57% of ISO 27017 you already have
Malaysia PDPA 2010 already covers about 57% of ISO 27017, leaving
16 of 37 controls as genuinely new work.
Already covered 6
Likely covered 15
New work 16
What is genuinely new work
Nothing in Malaysia PDPA 2010 reaches these. This is the list to scope.
11.2.7Secure disposal or reuse of equipment (cloud)
14.1.1Information security requirements analysis (cloud apps)
15.1.1Information security policy for supplier relationships (cloud)
16.1.1Responsibilities and procedures (cloud incidents)
18.1.1Identification of applicable legislation (cloud)
CLD.12.1.5Administrator's operational security
CLD.12.4.5Monitoring of cloud services
CLD.13.1.4Alignment of security management for virtual and physical networks
CLD.6.3.1Shared roles and responsibilities within a cloud computing environment
CLD.8.1.5Removal of cloud service customer assets
CLD.9.5.1Segregation in virtual computing environments
CLD.9.5.2Virtual machine hardening
ISO27017-09Federation and single sign-on
ISO27017-10API security and access tokens
ISO27017-18Cloud workload protection
ISO27017-25Service level agreement management
Show the 21 you already have
ISO27017-03Cloud risk assessment
ISO27017-04Regulatory compliance for cloud services
ISO27017-12Encryption of cloud-stored data
ISO27017-13Data residency and sovereignty
ISO27017-15Secure data deletion in cloud
ISO27017-22Incident response in cloud
ISO27017-01Shared responsibility model definition
ISO27017-02Cloud security policy and strategy
ISO27017-05Cloud security roles and responsibilities
ISO27017-06Cloud identity management
ISO27017-07Multi-factor authentication for cloud
ISO27017-08Privileged access in cloud environments
ISO27017-11Data classification for cloud
ISO27017-14Data backup and recovery in cloud
ISO27017-16Virtual network segmentation
ISO27017-17Container and serverless security
ISO27017-19Image and template hardening
ISO27017-20Cloud configuration management
ISO27017-21Cloud security monitoring and logging
ISO27017-23Cloud vulnerability management
ISO27017-24Cloud change management
How this is calculated
Already covered means a mapping runs from a control in Malaysia PDPA 2010 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition