Framework overlap

Does OWASP API Security Top 10 cover ISO 27799?

You hold OWASP API Security Top 10 and have been told to do ISO 27799. Here is how much overlaps, control by control.

26% of ISO 27799 you already have

OWASP API Security Top 10 already covers about 26% of ISO 27799, leaving 34 of 46 controls as genuinely new work.

Already covered 0 Likely covered 12 New work 34

No control in OWASP API Security Top 10 maps directly to one in ISO 27799. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in OWASP API Security Top 10 reaches these. This is the list to scope.

ISO27799-10
Contingency planning for ePHI
ISO27799-10.1
Operational Procedures for Clinical Systems
ISO27799-10.2
Backup of Health Records
ISO27799-10.3
Audit Logging in Clinical Systems
ISO27799-10.4
Anti-malware on Clinical Endpoints
ISO27799-11
Business associate management
ISO27799-11.1
Access Control to Health Records
ISO27799-11.2
User Authentication for Clinicians
ISO27799-11.3
Remote Access to Clinical Systems
ISO27799-12.1
Cryptography for Health Information
ISO27799-13
Automatic logoff and session management
ISO27799-13.1
Communications Security and Health Interfaces
ISO27799-14
Audit controls and monitoring
ISO27799-14.1
Secure Development of Clinical Applications
ISO27799-15
Integrity controls for ePHI
ISO27799-15.1
Supplier Relationships for Health IT
ISO27799-16.1
Incident Management for Health Data Breach
ISO27799-17.1
Continuity of Clinical Operations
ISO27799-18
Workstation security and use policies
ISO27799-18.1
Compliance with Health Sector Regulations
ISO27799-19
Device and media controls
ISO27799-20
Disposal and re-use procedures
ISO27799-21
Security and privacy policies
ISO27799-22
Documentation and record retention
ISO27799-23
Compliance evaluation and review
ISO27799-24
Incident reporting procedures
ISO27799-6.1
Health Information Security Policy
ISO27799-6.2
Health Information Governance Committee
ISO27799-7.1
Asset Inventory for Health Records
ISO27799-7.2
Classification of Health Information
ISO27799-8.1
Workforce Security in Healthcare
ISO27799-8.2
Health Information Awareness Training
ISO27799-9.1
Physical Security in Healthcare Facilities
ISO27799-9.2
Equipment Security and Medical Devices
Show the 12 you already have
ISO27799-01
ePHI access controls and authorization
ISO27799-02
ePHI encryption at rest and in transit
ISO27799-03
Minimum necessary standard enforcement
ISO27799-04
Patient data de-identification procedures
ISO27799-05
Audit trail for ePHI access
ISO27799-06
Security management process and risk analysis
ISO27799-07
Workforce security and clearance procedures
ISO27799-08
Information access management
ISO27799-09
Security awareness and training program
ISO27799-12
Unique user identification and authentication
ISO27799-16
Transmission security and encryption
ISO27799-17
Facility access controls

How this is calculated

Already covered means a mapping runs from a control in OWASP API Security Top 10 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition