Framework overlap

Does Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) cover NIST SP 1800-32?

You hold Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) and have been told to do NIST SP 1800-32. Here is how much overlaps, control by control.

30% of NIST SP 1800-32 you already have

Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) already covers about 30% of NIST SP 1800-32, leaving 31 of 44 controls as genuinely new work.

Already covered 0 Likely covered 13 New work 31

No control in Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) maps directly to one in NIST SP 1800-32. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) reaches these. This is the list to scope.

DER-DE-01
Continuous Monitoring of DER Communications
DER-DE-02
Logging and Audit Trail Collection
DER-DE-03
Integrity Monitoring of DER Settings
DER-GV-01
DER Cybersecurity Governance
DER-GV-02
Supply Chain Risk Management for DER
DER-ID-01
DER Asset Inventory
DER-ID-02
Data Flow Mapping for DER
DER-ID-03
DER Threat and Risk Assessment
DER-PR-01
Authentication for DER Communications
DER-PR-02
Secure Configuration of DER Devices
DER-PR-03
Network Segmentation for DER Operations
DER-PR-04
Cryptographic Protection of DER Communications
DER-PR-05
Identity and Access Management for DER Operators
DER-PR-06
Secure Firmware Update Process
DER-RC-01
Recovery Planning for DER
DER-RC-02
Backup and Configuration Restoration
DER-RC-03
Lessons Learned and Continuous Improvement
DER-RS-01
Incident Response for DER
DER-RS-02
Isolation and Containment Procedures
DER-RS-03
Communication with External Stakeholders
NIST1800-32-01
Critical asset identification and inventory
NIST1800-32-03
Security governance structure
NIST1800-32-04
Roles and responsibilities for critical systems
NIST1800-32-05
Security policy for operational technology
NIST1800-32-06
Physical and logical access controls
NIST1800-32-10
Revocation of access procedures
NIST1800-32-11
Security patch management for OT
NIST1800-32-12
Malware prevention for operational systems
NIST1800-32-15
Ports and services management
NIST1800-32-16
Incident response plan for operational disruptions
NIST1800-32-17
Recovery plan for critical systems
Show the 13 you already have
NIST1800-32-02
System security categorization
NIST1800-32-07
Personnel risk assessment
NIST1800-32-08
Electronic access perimeter management
NIST1800-32-09
Interactive remote access security
NIST1800-32-13
Network security monitoring
NIST1800-32-14
System security hardening
NIST1800-32-18
Reporting obligations to authorities
NIST1800-32-19
Coordination with sector-specific agencies
NIST1800-32-20
Exercises and drills for OT incidents
NIST1800-32-21
Supply chain risk management for critical components
NIST1800-32-22
Configuration management for OT systems
NIST1800-32-23
Change management procedures
NIST1800-32-24
Vulnerability assessment for critical systems

How this is calculated

Already covered means a mapping runs from a control in Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition