Framework overlap

Does SEC Climate Disclosure Rule cover BSI IT-Grundschutz?

You hold SEC Climate Disclosure Rule and have been told to do BSI IT-Grundschutz. Here is how much overlaps, control by control.

24% of BSI IT-Grundschutz you already have

SEC Climate Disclosure Rule already covers about 24% of BSI IT-Grundschutz, leaving 42 of 55 controls as genuinely new work.

Already covered 3 Likely covered 10 New work 42

What is genuinely new work

Nothing in SEC Climate Disclosure Rule reaches these. This is the list to scope.

APP.1.1
Office Products
APP.3.1
Web Applications
BSI-01
Account management and provisioning
BSI-02
Access enforcement and least privilege
BSI-06
Identity proofing and verification
BSI-07
Boundary protection and segmentation
BSI-08
Cryptographic protection of data
BSI-09
Denial-of-service protection
BSI-10
Transmission confidentiality and integrity
BSI-11
Session management controls
BSI-12
Network monitoring and defense
BSI-16
Threat intelligence integration
BSI-19
Incident handling and containment
BSI-22
Lessons learned and improvement
BSI-25
Security impact analysis
BSI-27
Software usage restrictions
BSI-28
Audit event logging and storage
BSI-29
Audit record review and analysis
BSI-30
Time synchronization
BSI-31
Audit log protection and retention
BSI-32
Accountability and non-repudiation
CON.1
Crypto Concept
CON.2
Data Protection
CON.3
Data Backup Concept
CON.8
Software Development
DER.1
Detection of Security-Relevant Events
DER.2.1
Security Incident Handling
DER.4
Business Continuity Management
INF.1
General Building
ISMS.1
Security Management
NET.1.1
Network Architecture and Design
OPS.1.1.2
Proper IT Administration
OPS.1.1.3
Patch and Change Management
OPS.1.1.5
Logging
OPS.1.2.4
Teleworking
OPS.2.2
Cloud Usage
ORP.1
Organisation
ORP.2
Personnel
ORP.3
Awareness and Training
ORP.4
Identity and Access Management
SYS.1.1
General Server
SYS.2.1
General Client
Show the 13 you already have
BSI-13
Risk assessment procedures
BSI-15
Security categorization
BSI-17
Continuous monitoring strategy
BSI-03
Multi-factor authentication requirements
BSI-04
Remote access controls
BSI-05
Wireless access restrictions
BSI-14
Vulnerability scanning and management
BSI-18
Incident response planning and testing
BSI-20
Incident reporting and notification
BSI-21
Forensic analysis capabilities
BSI-23
Baseline configuration establishment
BSI-24
Configuration change control
BSI-26
System component inventory

How this is calculated

Already covered means a mapping runs from a control in SEC Climate Disclosure Rule to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition