Framework overlap

Does NIST SP 1800-32 cover AS9100D:2016?

You hold NIST SP 1800-32 and have been told to do AS9100D:2016. Here is how much overlaps, control by control.

26% of AS9100D:2016 you already have

NIST SP 1800-32 already covers about 26% of AS9100D:2016, leaving 31 of 42 controls as genuinely new work.

Already covered 5 Likely covered 6 New work 31

What is genuinely new work

Nothing in NIST SP 1800-32 reaches these. This is the list to scope.

7.5
Threat assessment
8.3
Statement of Applicability linkage
AS9100D-5.2
Quality Policy
AS9100D-5.3
Organizational Roles, Responsibilities, and Authorities
AS9100D-8.3
Design and Development of Products
AS9100D-8.5
Production and Service Provision
AS9100D-8.7
Control of Nonconforming Outputs
AS9100D2016-10.1
Improvement
AS9100D2016-10.2
Nonconformity and Corrective Action
AS9100D2016-4.4
QMS and Its Processes
AS9100D2016-5.2
Quality Policy
AS9100D2016-5.3
Roles, Responsibilities, Authorities
AS9100D2016-6.1
Actions to Address Risks and Opportunities
AS9100D2016-6.2
Quality Objectives and Planning
AS9100D2016-7.5
Documented Information
AS9100D2016-8.1
Operational Planning and Control
AS9100D2016-8.1.1
Operational Risk Management
AS9100D2016-8.1.3
Product Safety
AS9100D2016-8.1.4
Prevention of Counterfeit Parts
AS9100D2016-8.2
Requirements for Products and Services
AS9100D2016-8.3.4
Design and Development Controls
AS9100D2016-8.4.1
Supplier Selection and Approval
AS9100D2016-8.4.2
Type and Extent of Control of Suppliers
AS9100D2016-8.4.3
Information for External Providers (Flowdown)
AS9100D2016-8.5.2
Identification and Traceability
AS9100D2016-8.5.3
Property Belonging to Customers/External Providers
AS9100D2016-8.5.5
Post-Delivery Activities
AS9100D2016-9.1.2
Customer Satisfaction
AS9100D2016-9.2
Internal Audit Program
ISO27003-5.2
Information Security Policy
ISO27003-5.3
Organizational Roles, Responsibilities, and Authorities
Show the 11 you already have
AS9100D-8.1
Operational Planning and Control
AS9100D-8.4
Control of Externally Provided Processes, Products, Services
ISO27003-8.1
Operational Planning and Control
ISO27003-8.2
Information Security Risk Assessment
ISO27003-8.3
Information Security Risk Treatment
8.5
Control effectiveness review
9.1
Risk communication and consultation
AS9100D-5.1
Leadership and Commitment
AS9100D2016-5.1
Leadership and Commitment
AS9100D2016-8.1.2
Configuration Management
ISO27003-5.1
Leadership and Commitment

How this is calculated

Already covered means a mapping runs from a control in NIST SP 1800-32 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition