26% of ISO 27799 you already have
SASB Standards already covers about 26% of ISO 27799, leaving
34 of 46 controls as genuinely new work.
Already covered 0
Likely covered 12
New work 34
No control in SASB Standards
maps directly to one in ISO 27799. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in SASB Standards reaches these. This is the list to scope.
ISO27799-10Contingency planning for ePHI
ISO27799-10.1Operational Procedures for Clinical Systems
ISO27799-10.2Backup of Health Records
ISO27799-10.3Audit Logging in Clinical Systems
ISO27799-10.4Anti-malware on Clinical Endpoints
ISO27799-11Business associate management
ISO27799-11.1Access Control to Health Records
ISO27799-11.2User Authentication for Clinicians
ISO27799-11.3Remote Access to Clinical Systems
ISO27799-12.1Cryptography for Health Information
ISO27799-13Automatic logoff and session management
ISO27799-13.1Communications Security and Health Interfaces
ISO27799-14Audit controls and monitoring
ISO27799-14.1Secure Development of Clinical Applications
ISO27799-15Integrity controls for ePHI
ISO27799-15.1Supplier Relationships for Health IT
ISO27799-16.1Incident Management for Health Data Breach
ISO27799-17.1Continuity of Clinical Operations
ISO27799-18Workstation security and use policies
ISO27799-18.1Compliance with Health Sector Regulations
ISO27799-19Device and media controls
ISO27799-20Disposal and re-use procedures
ISO27799-21Security and privacy policies
ISO27799-22Documentation and record retention
ISO27799-23Compliance evaluation and review
ISO27799-24Incident reporting procedures
ISO27799-6.1Health Information Security Policy
ISO27799-6.2Health Information Governance Committee
ISO27799-7.1Asset Inventory for Health Records
ISO27799-7.2Classification of Health Information
ISO27799-8.1Workforce Security in Healthcare
ISO27799-8.2Health Information Awareness Training
ISO27799-9.1Physical Security in Healthcare Facilities
ISO27799-9.2Equipment Security and Medical Devices
Show the 12 you already have
ISO27799-01ePHI access controls and authorization
ISO27799-02ePHI encryption at rest and in transit
ISO27799-03Minimum necessary standard enforcement
ISO27799-04Patient data de-identification procedures
ISO27799-05Audit trail for ePHI access
ISO27799-06Security management process and risk analysis
ISO27799-07Workforce security and clearance procedures
ISO27799-08Information access management
ISO27799-09Security awareness and training program
ISO27799-12Unique user identification and authentication
ISO27799-16Transmission security and encryption
ISO27799-17Facility access controls
How this is calculated
Already covered means a mapping runs from a control in SASB Standards to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition