Framework overlap

Does ISO/IEC 27011:2024 cover Space ISAC (Information Sharing and Analysis Center)?

You hold ISO/IEC 27011:2024 and have been told to do Space ISAC (Information Sharing and Analysis Center). Here is how much overlaps, control by control.

10% of Space ISAC (Information Sharing and Analysis Center) you already have

ISO/IEC 27011:2024 already covers about 10% of Space ISAC (Information Sharing and Analysis Center), leaving 36 of 40 controls as genuinely new work.

Already covered 4 Likely covered 0 New work 36

What is genuinely new work

Nothing in ISO/IEC 27011:2024 reaches these. This is the list to scope.

CT-1
RF Interference and Jamming
CT-2
GNSS Spoofing
CT-3
Signal Interception
CT-4
Uplink and Downlink Manipulation
GC-1
Norms of Responsible Behavior
GC-2
Public-Private Information Sharing
GC-3
Cross-Sector Coordination
GC-4
Technology-Agnostic Threat Formats
GT-1
Ground Station Cyber Attacks
SISAC-01
Membership and Trusted Community Onboarding
SISAC-02
Space Asset Inventory and Classification
SISAC-03
Adversary TTP Mapping for Space Systems
SISAC-04
Indicator and Threat Intelligence Sharing
SISAC-05
Command and Telemetry Link Protection
SISAC-06
Ground Segment Hardening
SISAC-07
Supply Chain Risk Management for Space Hardware
SISAC-08
Flight Software Assurance
SISAC-09
On-Orbit Anomaly Detection
SISAC-10
GNSS and Position, Navigation and Timing Resilience
SISAC-11
Space System Incident Response
SISAC-12
Threat Information Production and Quality
SISAC-13
Insider Threat Programme
SISAC-14
Vulnerability Management for Space Systems
SISAC-15
Tabletop and Red Team Exercises
SISAC-16
Cross Sector and Critical Infrastructure Coordination
SISAC-17
Encryption Key Lifecycle for Space Systems
SISAC-18
User Terminal and Edge Device Security
SISAC-19
Launch Phase Cybersecurity
SISAC-20
Metrics, Maturity and Continuous Improvement
ST-1
Satellite Cyber Intrusion
ST-2
On-Orbit Interference
ST-3
Anti-Satellite Weapons
ST-4
Space Debris as Threat
TI-1
STIX Framework for Space
TI-2
TAXII Transport Protocol
TI-4
Threat Correlation and Analysis
Show the 4 you already have
GT-2
Physical Security Threats
GT-3
Supply Chain Compromise
GT-4
Social Engineering Attacks
TI-3
Indicator of Compromise Sharing

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 27011:2024 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition