16% of ISO 27018:2019 you already have
NIST SP 800-171A already covers about 16% of ISO 27018:2019, leaving
67 of 80 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 67
No control in NIST SP 800-171A
maps directly to one in ISO 27018:2019. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST SP 800-171A reaches these. This is the list to scope.
10.1Cryptographic controls
10.1.1Policy on the use of cryptographic controls
11.2.1Equipment siting and protection
11.2.2Supporting utilities
11.2.4Equipment maintenance
11.2.6Security of equipment and assets off-premises
11.2.7Secure disposal or re-use of equipment
11.2.8Unattended user equipment
11.2.9Clear desk and clear screen policy
12.1Operational procedures and responsibilities
12.1.1Documented operating procedures
12.1.3Capacity management
12.1.4Separation of development, testing and operational environments
12.4.2Protection of log information
12.4.3Administrator and operator logs
12.4.4Clock synchronization
12.5Control of operational software
12.7Information systems audit considerations ISO/IEC 27018:2019
13.2.1Information transfer policies and procedures
13.2.2Agreements on information transfer
13.2.3Electronic messaging
16.1Management of information security incidents and improvements
16.1.1Responsibilities and procedures
16.1.3Reporting information security weaknesses
16.1.4Assessment of and decision on information security events
16.1.5Response to information security incidents
16.1.6Learning from information security incidents
16.1.7Collection of evidence
18.1Compliance with legal and contractual requirements
18.2Information security reviews
18.2.1Independent review of information security
18.2.2Compliance with security policies and standards
18.2.3Technical compliance review
4.1Structure of this document
5.1Management direction for information security
5.1.1Policies for information security
5.1.2Review of the policies for information security
6.1.1Information security roles and responsibilities
6.1.3Contact with authorities
6.1.4Contact with special interest groups
7.2.1Management responsibilities
7.2.2Informationa8096b2fa1f5/iso-iec-27018-2019
7.2.3Disciplinary process
7.3Termination and change of employment
9.1Business requirements of access control
9.2.1User registration and de-registration
9.2.4Management of secret authentication information of users
9.2.5Review of user access rights
9.2.6Removal or adjustment of access rights
9.3.1Use of secret authentication information
9.4System and application access control
9.4.1Information access restriction
9.4.2Secure log-on procedures
9.4.3Password management system
9.4.4Use of privileged utility programs
Show the 13 you already have
12.2Protection from malware
12.4Logging and monitoring
12.6Technical vulnerability management
13.1Network security management
13.2.4Confidentiality or non-disclosure agreements
16.1.2Reporting information security events
6.1.2Segregation of duties
9.2User access management
9.2.2User access provisioning
9.2.3Management of privileged access rights
9.4.5Access control to program source code
How this is calculated
Already covered means a mapping runs from a control in NIST SP 800-171A to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition