21% of FFIEC IT Examination Handbook you already have
Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) already covers about 21% of FFIEC IT Examination Handbook, leaving
62 of 78 controls as genuinely new work.
Already covered 1
Likely covered 15
New work 62
What is genuinely new work
Nothing in Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) reaches these. This is the list to scope.
FFIEC-01Information security program management
FFIEC-02Board and management oversight
FFIEC-04Security policy framework
FFIEC-13Third-party dependency management
FFIEC-15Communication and escalation procedures
FFIEC-16Due diligence and onboarding
FFIEC-17Contractual security requirements
FFIEC-19Concentration risk management
FFIEC-21Incident detection and classification
FFIEC-22Incident response and containment
IS-II.A.1Board Oversight of Information Security
IS-II.A.2Senior Management Responsibilities
IS-II.B.1Information Security Culture
IS-II.C.1Information Security Roles and Responsibilities
IS-III.A.1Information Security Risk Management Framework
IS-III.B.2Risk Measurement and Analysis
IS-III.B.3Risk Mitigation Strategy
IS-III.C.1Risk Monitoring and Reporting
IS-III.D.1Information Security Strategy
IS-IV.A.1Inventory and Classification of Information Assets
IS-IV.A.2Data Flow Diagrams
IS-IV.B.1Identity and Access Management Program
IS-IV.B.2Authentication Controls
IS-IV.B.3Privileged Access Management
IS-IV.B.4Access Reviews and Recertification
IS-IV.B.5Joiner Mover Leaver Process
IS-IV.C.1Network Security Architecture
IS-IV.C.2Firewall Configuration and Review
IS-IV.C.3Wireless Network Security
IS-IV.C.4Remote Access Security
IS-IV.D.1Endpoint Security Controls
IS-IV.D.2Mobile Device Management
IS-IV.D.3Removable Media Controls
IS-IV.E.1Secure Software Development Lifecycle
IS-IV.E.2Application Security Testing
IS-IV.E.3Application Change Management
IS-IV.F.1Encryption Standards and Key Management
IS-IV.F.2Data in Transit Encryption
IS-IV.F.3Data at Rest Encryption
IS-IX.A.1Third Party Risk Management
IS-IX.A.2Cloud Service Provider Oversight
IS-V.A.1IT Operations Management
IS-V.A.2Configuration Management
IS-V.B.1Vulnerability Management Program
IS-V.B.2Penetration Testing
IS-V.C.1Physical and Environmental Security
IS-VI.A.1Security Logging Standards
IS-VI.A.2Security Monitoring and SIEM
IS-VI.A.3Threat Intelligence
IS-VI.B.1User Behavior Analytics
IS-VII.A.1Incident Response Program
IS-VII.A.2Incident Detection and Classification
IS-VII.A.3Incident Response Testing and Exercises
IS-VII.A.4Notification of Customers Regulators and Law Enforcement
IS-VIII.A.1Business Continuity Integration
IS-VIII.A.2Backup and Recovery
IS-X.A.1Security Awareness Training
IS-X.B.1Independent Information Security Audit
IS-X.B.2Cybersecurity Assessment and Maturity
IS-XI.A.1Architecture and Operations Alignment
IS-XI.A.2Management Booklet Governance Alignment
Show the 16 you already have
FFIEC-05Roles and responsibilities definition
FFIEC-03Risk appetite and tolerance for IT risk
FFIEC-06Network security and segmentation
FFIEC-07Endpoint protection and detection
FFIEC-08Application security controls
FFIEC-09Encryption and key management
FFIEC-10Secure configuration standards
FFIEC-11Business continuity planning and testing
FFIEC-12Disaster recovery procedures
FFIEC-14Critical service identification
FFIEC-18Ongoing monitoring and assessment
FFIEC-20Exit strategy and transition planning
FFIEC-23Regulatory reporting requirements
FFIEC-24Customer notification procedures
FFIEC-25Post-incident review and improvement
IS-III.B.1Risk Identification
How this is calculated
Already covered means a mapping runs from a control in Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition