50% of NIST SP 800-171A you already have
Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) already covers about 50% of NIST SP 800-171A, leaving
16 of 32 controls as genuinely new work.
Already covered 0
Likely covered 16
New work 16
No control in Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018)
maps directly to one in NIST SP 800-171A. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) reaches these. This is the list to scope.
171A-AC-01Assess Account Management
171A-AC-02Assess Access Enforcement
171A-AC-03Assess Information Flow Enforcement
171A-AC-04Assess Separation of Duties
171A-AC-05Assess Least Privilege
171A-AU-01Assess Audit Event Logging
171A-AU-02Assess Audit Record Review and Reporting
171A-AU-03Assess Audit Record Protection
171A-CM-02Assess Configuration Change Control
171A-CM-03Assess Least Functionality
171A-CM-04Assess Software Restrictions
171A-IA-03Assess Authenticator Management
171A-MA-01Assess System Maintenance Controls
171A-MA-02Assess Remote Maintenance
171A-MP-02Assess Media Transport Protection
171A-SI-02Assess Malicious Code Protection
Show the 16 you already have
171A-AC-06Assess Remote Access Controls
171A-AC-07Assess Wireless Access Controls
171A-AT-01Assess Security Awareness Training
171A-AT-02Assess Role-Based Security Training
171A-AU-04Assess Audit Record Retention
171A-CM-01Assess Baseline Configuration
171A-IA-01Assess Identification and Authentication
171A-IA-02Assess Multi-Factor Authentication
171A-IR-01Assess Incident Handling
171A-IR-02Assess Incident Response Testing
171A-MP-01Assess Media Protection
171A-SC-01Assess Boundary Protection
171A-SC-02Assess Cryptographic Protection
171A-SC-03Assess Communications Protection
171A-SI-01Assess Flaw Remediation
171A-SI-03Assess System Monitoring
How this is calculated
Already covered means a mapping runs from a control in Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition