23% of AS9100D you already have
Monetary Authority of Singapore Technology Risk Management Guidelines already covers about 23% of AS9100D, leaving
47 of 61 controls as genuinely new work.
Already covered 4
Likely covered 10
New work 47
What is genuinely new work
Nothing in Monetary Authority of Singapore Technology Risk Management Guidelines reaches these. This is the list to scope.
8.3Statement of Applicability linkage
AS9100D-10.1General Improvement
AS9100D-10.3Continual Improvement
AS9100D-4.1Understanding the Organization and Its Context
AS9100D-4.2Understanding Needs and Expectations of Interested Parties
AS9100D-4.3Determining the Scope of the QMS
AS9100D-4.4Quality Management System and Its Processes
AS9100D-5.1.2Customer Focus and Product Safety
AS9100D-5.2Quality Policy
AS9100D-5.3Organizational Roles, Responsibilities, and Authorities
AS9100D-6.1Risk-Based Thinking and Operational Risk
AS9100D-6.2Quality Objectives and Planning to Achieve Them
AS9100D-6.3Planning of Changes
AS9100D-7.1.5Monitoring and Measuring Resources
AS9100D-7.1.6Organizational Knowledge
AS9100D-7.5Documented Information
AS9100D-8.1.2Operational Risk Management
AS9100D-8.1.3Product Safety
AS9100D-8.1.4Prevention of Counterfeit Parts
AS9100D-8.2.3Review of Requirements for Products and Services
AS9100D-8.3Design and Development of Products
AS9100D-8.5Production and Service Provision
AS9100D-8.5.1Control of Production and Service Provision
AS9100D-8.5.1.3Production Process Verification
AS9100D-8.5.4Preservation - Including FOD Prevention
AS9100D-8.5.6Control of Changes
AS9100D-8.6Release of Products and Services
AS9100D-8.7Control of Nonconforming Outputs
AS9100D-9.1Monitoring, Measurement, Analysis, Evaluation
AS9100D-9.2Internal Audit
AS9100D-9.3Management Review
ISO27003-4.1Understanding the Organization and Its Context
ISO27003-4.4Information Security Management System
ISO27003-5.2Information Security Policy
ISO27003-5.3Organizational Roles, Responsibilities, and Authorities
ISO27003-6.2Information Security Objectives and Planning to Achieve Them
ISO27003-7.4Communication
ISO27003-7.5Documented Information
ISO27003-9.1Monitoring, Measurement, Analysis and Evaluation
ISO27003-9.2Internal Audit
ISO27003-9.3Management Review
Show the 14 you already have
AS9100D-8.1Operational Planning and Control
ISO27003-4.3Determining the Scope of the ISMS
ISO27003-6.1Actions to Address Risks and Opportunities
ISO27003-8.3Information Security Risk Treatment
8.5Control effectiveness review
AS9100D-10.2Nonconformity and Corrective Action
AS9100D-5.1Leadership and Commitment
AS9100D-8.4Control of Externally Provided Processes, Products, Services
ISO27003-10.1Continual Improvement
ISO27003-10.2Nonconformity and Corrective Action
ISO27003-4.2Understanding Needs and Expectations of Interested Parties
ISO27003-5.1Leadership and Commitment
ISO27003-8.1Operational Planning and Control
ISO27003-8.2Information Security Risk Assessment
How this is calculated
Already covered means a mapping runs from a control in Monetary Authority of Singapore Technology Risk Management Guidelines to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition