Framework overlap

Does Ley Orgánica de Protección de Datos Personales (LOPDP) cover SSAE 18?

You hold Ley Orgánica de Protección de Datos Personales (LOPDP) and have been told to do SSAE 18. Here is how much overlaps, control by control.

24% of SSAE 18 you already have

Ley Orgánica de Protección de Datos Personales (LOPDP) already covers about 24% of SSAE 18, leaving 51 of 67 controls as genuinely new work.

Already covered 0 Likely covered 16 New work 51

No control in Ley Orgánica de Protección de Datos Personales (LOPDP) maps directly to one in SSAE 18. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in Ley Orgánica de Protección de Datos Personales (LOPDP) reaches these. This is the list to scope.

SSAE-01
Common Attestation Concepts (AT-C 105)
SSAE-02
Examination Engagements (AT-C 205)
SSAE-03
Review Engagements (AT-C 210)
SSAE-04
Agreed-Upon Procedures (AT-C 215)
SSAE-05
SOC 1 Engagements (AT-C 320)
SSAE-06
SOC 2 Engagements (AT-C 205 with TSC)
SSAE-07
SOC 3 General Use Reports
SSAE-08
Preconditions for Attestation Engagement
SSAE-09
Independence and Ethics
SSAE-10
Engagement Risk Assessment
SSAE-11
Materiality in Attestation
SSAE-12
Written Representations
SSAE-13
Other Information in Reports
SSAE-14
Reporting on Pro Forma Financial Information (AT-C 310)
SSAE-15
Reporting on Compliance (AT-C 315)
SSAE-16
Examinations of Prospective Financial Information (AT-C 305)
SSAE-17
Engagement Documentation
SSAE-18
Quality Management at Firm and Engagement Level
SSAE-19
Modifications to the Standard Report
SSAE-20
Use by Specified Parties and Restricted Distribution
SSAE18-A1.1
A1.1 - Availability Commitments and Requirements
SSAE18-C1.1
C1.1 - Confidential Information Identification
SSAE18-C1.2
C1.2 - Confidential Information Disposal
SSAE18-CC1.1
CC1.1 - COSO Principle 1: Integrity and Ethical Values
SSAE18-CC1.2
CC1.2 - COSO Principle 2: Board Independence and Oversight
SSAE18-CC1.3
CC1.3 - COSO Principle 3: Management Structure and Authority
SSAE18-CC1.4
CC1.4 - COSO Principle 4: Commitment to Competence
SSAE18-CC1.5
CC1.5 - COSO Principle 5: Accountability
SSAE18-CC2.1
CC2.1 - COSO Principle 13: Quality Information
SSAE18-CC2.2
CC2.2 - COSO Principle 14: Internal Communication
SSAE18-CC2.3
CC2.3 - COSO Principle 15: External Communication
SSAE18-CC3.3
CC3.3 - COSO Principle 8: Fraud Risk Assessment
SSAE18-CC5.1
CC5.1 - COSO Principle 10: Control Activity Selection
SSAE18-CC5.2
CC5.2 - COSO Principle 11: Technology General Controls
SSAE18-CC5.3
CC5.3 - COSO Principle 12: Control Activity Policies
SSAE18-CC6.1
CC6.1 - Logical Access Security Software
SSAE18-CC6.3
CC6.3 - Access Removal
SSAE18-CC6.5
CC6.5 - Logical Access to Protected Assets
SSAE18-CC6.6
CC6.6 - External Threats and Security Measures
SSAE18-CC6.7
CC6.7 - Data Transmission Restrictions
SSAE18-CC6.8
CC6.8 - Unauthorized Software Prevention
SSAE18-CC7.1
CC7.1 - Infrastructure and Software Monitoring
SSAE18-CC7.2
CC7.2 - Anomaly Monitoring in Operations
SSAE18-CC7.3
CC7.3 - Security Event Evaluation
SSAE18-CC9.1
CC9.1 - Risk Mitigation Activities
SSAE18-PI1.2
PI1.2 - System Processing Completeness and Accuracy
SSAE18-PI1.3
PI1.3 - Processing Error Handling
SSAE18-SOC1-01
Control Environment
SSAE18-SOC1-03
Information and Communication
SSAE18-SOC1-04
Monitoring Activities
SSAE18-SOC1-05
Control Activities for Financial Processing
Show the 16 you already have
SSAE18-A1.2
A1.2 - Environmental Protections and Recovery
SSAE18-A1.3
A1.3 - Recovery Plan Testing
SSAE18-CC3.1
CC3.1 - COSO Principle 6: Risk Identification
SSAE18-CC3.2
CC3.2 - COSO Principle 7: Risk Analysis
SSAE18-CC3.4
CC3.4 - COSO Principle 9: Change Management
SSAE18-CC6.2
CC6.2 - New User Registration and Authorization
SSAE18-CC6.4
CC6.4 - Physical Access Restrictions
SSAE18-CC7.4
CC7.4 - Incident Response
SSAE18-CC7.5
CC7.5 - Incident Recovery
SSAE18-CC8.1
CC8.1 - Infrastructure and Software Change Management
SSAE18-CC9.2
CC9.2 - Vendor and Business Partner Risk Management
SSAE18-P1.1
P1.1 - Privacy Notice
SSAE18-P1.2
P1.2 - Choice and Consent
SSAE18-PI1.1
PI1.1 - Processing Integrity Definition
SSAE18-SOC1-02
Risk Assessment
SSAE18-SOC1-06
Transaction Processing Controls

How this is calculated

Already covered means a mapping runs from a control in Ley Orgánica de Protección de Datos Personales (LOPDP) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair · Today's edition