Use the mapping for the gap analysis (chapter 14). Search by requirement area or control. The yellow rows mark where ISO 27001 needs supplementing to meet the law in full.
| Requirement area | ISO 27001 controls | What it covers | Coverage |
|---|---|---|---|
| 1 Risk analysis and security policies | 6.1, 8.2, 8.3, A.5.7 | Risk assessment, risk treatment, threat intelligence.The whole entity approach of the law may require broader scope than the chosen ISMS scope. | High |
| 2 Incident response | A.5.24-A.5.28, A.8.16 | Incident process, reporting, monitoring.The 24 hour requirement and the staged model call for specific process adjustment. | Medium |
| 3 Operational continuity | A.5.29, A.5.30, A.8.13-14 | Continuity plan, ICT readiness, backup.The crisis management requirement of the law may reach beyond pure IT continuity. | High |
| 4 Supply chain security | A.5.19-A.5.23 | Supplier policy, review, cloud services.Explicit SBOM and exit strategies are absent from ISO and have to be added. | Medium |
| 5 Security in acquisition, development and maintenance | A.8.9, A.8.25-A.8.31 | Configuration, secure development, vulnerability management.Specific vulnerability management requirements may need formalising. | High |
| 6 Follow up on the effectiveness of measures | 9.1-9.3, 10.1-10.2 | Measurement, internal audit, improvement.Minimal. The ISO 27001 requirements are robust here. | High |
| 7 Cyber hygiene and training | A.6.3, A.7.2-A.7.3 | Awareness, training, basic hygiene.The specific requirement on training the leadership is more precise in the law than in ISO. | Medium |
| 8 Cryptography | A.8.24 | Cryptography policy and key management.Minimal. The cryptography policy normally covers this. | High |
| 9 Personnel security and access control | A.5.15-A.5.18, A.6.1-A.6.6, A.8.2-A.8.5 | Access, HR security, identity management.Minimal. | High |
| 10 Multi factor authentication and secure communication | A.8.5 | Authentication, secure communication solutions.The explicit requirements on MFA and emergency communication reach beyond the general ISO requirement. | Medium |
Inga träffar. Prova ett annat sökord.
The full mapping as an Excel file is among the downloads on Verktygsboxen (Control mapping ISO 27001 to the Cybersecurity Act, Excel).