Framework overlap

Does Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) cover APRA CPS 234?

You hold Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) and have been told to do APRA CPS 234. Here is how much overlaps, control by control.

43% of APRA CPS 234 you already have

Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) already covers about 43% of APRA CPS 234, leaving 20 of 35 controls as genuinely new work.

Already covered 0 Likely covered 15 New work 20

No control in Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) maps directly to one in APRA CPS 234. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) reaches these. This is the list to scope.

CPS234-01
Information security program management
CPS234-02
Board and management oversight
CPS234-03
Risk appetite and tolerance for IT risk
CPS234-04
Security policy framework
CPS234-07
Endpoint protection and detection
CPS234-13
Board Responsibility for Information Security
CPS234-17
Contractual security requirements
CPS234-19
Information Security Policy Framework
CPS234-22
Control Testing Programme
CPS234-24
Customer notification procedures
CPS234-27
Audit of Third Party Information Security
CPS234-28
Documented Reporting of Material Findings
CPS234-30
Incident Response Plans
CPS234-32
Incident Response Testing
CPS234-35
APRA Notification of Material Incidents
CPS234-36
APRA Notification of Control Weaknesses
CPS234-37
Access Controls
CPS234-39
Encryption of Sensitive Data
CPS234-41
Vulnerability Management
CPS234-43
Security Awareness Training
Show the 15 you already have
CPS234-05
Roles and responsibilities definition
CPS234-06
Network security and segmentation
CPS234-08
Application security controls
CPS234-09
Encryption and key management
CPS234-10
Secure configuration standards
CPS234-11
Business continuity planning and testing
CPS234-12
Disaster recovery procedures
CPS234-14
Roles and Responsibilities
CPS234-15
Information Security Capability
CPS234-16
Capability of Third Parties
CPS234-18
Ongoing monitoring and assessment
CPS234-20
Information Asset Identification and Classification
CPS234-21
Implementation of Controls
CPS234-23
Frequency and Methodology of Testing
CPS234-25
Internal Audit of Information Security

How this is calculated

Already covered means a mapping runs from a control in Italy Personal Data Protection Code (Legislative Decree No. 196/2003, amended 2018) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition