40% of PCI PIN Security you already have
NIST SP 800-146 already covers about 40% of PCI PIN Security, leaving
26 of 43 controls as genuinely new work.
Already covered 0
Likely covered 17
New work 26
No control in NIST SP 800-146
maps directly to one in PCI PIN Security. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST SP 800-146 reaches these. This is the list to scope.
CO-1PINs Used for Cardholder Authentication Are Processed in Approved Devices
CO-10Equipment Used to Process PINs and Keys Is Managed in a Secure Manner
CO-11Secret and Private Keys and Key Components Are Generated, Conveyed, and Used in a Manner That Prevents or Detects Their Unauthorized Disclosure, Modification, or Substitution
CO-12Keys Are Used in a Manner That Prevents or Detects Their Unauthorized Usage
CO-13Keys Are Administered Throughout Their Lifecycle in a Secure Manner
CO-14Materials Used to Generate or Transport Keys Are Treated With the Same Security as the Keys They Protect
CO-15Cryptographic Keys Are Replaced With New Keys When Knowledge of Or Access to a Key Is No Longer Required
CO-16Keys No Longer Used or Replaced Are Securely Destroyed
CO-17Access to Secret and Private Cryptographic Keys and Key Material Is Restricted
CO-18Logging Is in Place to Enable Audit and Investigation of Key Management Activities
CO-19Organizations Implement and Document Risk-Mitigation Practices
CO-2Devices Approved Under PCI PTS POI Have SRED Functionality
CO-3POIs and HSMs Are Protected From Unauthorized Access
CO-4Procedures Exist to Protect Devices From Tampering and Substitution
CO-5Cryptographic Keys Are Generated Using Approved Methods
CO-6Cryptographic Keys Are Conveyed or Transmitted Securely
CO-7Key Loading Is Handled in a Secure Manner
CO-8Keys Are Used Only for Their Designated Purpose
CO-9Keys Are Administered in a Secure Manner
CO-Annex-ASymmetric Key Distribution Using Asymmetric Techniques
CO-Annex-BKey-Injection Facility Requirements
PCI-PIN-04Security policy framework
PCI-PIN-17Contractual security requirements
PCI-PIN-20Exit strategy and transition planning
PCI-PIN-21Incident detection and classification
PCI-PIN-22Incident response and containment
Show the 17 you already have
PCI-PIN-05Roles and responsibilities definition
PCI-PIN-06Network security and segmentation
PCI-PIN-07Endpoint protection and detection
PCI-PIN-08Application security controls
PCI-PIN-09Encryption and key management
PCI-PIN-10Secure configuration standards
PCI-PIN-11Business continuity planning and testing
PCI-PIN-12Disaster recovery procedures
PCI-PIN-13Third-party dependency management
PCI-PIN-14Critical service identification
PCI-PIN-15Communication and escalation procedures
PCI-PIN-16Due diligence and onboarding
PCI-PIN-18Ongoing monitoring and assessment
PCI-PIN-19Concentration risk management
PCI-PIN-23Regulatory reporting requirements
PCI-PIN-24Customer notification procedures
PCI-PIN-25Post-incident review and improvement
How this is calculated
Already covered means a mapping runs from a control in NIST SP 800-146 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition