Framework overlap

Does GDPR cover FFIEC IT Examination Handbook?

You hold GDPR and have been told to do FFIEC IT Examination Handbook. Here is how much overlaps, control by control.

19% of FFIEC IT Examination Handbook you already have

GDPR already covers about 19% of FFIEC IT Examination Handbook, leaving 63 of 78 controls as genuinely new work.

Already covered 0 Likely covered 15 New work 63

No control in GDPR maps directly to one in FFIEC IT Examination Handbook. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in GDPR reaches these. This is the list to scope.

FFIEC-01
Information security program management
FFIEC-02
Board and management oversight
FFIEC-04
Security policy framework
FFIEC-07
Endpoint protection and detection
FFIEC-13
Third-party dependency management
FFIEC-15
Communication and escalation procedures
FFIEC-16
Due diligence and onboarding
FFIEC-17
Contractual security requirements
FFIEC-19
Concentration risk management
FFIEC-21
Incident detection and classification
FFIEC-22
Incident response and containment
IS-II.A.1
Board Oversight of Information Security
IS-II.A.2
Senior Management Responsibilities
IS-II.B.1
Information Security Culture
IS-II.C.1
Information Security Roles and Responsibilities
IS-III.A.1
Information Security Risk Management Framework
IS-III.B.2
Risk Measurement and Analysis
IS-III.B.3
Risk Mitigation Strategy
IS-III.C.1
Risk Monitoring and Reporting
IS-III.D.1
Information Security Strategy
IS-IV.A.1
Inventory and Classification of Information Assets
IS-IV.A.2
Data Flow Diagrams
IS-IV.B.1
Identity and Access Management Program
IS-IV.B.2
Authentication Controls
IS-IV.B.3
Privileged Access Management
IS-IV.B.4
Access Reviews and Recertification
IS-IV.B.5
Joiner Mover Leaver Process
IS-IV.C.1
Network Security Architecture
IS-IV.C.2
Firewall Configuration and Review
IS-IV.C.3
Wireless Network Security
IS-IV.C.4
Remote Access Security
IS-IV.D.1
Endpoint Security Controls
IS-IV.D.2
Mobile Device Management
IS-IV.D.3
Removable Media Controls
IS-IV.E.1
Secure Software Development Lifecycle
IS-IV.E.2
Application Security Testing
IS-IV.E.3
Application Change Management
IS-IV.F.1
Encryption Standards and Key Management
IS-IV.F.2
Data in Transit Encryption
IS-IV.F.3
Data at Rest Encryption
IS-IX.A.1
Third Party Risk Management
IS-IX.A.2
Cloud Service Provider Oversight
IS-V.A.1
IT Operations Management
IS-V.A.2
Configuration Management
IS-V.A.3
Patch Management
IS-V.B.1
Vulnerability Management Program
IS-V.B.2
Penetration Testing
IS-V.C.1
Physical and Environmental Security
IS-VI.A.1
Security Logging Standards
IS-VI.A.2
Security Monitoring and SIEM
IS-VI.A.3
Threat Intelligence
IS-VI.B.1
User Behavior Analytics
IS-VII.A.1
Incident Response Program
IS-VII.A.2
Incident Detection and Classification
IS-VII.A.3
Incident Response Testing and Exercises
IS-VII.A.4
Notification of Customers Regulators and Law Enforcement
IS-VIII.A.1
Business Continuity Integration
IS-VIII.A.2
Backup and Recovery
IS-X.A.1
Security Awareness Training
IS-X.B.1
Independent Information Security Audit
IS-X.B.2
Cybersecurity Assessment and Maturity
IS-XI.A.1
Architecture and Operations Alignment
IS-XI.A.2
Management Booklet Governance Alignment
Show the 15 you already have
FFIEC-03
Risk appetite and tolerance for IT risk
FFIEC-05
Roles and responsibilities definition
FFIEC-06
Network security and segmentation
FFIEC-08
Application security controls
FFIEC-09
Encryption and key management
FFIEC-10
Secure configuration standards
FFIEC-11
Business continuity planning and testing
FFIEC-12
Disaster recovery procedures
FFIEC-14
Critical service identification
FFIEC-18
Ongoing monitoring and assessment
FFIEC-20
Exit strategy and transition planning
FFIEC-23
Regulatory reporting requirements
FFIEC-24
Customer notification procedures
FFIEC-25
Post-incident review and improvement
IS-III.B.1
Risk Identification

How this is calculated

Already covered means a mapping runs from a control in GDPR to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition