Framework overlap

Does OWASP MASVS cover ISO 27799?

You hold OWASP MASVS and have been told to do ISO 27799. Here is how much overlaps, control by control.

26% of ISO 27799 you already have

OWASP MASVS already covers about 26% of ISO 27799, leaving 34 of 46 controls as genuinely new work.

Already covered 7 Likely covered 5 New work 34

What is genuinely new work

Nothing in OWASP MASVS reaches these. This is the list to scope.

ISO27799-10
Contingency planning for ePHI
ISO27799-10.1
Operational Procedures for Clinical Systems
ISO27799-10.2
Backup of Health Records
ISO27799-10.3
Audit Logging in Clinical Systems
ISO27799-10.4
Anti-malware on Clinical Endpoints
ISO27799-11
Business associate management
ISO27799-11.1
Access Control to Health Records
ISO27799-11.2
User Authentication for Clinicians
ISO27799-11.3
Remote Access to Clinical Systems
ISO27799-12.1
Cryptography for Health Information
ISO27799-13
Automatic logoff and session management
ISO27799-13.1
Communications Security and Health Interfaces
ISO27799-14
Audit controls and monitoring
ISO27799-14.1
Secure Development of Clinical Applications
ISO27799-15
Integrity controls for ePHI
ISO27799-15.1
Supplier Relationships for Health IT
ISO27799-16.1
Incident Management for Health Data Breach
ISO27799-17.1
Continuity of Clinical Operations
ISO27799-18
Workstation security and use policies
ISO27799-18.1
Compliance with Health Sector Regulations
ISO27799-19
Device and media controls
ISO27799-20
Disposal and re-use procedures
ISO27799-21
Security and privacy policies
ISO27799-22
Documentation and record retention
ISO27799-23
Compliance evaluation and review
ISO27799-24
Incident reporting procedures
ISO27799-6.1
Health Information Security Policy
ISO27799-6.2
Health Information Governance Committee
ISO27799-7.1
Asset Inventory for Health Records
ISO27799-7.2
Classification of Health Information
ISO27799-8.1
Workforce Security in Healthcare
ISO27799-8.2
Health Information Awareness Training
ISO27799-9.1
Physical Security in Healthcare Facilities
ISO27799-9.2
Equipment Security and Medical Devices
Show the 12 you already have
ISO27799-01
ePHI access controls and authorization
ISO27799-02
ePHI encryption at rest and in transit
ISO27799-05
Audit trail for ePHI access
ISO27799-08
Information access management
ISO27799-12
Unique user identification and authentication
ISO27799-16
Transmission security and encryption
ISO27799-17
Facility access controls
ISO27799-03
Minimum necessary standard enforcement
ISO27799-04
Patient data de-identification procedures
ISO27799-06
Security management process and risk analysis
ISO27799-07
Workforce security and clearance procedures
ISO27799-09
Security awareness and training program

How this is calculated

Already covered means a mapping runs from a control in OWASP MASVS to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition