32% of ISO/SAE 21434 you already have
Liechtenstein DPA already covers about 32% of ISO/SAE 21434, leaving
34 of 50 controls as genuinely new work.
Already covered 7
Likely covered 9
New work 34
What is genuinely new work
Nothing in Liechtenstein DPA reaches these. This is the list to scope.
21434-10Product Development at System Level
21434-10.4Hardware and Software Component Requirements
21434-11Cybersecurity Validation
21434-13Operations and Maintenance
21434-14End of Cybersecurity Support and Decommissioning
21434-15.3Asset Identification (TARA Step 1)
21434-15.5Threat Scenario Identification (TARA Step 2)
21434-15.6Impact Rating (TARA Step 3)
21434-15.7Attack Path Analysis (TARA Step 4)
21434-15.8Attack Feasibility and Risk Determination (TARA Step 5)
21434-15.9Cybersecurity Assurance Level (CAL) and Risk Treatment
21434-5Cybersecurity Governance
21434-6Cybersecurity Culture and Competence
21434-7Continuous Cybersecurity Activities
21434-8Risk Assessment Methods
21434-9.4Cybersecurity Goals and Claims
21434-Annex-EDistributed Cybersecurity Activities and Supplier Management
ISO21434-01Information security policy framework
ISO21434-02Management direction and commitment
ISO21434-03Policy review and update procedures
ISO21434-05Contact with authorities and special interest groups
ISO21434-06Asset inventory and ownership
ISO21434-10Media management and disposal
ISO21434-11Access control policy and enforcement
ISO21434-20Key lifecycle management
ISO21434-21Operational procedures and responsibilities
ISO21434-22Protection from malware
ISO21434-26Audit considerations
ISO21434-28Network service security
ISO21434-29Segregation in networks
ISO21434-30Information transfer policies
ISO21434-31Secure messaging
Show the 16 you already have
ISO21434-12User access management and provisioning
ISO21434-14Privileged access management
ISO21434-15Access review and recertification
ISO21434-16Cryptographic policy and key management
ISO21434-17Encryption of data at rest
ISO21434-18Encryption of data in transit
ISO21434-19Certificate management
ISO21434-04Roles and responsibilities definition
ISO21434-07Acceptable use of assets
ISO21434-08Information classification and labeling
ISO21434-09Asset handling procedures
ISO21434-13Authentication and password management
ISO21434-23Backup and recovery procedures
ISO21434-24Logging and monitoring
ISO21434-25Technical vulnerability management
ISO21434-27Network security management
How this is calculated
Already covered means a mapping runs from a control in Liechtenstein DPA to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition