33% of PCI SSF you already have
FDA 21 CFR Part 11 already covers about 33% of PCI SSF, leaving
33 of 49 controls as genuinely new work.
Already covered 0
Likely covered 16
New work 33
No control in FDA 21 CFR Part 11
maps directly to one in PCI SSF. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in FDA 21 CFR Part 11 reaches these. This is the list to scope.
PCI-SSF-01Information security program management
PCI-SSF-02Board and management oversight
PCI-SSF-04Security policy framework
PCI-SSF-13Third-party dependency management
PCI-SSF-18Ongoing monitoring and assessment
PCI-SSF-19Concentration risk management
PCI-SSF-20Exit strategy and transition planning
PCI-SSF-22Incident response and containment
PCI-SSF-23Regulatory reporting requirements
SSLC-1.1Security Responsibility and Resources
SSLC-10.1Software Integrity
SSLC-11.1Stakeholder Communication
SSLC-12.1Software Update Integrity and Verification
SSLC-2.1Software Security Policy
SSLC-3.1Software Security Personnel Skills
SSLC-4.1Threat Identification and Risk Mitigation
SSLC-5.1Software Design Security
SSLC-6.1Secure Coding Practices
SSLC-8.1Vulnerability Disclosure and Response
SSLC-9.1Change Management
SSS-1.1Critical Asset Identification
SSS-1.2Critical Asset Protection
SSS-10.1Sensitive Authentication Data (Module A)
SSS-11.1Terminal Software Module Requirements (Module B)
SSS-2.1Sensitive Data Inventory and Protection
SSS-3.1Critical Asset Cryptographic Protection
SSS-4.1Authentication and Access Control
SSS-6.1Threat and Vulnerability Management
SSS-7.1Secure Software Updates
SSS-8.1Vendor Security Guidance
SSS-9.1Account-Data Protection (Module A)
Show the 16 you already have
PCI-SSF-03Risk appetite and tolerance for IT risk
PCI-SSF-05Roles and responsibilities definition
PCI-SSF-06Network security and segmentation
PCI-SSF-07Endpoint protection and detection
PCI-SSF-08Application security controls
PCI-SSF-09Encryption and key management
PCI-SSF-10Secure configuration standards
PCI-SSF-11Business continuity planning and testing
PCI-SSF-12Disaster recovery procedures
PCI-SSF-14Critical service identification
PCI-SSF-15Communication and escalation procedures
PCI-SSF-16Due diligence and onboarding
PCI-SSF-17Contractual security requirements
PCI-SSF-21Incident detection and classification
PCI-SSF-24Customer notification procedures
PCI-SSF-25Post-incident review and improvement
How this is calculated
Already covered means a mapping runs from a control in FDA 21 CFR Part 11 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition