Framework overlap

Does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 cover Jamaica Data Protection Act 2020?

You hold CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 and have been told to do Jamaica Data Protection Act 2020. Here is how much overlaps, control by control.

47% of Jamaica Data Protection Act 2020 you already have

CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 already covers about 47% of Jamaica Data Protection Act 2020, leaving 9 of 17 controls as genuinely new work.

Already covered 4 Likely covered 4 New work 9

What is genuinely new work

Nothing in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 reaches these. This is the list to scope.

JM-DPA2020-Information-Commissioner-Sec6-15-OIC-Office-Information-Commissioner-Establishment-Independence-Functions
Jamaica DPA 2020 Office of the Information Commissioner (OIC) + Sections 6-15 + Establishment + Independence + Functions + Powers + Registration Requirements + Investigation + Enfo
JM-DPA2020-Penalty-Risk-Sec31-33-50-52-Criminal-Civil-Administrative-Up-to-10M-JMD-Compensation-Imprisonment
Jamaica DPA 2020 Penalty Risk Management + Sections 31-33 + 50 + 52 + Criminal Offences + Civil Compensation + Administrative Penalties + Up to JMD 10 Million + Imprisonment + Dire
JM-DPA2020-Public-Authority-Exemptions-Sec4-44-46-National-Security-Intelligence-Crime-Tax-Defence-Limitations
Jamaica DPA 2020 Public Authority Exemptions + Sections 4 + 44 + 46 + National Security + Intelligence Services + Crime Prevention + Tax + Defence + Research + Journalism + Data Su
JM-DPA2020-Scope-Application-Sec1-3-31Dec2021-PartialEffective-1Dec2023-MandatoryCompliance-Territorial-Extraterritorial
Jamaica Data Protection Act 2020 - Scope + Application + Sections 1-3 + Commencement 1 December 2021 Partial + 1 December 2023 Mandatory Compliance + Territorial + Extraterritorial
JM-DPA2020-Standard1-Fair-Lawful-Transparent-Sec19-Lawful-Basis-Consent-Contract-Legal-Vital-Public-Interest-Legitimate
Jamaica DPA 2020 Standard 1 - Fair + Lawful + Transparent Processing + Section 19 + Lawful Basis + Consent + Contract Performance + Legal Obligation + Vital Interests + Public Inte
JM-DPA2020-Standard2-Purpose-Limitation-Sec20-Specified-Explicit-Legitimate-No-Further-Processing-Incompatible
Jamaica DPA 2020 Standard 2 - Purpose Limitation + Section 20 + Specified + Explicit + Legitimate Purposes + No Further Processing Incompatible + Purpose Compatibility Test + Secon
JM-DPA2020-Standard3-Adequacy-Relevance-Necessity-Sec21-Data-Minimisation-No-Excess-Processing
Jamaica DPA 2020 Standard 3 - Adequacy + Relevance + Necessity + Section 21 + Data Minimisation + No Excess Processing + Proportionality + Privacy by Default + Field-Level Restrain
JM-DPA2020-Standard4-Accuracy-Sec22-Up-to-Date-Rectification-Erasure-Correction-Right
Jamaica DPA 2020 Standard 4 - Accuracy + Section 22 + Up-to-Date + Rectification Right + Erasure Right + Correction Procedures + Quality Assurance + Sources Verification
JM-DPA2020-Standard5-Retention-Sec23-Time-Limit-No-Longer-Than-Necessary-Erasure-Deletion-Anonymisation
Jamaica DPA 2020 Standard 5 - Retention + Section 23 + Time Limit + No Longer Than Necessary + Erasure + Deletion + Anonymisation + Retention Schedule + Legal Hold + Backup Conside
Show the 8 you already have
JM-DPA2020-Complaints-Enforcement-Sec45-50-Investigation-Hearing-Determination-Appeal-Tribunal
Jamaica DPA 2020 Complaints + Enforcement + Sections 45-50 + Complaint Procedure + Investigation + Hearing + Determination + Compliance Orders + Administrative Penalties + Data Pro
JM-DPA2020-Joint-Controller-Processor-Sec24-25-26-Arrangements-Allocation-Responsibilities-Contracts
Jamaica DPA 2020 Joint Controllers + Processors + Sections 24-26 + Arrangements + Allocation of Responsibilities + Contracts + Records of Processing Activities (ROPA) + Sub-Process
JM-DPA2020-Privacy-by-Design-Default-Sec34-Engineering-Data-Protection-Impact-Assessment-DPIA-Risk-Based
Jamaica DPA 2020 Privacy by Design + Privacy by Default + Section 34 + Data Protection Impact Assessment (DPIA) + Risk-Based + High-Risk Processing + Prior Consultation + Privacy E
JM-DPA2020-Standard7-Security-Sec35-Appropriate-Technical-Organisational-Confidentiality-Integrity-Availability-Resilience
Jamaica DPA 2020 Standard 7 - Security + Section 35 + Appropriate Technical and Organisational Measures + Confidentiality + Integrity + Availability + Resilience + Encryption + Pse
JM-DPA2020-Breach-Notification-Sec28-30-Duty-Notify-Commissioner-Affected-Subjects-72-Hours-Severe
Jamaica DPA 2020 Personal Data Breach Notification + Sections 28-30 + Duty to Notify Commissioner + Affected Subjects + 72-Hour Reporting + High Risk + Severe + Mitigation + Docume
JM-DPA2020-Childrens-Data-Special-Categories-Sensitive-Sec5-Genetic-Biometric-Health-Race-Political-Religious
Jamaica DPA 2020 Section 5 Sensitive Personal Data + Special Categories + Genetic + Biometric + Health + Race + Ethnicity + Political + Religious + Philosophical + Trade Union + Se
JM-DPA2020-Standard6-Subject-Rights-Sec37-43-Access-Correction-Erasure-Portability-Objection-Profiling-Restriction
Jamaica DPA 2020 Standard 6 - Data Subject Rights Enablement + Section 37-43 + Access Right + Correction Right + Erasure Right + Portability Right + Objection Right + Automated Dec
JM-DPA2020-Standard8-Transfers-Outside-Jamaica-Sec27-Adequacy-Decisions-Standard-Contractual-Clauses-BCR-Derogations
Jamaica DPA 2020 Standard 8 - Transfers Outside Jamaica + Section 27 + Adequacy Decisions + Standard Contractual Clauses + Binding Corporate Rules + Derogations + Cross-Border Data

How this is calculated

Already covered means a mapping runs from a control in CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition