9% of ITIL 4 you already have
GDPR already covers about 9% of ITIL 4, leaving
48 of 53 controls as genuinely new work.
Already covered 0
Likely covered 5
New work 48
No control in GDPR
maps directly to one in ITIL 4. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in GDPR reaches these. This is the list to scope.
GM-ARC-1Architecture Management
GM-CI-1Continual Improvement
GM-FIN-1Service Financial Management
GM-ISM-1Information Security Management
GM-ITAM-1IT Asset Management
GM-KM-1Knowledge Management
GM-MS-1Measurement and Reporting
GM-PFM-1Portfolio Management
GM-PM-1Project Management
GM-REL-1Relationship Management
GM-SRV-1Service Catalogue Management
GM-STR-1Strategy Management
GM-SUP-1Supplier Management
GM-WT-1Workforce and Talent Management
ITIL4-01Service portfolio management
ITIL4-02Service level management
ITIL4-04IT service continuity management
ITIL4-05Information security for services
ITIL4-07Release and deployment management
ITIL4-08Service validation and testing
ITIL4-09Knowledge management
ITIL4-12Problem management
ITIL4-13Event management and monitoring
ITIL4-14Request fulfillment
ITIL4-16Service measurement and reporting
ITIL4-17Continual improvement process
ITIL4-18Benchmarking and maturity assessment
ITIL4-19Stakeholder feedback management
SM-AV-1Availability Management
SM-CAP-1Capacity and Performance Management
SM-CHG-1Change Enablement
SM-DEP-1Deployment Management
SM-INC-1Incident Management
SM-MEM-1Monitoring and Event Management
SM-OCM-1Organizational Change Management
SM-PRB-1Problem Management
SM-REL-1Release Management
SM-SCM-1Service Configuration Management
SM-SCONT-1Service Continuity Management
SM-SD-DES-1Service Design
SM-SLM-1Service Level Management
SM-SRM-1Service Request Management
SM-SVAL-1Service Validation and Testing
TM-INF-1Infrastructure and Platform Management
TM-SDM-1Software Development and Management
Show the 5 you already have
ITIL4-03Capacity and availability management
ITIL4-06Change management processes
ITIL4-10Configuration management
ITIL4-11Incident management
ITIL4-15Access management for services
How this is calculated
Already covered means a mapping runs from a control in GDPR to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition