Framework overlap

Does ISO/IEC 27010:2015 cover PCI SSF?

You hold ISO/IEC 27010:2015 and have been told to do PCI SSF. Here is how much overlaps, control by control.

33% of PCI SSF you already have

ISO/IEC 27010:2015 already covers about 33% of PCI SSF, leaving 33 of 49 controls as genuinely new work.

Already covered 7 Likely covered 9 New work 33

What is genuinely new work

Nothing in ISO/IEC 27010:2015 reaches these. This is the list to scope.

PCI-SSF-01
Information security program management
PCI-SSF-02
Board and management oversight
PCI-SSF-04
Security policy framework
PCI-SSF-13
Third-party dependency management
PCI-SSF-18
Ongoing monitoring and assessment
PCI-SSF-19
Concentration risk management
PCI-SSF-20
Exit strategy and transition planning
PCI-SSF-22
Incident response and containment
PCI-SSF-23
Regulatory reporting requirements
SSLC-1.1
Security Responsibility and Resources
SSLC-10.1
Software Integrity
SSLC-11.1
Stakeholder Communication
SSLC-12.1
Software Update Integrity and Verification
SSLC-2.1
Software Security Policy
SSLC-3.1
Software Security Personnel Skills
SSLC-4.1
Threat Identification and Risk Mitigation
SSLC-5.1
Software Design Security
SSLC-6.1
Secure Coding Practices
SSLC-7.1
Security Testing
SSLC-8.1
Vulnerability Disclosure and Response
SSLC-9.1
Change Management
SSS-1.1
Critical Asset Identification
SSS-1.2
Critical Asset Protection
SSS-10.1
Sensitive Authentication Data (Module A)
SSS-11.1
Terminal Software Module Requirements (Module B)
SSS-2.1
Sensitive Data Inventory and Protection
SSS-3.1
Critical Asset Cryptographic Protection
SSS-4.1
Authentication and Access Control
SSS-5.1
Attack Detection
SSS-6.1
Threat and Vulnerability Management
SSS-7.1
Secure Software Updates
SSS-8.1
Vendor Security Guidance
SSS-9.1
Account-Data Protection (Module A)
Show the 16 you already have
PCI-SSF-06
Network security and segmentation
PCI-SSF-09
Encryption and key management
PCI-SSF-11
Business continuity planning and testing
PCI-SSF-12
Disaster recovery procedures
PCI-SSF-21
Incident detection and classification
PCI-SSF-24
Customer notification procedures
PCI-SSF-25
Post-incident review and improvement
PCI-SSF-03
Risk appetite and tolerance for IT risk
PCI-SSF-05
Roles and responsibilities definition
PCI-SSF-07
Endpoint protection and detection
PCI-SSF-08
Application security controls
PCI-SSF-10
Secure configuration standards
PCI-SSF-14
Critical service identification
PCI-SSF-15
Communication and escalation procedures
PCI-SSF-16
Due diligence and onboarding
PCI-SSF-17
Contractual security requirements

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 27010:2015 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition