-3
Corrective controls
CAT-D5-4
Resilience planning and testing
CAT-IRP-4
Organizational characteristics
CAT-IRP-5
External threats
CAT-ML-2
Evolving

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 27010:2015 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition