70% of ASEAN Data Management Framework you already have
Canada ITSG-33 already covers about 70% of ASEAN Data Management Framework, leaving
8 of 27 controls as genuinely new work.
Already covered 0
Likely covered 19
New work 8
No control in Canada ITSG-33
maps directly to one in ASEAN Data Management Framework. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Canada ITSG-33 reaches these. This is the list to scope.
ADMF-1.2Data management function responsibilities
ADMF-1.3Business process function responsibilities
ADMF-2.1Leadership commitment in policy (who)
ADMF-3.1Identify and understand organisational data
ADMF-3.2Maintain a data inventory
ADMF-4.3Assess business impact categories
ADMF-5.5Manage and accept residual risk
ADMF-5.6Reference recognised security and privacy standards
Show the 19 you already have
ADMF-1.1Establish data management governance functions
ADMF-1.4Risk management function responsibilities
ADMF-1.5Executive direction and risk appetite
ADMF-2.2Define objectives, scope and considerations (what and why)
ADMF-2.3Establish the data management approach (how)
ADMF-2.4Embed data management in corporate governance and policy
ADMF-3.3Apply overarching categorisation considerations
ADMF-4.1Establish a data categorisation matrix
ADMF-4.2Assess confidentiality, integrity and availability impact
ADMF-4.4Assign datasets to risk tiers
ADMF-5.1Implement risk-based protection controls
ADMF-5.2Apply technical, procedural and physical safeguards
ADMF-5.3Protect data across the data lifecycle
ADMF-5.4Build a data protection control matrix
ADMF-6.1Define monitoring and measurement scope
ADMF-6.2Review controls associated with each category
ADMF-6.3Review categories assigned to datasets
ADMF-6.4Test data protection control effectiveness
ADMF-6.5Update policies, procedures and processes
How this is calculated
Already covered means a mapping runs from a control in Canada ITSG-33 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition