Toolbox

All tools in the Toolbox

Appendix B · Reference

Control mapping

ISO 27001:2022 mapped against the ten requirement areas of the Cybersecurity Act. A mature management system covers an estimated 70 to 80 per cent of what the law requires. The table shows where, and where the gaps are.

Use the mapping for the gap analysis (chapter 14). Search by requirement area or control. The yellow rows mark where ISO 27001 needs supplementing to meet the law in full.

Requirement areaISO 27001 controlsWhat it coversCoverage
1 Risk analysis and security policies 6.1, 8.2, 8.3, A.5.7 Risk assessment, risk treatment, threat intelligence.The whole entity approach of the law may require broader scope than the chosen ISMS scope. High
2 Incident response A.5.24-A.5.28, A.8.16 Incident process, reporting, monitoring.The 24 hour requirement and the staged model call for specific process adjustment. Medium
3 Operational continuity A.5.29, A.5.30, A.8.13-14 Continuity plan, ICT readiness, backup.The crisis management requirement of the law may reach beyond pure IT continuity. High
4 Supply chain security A.5.19-A.5.23 Supplier policy, review, cloud services.Explicit SBOM and exit strategies are absent from ISO and have to be added. Medium
5 Security in acquisition, development and maintenance A.8.9, A.8.25-A.8.31 Configuration, secure development, vulnerability management.Specific vulnerability management requirements may need formalising. High
6 Follow up on the effectiveness of measures 9.1-9.3, 10.1-10.2 Measurement, internal audit, improvement.Minimal. The ISO 27001 requirements are robust here. High
7 Cyber hygiene and training A.6.3, A.7.2-A.7.3 Awareness, training, basic hygiene.The specific requirement on training the leadership is more precise in the law than in ISO. Medium
8 Cryptography A.8.24 Cryptography policy and key management.Minimal. The cryptography policy normally covers this. High
9 Personnel security and access control A.5.15-A.5.18, A.6.1-A.6.6, A.8.2-A.8.5 Access, HR security, identity management.Minimal. High
10 Multi factor authentication and secure communication A.8.5 Authentication, secure communication solutions.The explicit requirements on MFA and emergency communication reach beyond the general ISO requirement. Medium

The full mapping as an Excel file is among the downloads on Verktygsboxen (Control mapping ISO 27001 to the Cybersecurity Act, Excel).