43% of NIST SP 800-171A Rev 3 you already have
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) already covers about 43% of NIST SP 800-171A Rev 3, leaving
20 of 35 controls as genuinely new work.
Already covered 0
Likely covered 15
New work 20
No control in Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)
maps directly to one in NIST SP 800-171A Rev 3. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) reaches these. This is the list to scope.
3.1.1Authorized Access Control
3.1.2Transaction and Function Control
3.13Deploy a Data Loss Prevention Solution
3.13.1Boundary Protection Assessment
3.14Log Sensitive Data Access
3.2Establish and Maintain a Data Inventory
3.2.1Account data storage minimised
3.3.1Audit Record Creation
3.4Enforce Data Retention
3.5Securely Dispose of Data
3.9Encrypt Data on Removable Media
3.9.1Personnel Screening Assessment
FEDRAMP-CM-1Configuration Management Policy
FEDRAMP-CM-2Baseline Configuration
FEDRAMP-SC-1System and Communications Protection Policy
FEDRAMP-SC-12Cryptographic Key Establishment and Management
FEDRAMP-SC-7Boundary Protection
Show the 15 you already have
3.10Encrypt Sensitive Data in Transit
3.11Encrypt Sensitive Data at Rest
3.12Segment Data Processing and Storage Based on Sensitivity
3.16System and Services Acquisition
3.17Supply Chain Risk Management
3.3Configure Data Access Control Lists
3.6Encrypt Data on End-User Devices
3.6.1Incident Response Capability
3.7Establish and Maintain a Data Classification Scheme
3.7.1Key generation procedures
FEDRAMP-CM-6Configuration Settings
FEDRAMP-CP-9System Backup
FEDRAMP-SC-13Cryptographic Protection
FEDRAMP-SC-28Protection of Information at Rest
FEDRAMP-SC-8Transmission Confidentiality and Integrity
How this is calculated
Already covered means a mapping runs from a control in Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition