AS9100D - Aerospace Quality Management System
Context of the Organization (Clause 4)

AS9100D - Aerospace Quality Management System 8.1: Operational Planning and Control

Plan, implement, and control processes including operational risk management and configuration management

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 285 controls across 128 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 6 controls

  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-10 Secure configuration standards
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied

PCI P2PE · 4 controls

PCI PIN Security · 4 controls

PCI SSF · 4 controls

SASB Standards · 4 controls

API 1164 · 3 controls

  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)

BSI IT-Grundschutz · 3 controls

  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory

IEC 62443 · 3 controls

ISO 27005 · 3 controls

ISO 27019 · 3 controls

ISO 31000 · 3 controls

ISO/IEC 23894:2023 · 3 controls

Japan AI Guidelines · 3 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 3 controls

NIST SP 800-30 · 3 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

OSFI B-13 · 3 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OSFIB13-4 Third-Party Risk Management and Cloud

PSD2 SCA · 3 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs

Solvency II · 3 controls

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BMA-3 Operational Cyber Risk Management Programme
  • BMA-4 Chief Information Security Officer
  • CJIS-19 Supply Chain Risk Management
  • CJIS-7 Configuration Management

FISMA · 2 controls

FedRAMP Rev 5 · 2 controls

HKMA SPM · 2 controls

  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

IEEE 1686 · 2 controls

IEEE 7000 · 2 controls

ISO 27017 · 2 controls

ISO 27018 · 2 controls

ISO/IEC 27003:2017 · 2 controls

MTCS (Singapore) · 2 controls

NERC CIP · 2 controls

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NERCCIP-8 Supply Chain Risk Management (CIP-013)

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-190 · 2 controls

NIST SP 800-37 · 2 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 2 controls

  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

Open Banking Security · 2 controls

  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence

South Korea ISMS-P · 2 controls

  • SPS220-28 Annual Board Risk Management Declaration

GLBA · 1 control

  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

ISMAP (Japan) · 1 control

ISO 14001:2015 · 1 control

  • 8.1 Operational planning and control

ISO 14004:2016 · 1 control

  • 8.1 Operational planning and control

ISO 20000-1 · 1 control

ISO 22000:2018 · 1 control

  • 8.1 Operational planning and control

ISO 22301:2019 · 1 control

  • 8.1 Operational planning and control

ISO 22320:2018 · 1 control

ISO 27701:2019 · 1 control

  • 5.6.1 Operational planning and control

ISO 37001:2016 · 1 control

  • 8.1 Operational planning and control

ISO 37301:2021 · 1 control

  • 8.1 Operational planning and control

ISO 45001:2018 · 1 control

  • 8.1 Operational planning and control
  • 8.1 Operational planning and control

ISO 55001:2014 · 1 control

  • 8.1 Operational planning and control

ISO 9001:2015 · 1 control

  • 8.1 Operational planning and control

ISO/IEC 27400:2022 · 1 control

ISO/IEC 42001:2023 · 1 control

  • 8.1 Operational planning and control

ITIL 4 · 1 control

  • NIS2I-2 Policy, Risk Management, and Roles + Responsibilities

NIST SP 800-144 · 1 control

  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration

NIST SP 800-146 · 1 control

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security
  • ORSA-S1 ORSA Manual Section 1: Description of Insurer's Risk Management Framework
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • PSPF24-1 Security Culture, Governance, Risk Management
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • AIGF-1.1 Risk Management and Internal Controls
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Context of the Organization (Clause 4)

Query this from an agent

The graph holds this control, the 285 it maps to, and the evidence behind each claim, over MCP and REST.