42% of NIST SP 800-190 you already have
Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) already covers about 42% of NIST SP 800-190, leaving
26 of 45 controls as genuinely new work.
Already covered 4
Likely covered 15
New work 26
What is genuinely new work
Nothing in Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) reaches these. This is the list to scope.
NIST190-09Federation and single sign-on
NIST190-10API security and access tokens
NIST190-13Data residency and sovereignty
NIST190-17Container and serverless security
NIST190-18Cloud workload protection
NIST190-25Service level agreement management
SP800-190-3.1Container Image Vulnerability Management
SP800-190-3.10Network Segmentation Between Pods
SP800-190-3.11Mixed Sensitivity Workload Isolation
SP800-190-3.12Container Runtime Hardening
SP800-190-3.13Host Operating System Minimization
SP800-190-3.14Host Patch Management
SP800-190-3.15Container File System Integrity
SP800-190-3.16Container Logging and Visibility
SP800-190-3.17Runtime Threat Detection
SP800-190-3.18Incident Response for Containers
SP800-190-3.19Supply Chain Risk for Third Party Images
SP800-190-3.2Image Configuration Hardening
SP800-190-3.20Secrets Management at Runtime
SP800-190-3.3Embedded Secrets in Images
SP800-190-3.4Image Trust and Provenance
SP800-190-3.5Registry Authentication and Authorization
SP800-190-3.6Registry Image Freshness
SP800-190-3.7Orchestrator Authentication
SP800-190-3.8Orchestrator Authorization with RBAC
SP800-190-3.9Pod Security Standards
Show the 19 you already have
NIST190-01Shared responsibility model definition
NIST190-11Data classification for cloud
NIST190-12Encryption of cloud-stored data
NIST190-15Secure data deletion in cloud
NIST190-02Cloud security policy and strategy
NIST190-03Cloud risk assessment
NIST190-04Regulatory compliance for cloud services
NIST190-05Cloud security roles and responsibilities
NIST190-06Cloud identity management
NIST190-07Multi-factor authentication for cloud
NIST190-08Privileged access in cloud environments
NIST190-14Data backup and recovery in cloud
NIST190-16Virtual network segmentation
NIST190-19Image and template hardening
NIST190-20Cloud configuration management
NIST190-21Cloud security monitoring and logging
NIST190-22Incident response in cloud
NIST190-23Cloud vulnerability management
NIST190-24Cloud change management
How this is calculated
Already covered means a mapping runs from a control in Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition