34% of PCI P2PE you already have
Nebraska Data Privacy Act already covers about 34% of PCI P2PE, leaving
29 of 44 controls as genuinely new work.
Already covered 1
Likely covered 14
New work 29
What is genuinely new work
Nothing in Nebraska Data Privacy Act reaches these. This is the list to scope.
Annex-ASymmetric Key Distribution Using Asymmetric Techniques
Annex-BKey Injection Facility Requirements
Domain-1.1POI Device Approval Status
Domain-1.2Account Data Encryption at POI
Domain-1.3POI Device Tampering Protection
Domain-2.1POI Application Security
Domain-2.2POI Device Authentication
Domain-3.1POI Device Management
Domain-3.2Merchant POI Device Deployment
Domain-4.1Decryption Environment Logical Security
Domain-4.2Decryption Environment Physical Security
Domain-5.2Key Distribution and Injection
Domain-5.4Key Usage and Cryptoperiods
Domain-5.5Key Destruction
Domain-6.1P2PE Solution Documentation
Domain-6.2Annual Reassessment and Change Management
Domain-6.3Merchant Self-Assessment Support
PCI-P2PE-01Information security program management
PCI-P2PE-02Board and management oversight
PCI-P2PE-03Risk appetite and tolerance for IT risk
PCI-P2PE-04Security policy framework
PCI-P2PE-13Third-party dependency management
PCI-P2PE-15Communication and escalation procedures
PCI-P2PE-17Contractual security requirements
PCI-P2PE-20Exit strategy and transition planning
PCI-P2PE-23Regulatory reporting requirements
PCI-P2PE-24Customer notification procedures
Show the 15 you already have
PCI-P2PE-05Roles and responsibilities definition
PCI-P2PE-06Network security and segmentation
PCI-P2PE-07Endpoint protection and detection
PCI-P2PE-08Application security controls
PCI-P2PE-09Encryption and key management
PCI-P2PE-10Secure configuration standards
PCI-P2PE-11Business continuity planning and testing
PCI-P2PE-12Disaster recovery procedures
PCI-P2PE-14Critical service identification
PCI-P2PE-16Due diligence and onboarding
PCI-P2PE-18Ongoing monitoring and assessment
PCI-P2PE-19Concentration risk management
PCI-P2PE-21Incident detection and classification
PCI-P2PE-22Incident response and containment
PCI-P2PE-25Post-incident review and improvement
How this is calculated
Already covered means a mapping runs from a control in Nebraska Data Privacy Act to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition