Standards Comparison

    ISO 27032

    Voluntary
    2012

    International guidelines for Internet cybersecurity collaboration

    VS

    EN 1090

    Mandatory
    2009

    EU standard for execution of structural steel and aluminium.

    Quick Verdict

    ISO 27032 provides voluntary cybersecurity guidelines for internet risks across industries globally, while EN 1090 mandates CE marking and FPC for structural steel/aluminium in EU construction. Organizations adopt ISO 27032 for resilience; EN 1090 for legal market access.

    Cybersecurity

    ISO 27032

    ISO/IEC 27032:2023 Cybersecurity – Guidelines for Internet Security

    Cost
    €€€
    Complexity
    Medium
    Implementation Time
    6-12 months

    Key Features

    • Multi-stakeholder collaboration across cyberspace ecosystems
    • Guidelines bridging siloed security domains
    • Risk assessment for Internet-specific threats
    • Annex mapping to ISO 27002 controls
    • Emphasis on detection and incident coordination
    Structural Metalwork

    EN 1090

    EN 1090 Execution of steel and aluminium structures

    Cost
    €€€€
    Complexity
    High
    Implementation Time
    6-12 months

    Key Features

    • Risk-based Execution Classes (EXC1-EXC4)
    • Factory Production Control (FPC) certification
    • CE marking under CPR for market access
    • Welding quality management via ISO 3834
    • Material traceability and NDT inspection requirements

    Detailed Analysis

    A comprehensive look at the specific requirements, scope, and impact of each standard.

    ISO 27032 Details

    What It Is

    ISO/IEC 27032:2023 is an international guidelines standard titled Cybersecurity – Guidelines for Internet Security. It provides non-certifiable guidance for managing Internet security risks in interconnected ecosystems, emphasizing multi-stakeholder collaboration. Its risk-based approach connects information security, network security, Internet security, and critical infrastructure protection.

    Key Components

    • Stakeholder roles and collaboration frameworks
    • Risk assessment, threat modeling, incident management
    • Controls mapped to ISO/IEC 27002 in Annex A (no fixed control count)
    • Principles of trust, transparency, PDCA cycle
    • Guidance-only model, integrates with ISO 27001 ISMS

    Why Organizations Use It

    • Reduces ecosystem risks, shortens incident dwell time
    • Aids regulatory alignment (e.g., NIS2, GDPR intersections)
    • Enhances resilience, stakeholder trust, competitive edge
    • Streamlines vendor management, operational efficiency

    Implementation Overview

    Phased approach: gap analysis, risk prioritization, controls deployment, monitoring. Suited for all sizes/industries with online presence; no certification required, focuses on continuous improvement via audits and exercises. (178 words)

    EN 1090 Details

    What It Is

    EN 1090 is a harmonized European standard family (EN 1090-1, -2, -3) under the Construction Products Regulation (CPR). It governs execution and conformity assessment of structural steel and aluminium components for construction works. Primary purpose: ensure safe fabrication, assembly, and CE marking via risk-based Execution Classes (EXC1–EXC4).

    Key Components

    • **EN 1090-1Conformity assessment, Factory Production Control (FPC) certification.
    • **EN 1090-2/-3Technical rules for steel/aluminium (welding, tolerances, corrosion protection).
    • Core pillars: material traceability, welding (ISO 3834), inspection/NDT, tolerances.
    • Notified Body certification with ongoing surveillance.

    Why Organizations Use It

    Mandatory for EU/EEA market access via CE marking; reduces liability, ensures compliance. Benefits: risk mitigation, quality consistency, competitive tenders. Builds stakeholder trust through traceability and certified capability.

    Implementation Overview

    Phased: gap analysis, FPC design, personnel training (welding coordinators), NB audits. Applies to fabricators globally targeting Europe; 6-12 months typical, scales with EXC and size.

    Key Differences

    Scope

    ISO 27032
    Internet cybersecurity guidelines in cyberspace
    EN 1090
    Steel/aluminium structural components execution

    Industry

    ISO 27032
    All sectors with online presence, global
    EN 1090
    Construction/fabrication, EU/EEA market

    Nature

    ISO 27032
    Voluntary informative guidance, non-certifiable
    EN 1090
    Harmonized standard, mandatory CE marking

    Testing

    ISO 27032
    Risk assessments, internal audits, exercises
    EN 1090
    FPC certification, NB audits, surveillance

    Penalties

    ISO 27032
    No legal penalties, reputational risk
    EN 1090
    Market exclusion, fines, legal liability

    Frequently Asked Questions

    Common questions about ISO 27032 and EN 1090

    ISO 27032 FAQ

    EN 1090 FAQ

    You Might also be Interested in These Articles...

    Run Maturity Assessments with GRADUM

    Transform your compliance journey with our AI-powered assessment platform

    Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.

    100+ Standards & Regulations
    AI-Powered Insights
    Collaborative Assessments
    Actionable Recommendations

    Check out these other Gradum.io Standards Comparison Pages