Framework overlap

Does AICPA Privacy Management Framework (PMF) cover Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134)?

You hold AICPA Privacy Management Framework (PMF) and have been told to do Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134). Here is how much overlaps, control by control.

65% of Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134) you already have

AICPA Privacy Management Framework (PMF) already covers about 65% of Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), leaving 7 of 20 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 7

No control in AICPA Privacy Management Framework (PMF) maps directly to one in Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in AICPA Privacy Management Framework (PMF) reaches these. This is the list to scope.

SD134-1
Scope and Application
SD134-12
Third-Party Disclosure
SD134-15
Subscriber Rights
SD134-18
Training and Awareness
SD134-19
MPTC Reporting
SD134-2
Definitions of Personal Data
SD134-20
Penalties and Enforcement
Show the 13 you already have
SD134-10
Retention Limitation
SD134-11
Secure Disposal
SD134-13
Cross-Border Transfer
SD134-14
Processor Oversight
SD134-16
Complaint Handling
SD134-17
Incident Notification
SD134-3
Lawful Collection
SD134-4
Consent Requirements
SD134-5
Purpose Limitation
SD134-6
Data Minimisation
SD134-7
Accuracy and Quality
SD134-8
Security Safeguards
SD134-9
Access Control

How this is calculated

Already covered means a mapping runs from a control in AICPA Privacy Management Framework (PMF) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition