Framework overlap

Does ISO/IEC 27400:2022 cover AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)?

You hold ISO/IEC 27400:2022 and have been told to do AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association). Here is how much overlaps, control by control.

43% of AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) you already have

ISO/IEC 27400:2022 already covers about 43% of AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association), leaving 21 of 37 controls as genuinely new work.

Already covered 9 Likely covered 7 New work 21

What is genuinely new work

Nothing in ISO/IEC 27400:2022 reaches these. This is the list to scope.

AWWA-1.4
Compliance and Regulatory Alignment
AWWA-3.3
Wireless Security
AWWA-G430-1
Cybersecurity Program Governance
AWWA-G430-11
Manual Operations Capability
AWWA-G430-13
Supply Chain and Vendor Risk
AWWA-G430-14
Personnel Security and Insider Threat
AWWA-G430-15
Cybersecurity Training for Operators
AWWA-G430-16
Logging and Audit
AWWA-G430-17
Physical Security of Cyber Assets
AWWA-G430-18
Configuration and Change Management for OT
AWWA-G430-19
AWIA Risk and Resilience Assessment Compliance
AWWA-G430-2
Asset Inventory and Classification
AWWA-G430-20
Information Sharing and Reporting
AWWA-G430-21
Cybersecurity Program Review
AWWA-G430-3
Risk Assessment for Water Systems
AWWA-G430-4
Network Segmentation IT/OT
AWWA-G430-5
Access Control for SCADA and Control Systems
AWWA-G430-6
Remote Access Management
AWWA-G430-7
Patch and Vulnerability Management
AWWA-G430-8
Malware Protection
AWWA-G430-9
Boundary Protection and Monitoring
Show the 16 you already have
AWWA-1.1
Security Policy and Governance
AWWA-1.3
Security Awareness and Training
AWWA-2.1
User Access Management
AWWA-2.2
Authentication Mechanisms
AWWA-2.4
Physical Access Controls
AWWA-3.2
Remote Access Security
AWWA-3.4
Encryption and Data Protection
AWWA-4.2
Patch Management
AWWA-4.3
Configuration Management
AWWA-1.2
Risk Assessment
AWWA-2.3
Account Management
AWWA-3.1
Network Segmentation
AWWA-4.1
Malware Protection
AWWA-4.4
Audit Logging and Monitoring
AWWA-G430-10
Incident Response for Water Utilities
AWWA-G430-12
Backup and Recovery for Control Systems

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 27400:2022 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition