Framework overlap

Does ISO/IEC 27011:2024 cover ITU-T X.805?

You hold ISO/IEC 27011:2024 and have been told to do ITU-T X.805. Here is how much overlaps, control by control.

31% of ITU-T X.805 you already have

ISO/IEC 27011:2024 already covers about 31% of ITU-T X.805, leaving 9 of 13 controls as genuinely new work.

Already covered 1 Likely covered 3 New work 9

What is genuinely new work

Nothing in ISO/IEC 27011:2024 reaches these. This is the list to scope.

X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention
ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Fo
X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection
ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication
X805-Dim6-Data-Integrity-Correctness-Accuracy-Unauthorized-Modification-Deletion-Detection
ITU-T X.805 Security Dimension 6 - Data Integrity + Correctness + Accuracy + Unauthorized Modification Prevention + Deletion Detection + Hashing + HMAC + Digital Signatures + Merkl
X805-Layer1-Infrastructure-Security-Transmission-Facilities-Network-Elements-Lines-Routers-Switches
ITU-T X.805 Security Layer 1 - Infrastructure Security + Transmission Facilities + Network Elements + Routers + Switches + Lines + Physical + Datacenter + Optical + Radio Access +
X805-Layer2-Services-Security-Frame-Relay-ATM-IP-VoIP-QoS-Toll-Free-IM-VPN-AAA-DNS
ITU-T X.805 Security Layer 2 - Services Security + Frame Relay + ATM + IP + VoIP + QoS + Toll-Free + Instant Messaging + VPN + AAA Authentication-Authorization-Accounting + DNS + I
X805-Layer3-Applications-Security-Email-Web-Directory-File-Transfer-E-Commerce-Video
ITU-T X.805 Security Layer 3 - Applications Security + Email + Web + Directory + File Transfer + E-Commerce + Video Conferencing + IM + Office Collaboration + SaaS + B2B EDI + Mobi
X805-Planes-Management-Control-EndUser-OAM-Signalling-Network-Element-Subscriber-Data
ITU-T X.805 Security Planes - Management Plane + Control Plane + End-User Plane + OAM Operations-Administration-Maintenance + Signalling + Routing + Network Element Activity + Subs
X805-Scope-Architecture-3Layers-3Planes-8Dimensions-5Threats-72Cells-X.800-Series-Heritage
ITU-T X.805 Scope + Security Architecture Overview + 3 Security Layers x 3 Security Planes (9 Modules) x 8 Security Dimensions = 72 Security Perspectives + 5 Threat Categories + X.
X805-Threats-Destruction-Corruption-Removal-Disclosure-Interruption-72Cell-Matrix-Application
ITU-T X.805 5 Threat Categories - Destruction + Corruption + Removal + Disclosure + Interruption + Threat-Dimension Countermeasure Matrix + 72-Cell Matrix Application + STRIDE + MI
Show the 4 you already have
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications
ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations +
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication
ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Fa
X805-Dim7-Availability-Network-Resources-Information-Authorized-Access-No-Service-Denial
ITU-T X.805 Security Dimension 7 - Availability + Network Resources + Information Accessible to Authorized Users + Denial-of-Service Prevention + Resilience + Redundancy + Disaster
X805-Dim8-Privacy-Identification-Network-Activity-Personal-Information-Confidentiality
ITU-T X.805 Security Dimension 8 - Privacy + Identification of Network Activity + Personal Information Confidentiality + Subscriber Anonymity + Pseudonymity + Anti-Tracking + Locat

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 27011:2024 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition