Security convergence brings individual PAP systems under security risk management principles and ties them into the wider security systems and the risk management of the whole enterprise as one managed process. Physical protection now depends heavily on IT networks, so security systems should not be put on the corporate network unless they can be secured physically and technically against deliberate or accidental compromise, because such systems may turn into the soft spot an attacker exploits to learn about the organization or disable protection; the added risks of using ICT should be weighed against its benefits. ISO/IEC 27001:2005 and ANSI/ASIS/BSI BCM.01-2010 can be run alongside this standard in one converged system under SPC.1-2009. Convergence should establish: a cost-effective strategy protecting people, information and property across functions; governance with top management commitment and clear ownership and accountability for the converged programme; one cross-discipline risk assessment and management framework for all security risks; a risk process that watches every security control and reports, in one place, weaknesses, vulnerabilities, attacks and failures of systems; continuous watch on how risks in IT and communications are shifting; measurement of how each PPS performs on its own, how they perform together, and how asset protection performs across all risk controls; a security risk framework working with the organization's wider risk view; strategies for a unified response to attacks that mitigate consequences and evaluate and report incident and response to strengthen controls; and a framework integrating people, information, technology and procedures.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.