Framework overlap

Does Ley Orgánica de Protección de Datos Personales (LOPDP) cover PCI PIN Security?

You hold Ley Orgánica de Protección de Datos Personales (LOPDP) and have been told to do PCI PIN Security. Here is how much overlaps, control by control.

33% of PCI PIN Security you already have

Ley Orgánica de Protección de Datos Personales (LOPDP) already covers about 33% of PCI PIN Security, leaving 29 of 43 controls as genuinely new work.

Already covered 0 Likely covered 14 New work 29

No control in Ley Orgánica de Protección de Datos Personales (LOPDP) maps directly to one in PCI PIN Security. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Ley Orgánica de Protección de Datos Personales (LOPDP) reaches these. This is the list to scope.

CO-1
PINs Used for Cardholder Authentication Are Processed in Approved Devices
CO-10
Equipment Used to Process PINs and Keys Is Managed in a Secure Manner
CO-11
Secret and Private Keys and Key Components Are Generated, Conveyed, and Used in a Manner That Prevents or Detects Their Unauthorized Disclosure, Modification, or Substitution
CO-12
Keys Are Used in a Manner That Prevents or Detects Their Unauthorized Usage
CO-13
Keys Are Administered Throughout Their Lifecycle in a Secure Manner
CO-14
Materials Used to Generate or Transport Keys Are Treated With the Same Security as the Keys They Protect
CO-15
Cryptographic Keys Are Replaced With New Keys When Knowledge of Or Access to a Key Is No Longer Required
CO-16
Keys No Longer Used or Replaced Are Securely Destroyed
CO-17
Access to Secret and Private Cryptographic Keys and Key Material Is Restricted
CO-18
Logging Is in Place to Enable Audit and Investigation of Key Management Activities
CO-19
Organizations Implement and Document Risk-Mitigation Practices
CO-2
Devices Approved Under PCI PTS POI Have SRED Functionality
CO-3
POIs and HSMs Are Protected From Unauthorized Access
CO-4
Procedures Exist to Protect Devices From Tampering and Substitution
CO-5
Cryptographic Keys Are Generated Using Approved Methods
CO-6
Cryptographic Keys Are Conveyed or Transmitted Securely
CO-7
Key Loading Is Handled in a Secure Manner
CO-8
Keys Are Used Only for Their Designated Purpose
CO-9
Keys Are Administered in a Secure Manner
CO-Annex-A
Symmetric Key Distribution Using Asymmetric Techniques
CO-Annex-B
Key-Injection Facility Requirements
PCI-PIN-04
Security policy framework
PCI-PIN-13
Third-party dependency management
PCI-PIN-14
Critical service identification
PCI-PIN-15
Communication and escalation procedures
PCI-PIN-17
Contractual security requirements
PCI-PIN-20
Exit strategy and transition planning
PCI-PIN-21
Incident detection and classification
PCI-PIN-22
Incident response and containment
Show the 14 you already have
PCI-PIN-05
Roles and responsibilities definition
PCI-PIN-06
Network security and segmentation
PCI-PIN-07
Endpoint protection and detection
PCI-PIN-08
Application security controls
PCI-PIN-09
Encryption and key management
PCI-PIN-10
Secure configuration standards
PCI-PIN-11
Business continuity planning and testing
PCI-PIN-12
Disaster recovery procedures
PCI-PIN-16
Due diligence and onboarding
PCI-PIN-18
Ongoing monitoring and assessment
PCI-PIN-19
Concentration risk management
PCI-PIN-23
Regulatory reporting requirements
PCI-PIN-24
Customer notification procedures
PCI-PIN-25
Post-incident review and improvement

How this is calculated

Already covered means a mapping runs from a control in Ley Orgánica de Protección de Datos Personales (LOPDP) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair · Today's edition