21% of ISO/IEC 27003:2017 you already have
MITRE D3FEND already covers about 21% of ISO/IEC 27003:2017, leaving
57 of 72 controls as genuinely new work.
Already covered 0
Likely covered 15
New work 57
No control in MITRE D3FEND
maps directly to one in ISO/IEC 27003:2017. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in MITRE D3FEND reaches these. This is the list to scope.
27003-10.1Nonconformity and Corrective Action
27003-10.2Continual Improvement
27003-4.1Understanding the Organization and Its Context
27003-4.2Interested Parties and Their Requirements
27003-4.3Determining ISMS Scope
27003-5.1Leadership and Commitment
27003-5.2Information Security Policy
27003-5.3Roles, Responsibilities, Authorities
27003-6.1.1Actions to Address Risks and Opportunities
27003-6.1.2Information Security Risk Assessment
27003-6.1.3Information Security Risk Treatment
27003-6.2Information Security Objectives
27003-7.5Documented Information
27003-8.1Operational Planning and Control
27003-8.2Risk Assessment Performance
27003-8.3Risk Treatment Implementation
27003-9.1Monitoring, Measurement, Analysis, Evaluation
27003-9.3Management Review
AS9100D-10.1General Improvement
AS9100D-10.3Continual Improvement
AS9100D-4.1Understanding the Organization and Its Context
AS9100D-4.2Understanding Needs and Expectations of Interested Parties
AS9100D-4.3Determining the Scope of the QMS
AS9100D-4.4Quality Management System and Its Processes
AS9100D-5.2Quality Policy
AS9100D-5.3Organizational Roles, Responsibilities, and Authorities
AS9100D-6.1Risk-Based Thinking and Operational Risk
AS9100D-6.2Quality Objectives and Planning to Achieve Them
AS9100D-6.3Planning of Changes
AS9100D-7.5Documented Information
AS9100D-8.3Design and Development of Products
AS9100D-8.7Control of Nonconforming Outputs
AS9100D-9.1Monitoring, Measurement, Analysis, Evaluation
AS9100D-9.2Internal Audit
AS9100D-9.3Management Review
ISO27003-4.1Understanding the Organization and Its Context
ISO27003-4.4Information Security Management System
ISO27003-5.1Leadership and Commitment
ISO27003-5.2Information Security Policy
ISO27003-5.3Organizational Roles, Responsibilities, and Authorities
ISO27003-6.2Information Security Objectives and Planning to Achieve Them
ISO27003-7.4Communication
ISO27003-7.5Documented Information
ISO27003-9.1Monitoring, Measurement, Analysis and Evaluation
ISO27003-9.2Internal Audit
ISO27003-9.3Management Review
Show the 15 you already have
8.3Statement of Applicability linkage
8.5Control effectiveness review
AS9100D-10.2Nonconformity and Corrective Action
AS9100D-5.1Leadership and Commitment
AS9100D-8.1Operational Planning and Control
AS9100D-8.4Control of Externally Provided Processes, Products, Services
AS9100D-8.5Production and Service Provision
ISO27003-10.1Continual Improvement
ISO27003-10.2Nonconformity and Corrective Action
ISO27003-4.2Understanding Needs and Expectations of Interested Parties
ISO27003-4.3Determining the Scope of the ISMS
ISO27003-6.1Actions to Address Risks and Opportunities
ISO27003-8.1Operational Planning and Control
ISO27003-8.2Information Security Risk Assessment
ISO27003-8.3Information Security Risk Treatment
How this is calculated
Already covered means a mapping runs from a control in MITRE D3FEND to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition