Framework overlap

Does New Hampshire Data Privacy Act cover FFIEC Cybersecurity Assessment Tool (CAT)?

You hold New Hampshire Data Privacy Act and have been told to do FFIEC Cybersecurity Assessment Tool (CAT). Here is how much overlaps, control by control.

27% of FFIEC Cybersecurity Assessment Tool (CAT) you already have

New Hampshire Data Privacy Act already covers about 27% of FFIEC Cybersecurity Assessment Tool (CAT), leaving 36 of 49 controls as genuinely new work.

Already covered 3 Likely covered 10 New work 36

What is genuinely new work

Nothing in New Hampshire Data Privacy Act reaches these. This is the list to scope.

CAT-D1-1
Governance
CAT-D1-3
Resources
CAT-D2-3
Information sharing
CAT-D4-1
Connections
CAT-D4-2
Relationship management
CAT-D5-2
Detection, response, and mitigation
CAT-D5-3
Escalation and reporting
CAT-IRP-1
Technologies and connection types
CAT-IRP-2
Delivery channels
CAT-IRP-3
Online/mobile products and technology services
CAT-ML-1
Baseline
CAT-ML-3
Intermediate
CAT-ML-4
Advanced
CAT-ML-5
Innovative
FFIEC-CAT-CC-1
Cybersecurity Controls - Preventive Controls Infrastructure Management
FFIEC-CAT-CC-2
Cybersecurity Controls - Access and Data Management
FFIEC-CAT-CC-3
Cybersecurity Controls - Detective Controls
FFIEC-CAT-CC-4
Cybersecurity Controls - Corrective Controls Patch Management
FFIEC-CAT-CRI-1
Migration Path to CRI Profile
FFIEC-CAT-CRMO-1
Cyber Risk Management and Oversight - Governance
FFIEC-CAT-CRMO-2
Risk Management Program
FFIEC-CAT-CRMO-3
Resources and Training
FFIEC-CAT-CRMO-4
Culture and Accountability
FFIEC-CAT-EDM-1
External Dependency Management - Connections
FFIEC-CAT-EDM-2
External Dependency Management - Relationship Management
FFIEC-CAT-IM-1
Incident Management - Incident Resilience Planning and Strategy
FFIEC-CAT-IM-2
Incident Management - Detection, Response, and Mitigation
FFIEC-CAT-IM-3
Incident Management - Escalation and Reporting
FFIEC-CAT-IRP-1
Inherent Risk Profile - Technologies and Connection Types
FFIEC-CAT-IRP-2
Inherent Risk Profile - Delivery Channels
FFIEC-CAT-IRP-3
Online or Mobile Products and Technology Services
FFIEC-CAT-IRP-4
Organizational Characteristics
FFIEC-CAT-IRP-5
External Threats
FFIEC-CAT-TI-1
Threat Intelligence - Intelligence and Information
FFIEC-CAT-TI-2
Threat Intelligence - Monitoring and Analyzing
FFIEC-CAT-TI-3
Threat Intelligence - Information Sharing
Show the 13 you already have
CAT-D3-1
Preventative controls
CAT-D4-3
Third-party access controls
CAT-D5-1
Incident planning and strategy
CAT-D1-2
Risk management
CAT-D1-4
Training and culture
CAT-D2-1
Threat intelligence
CAT-D2-2
Monitoring and analyzing
CAT-D3-2
Detective controls
CAT-D3-3
Corrective controls
CAT-D5-4
Resilience planning and testing
CAT-IRP-4
Organizational characteristics
CAT-IRP-5
External threats
CAT-ML-2
Evolving

How this is calculated

Already covered means a mapping runs from a control in New Hampshire Data Privacy Act to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition