Framework overlap

Does NIST SP 800-171A cover Jordan Draft Personal Data Protection Law (2022)?

You hold NIST SP 800-171A and have been told to do Jordan Draft Personal Data Protection Law (2022). Here is how much overlaps, control by control.

25% of Jordan Draft Personal Data Protection Law (2022) you already have

NIST SP 800-171A already covers about 25% of Jordan Draft Personal Data Protection Law (2022), leaving 6 of 8 controls as genuinely new work.

Already covered 0 Likely covered 2 New work 6

No control in NIST SP 800-171A maps directly to one in Jordan Draft Personal Data Protection Law (2022). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIST SP 800-171A reaches these. This is the list to scope.

JO-PDPL-Breach-Notification-Article19-Council-72Hour-High-Risk-Data-Subjects-Mitigation
Jordan PDPL Personal Data Breach Notification + Article 19 + Council Notification + 72-Hour SLA + High-Risk Affected Data Subjects + Mitigation + Documentation + Processor Notifica
JO-PDPL-Cross-Border-Transfer-Article20-21-Adequacy-Consent-Public-Interest-Performance-Council-Approval
Jordan PDPL Cross-Border Transfer + Articles 20-21 + Adequacy + Consent + Public Interest + Performance + Council Approval + Standard Contractual Clauses + Binding Corporate Rules
JO-PDPL-Data-Subject-Rights-Article16-17-18-19-Information-Access-Correction-Erasure-Object-Portability
Jordan PDPL Data Subject Rights + Articles 16-19 + Right to Information + Access + Correction + Erasure + Restriction + Object + Portability + Automated Decision + 30-Day Response
JO-PDPL-Scope-Application-Article2-3-Personal-Data-Definition-Hashemite-Kingdom-MoDEE-Council-No24-2023-17March2024
Jordan Personal Data Protection Law (PDPL) No. 24 of 2023 - Scope + Application + Articles 2-3 + Personal Data Definition + Hashemite Kingdom + Ministry of Digital Economy and Entr
JO-PDPL-Sensitive-Data-Children-Article6-Article8-Health-Genetic-Biometric-Religious-Political
Jordan PDPL Sensitive Data + Article 6 + Article 8 + Children's Data + Health + Genetic + Biometric + Racial + Religious + Political + Trade Union + Sexual Orientation + Criminal +
JO-PDPL-Standard1-Lawful-Basis-Article7-Consent-Contract-Legal-Vital-Public-Interest-Legitimate
Jordan PDPL Standard 1 - Lawful Basis + Article 7 + Consent + Contract Performance + Legal Obligation + Vital Interests + Public Interest + Legitimate Interests + Privacy Notice +
Show the 2 you already have
JO-PDPL-Personal-Data-Protection-Council-Article4-5-6-Establishment-MoDEE-Functions-Powers-Investigation
Jordan PDPL Personal Data Protection Council + Articles 4-5-6 + Establishment + Ministry of Digital Economy and Entrepreneurship (MoDEE) + Functions + Powers + Investigation + Admi
JO-PDPL-Training-Awareness-Penalties-Article22-23-24-Compensation-Administrative-Criminal-100K-200K-JOD
Jordan PDPL Training + Awareness + Penalties + Articles 22-23-24 + Compensation + Administrative Penalties JOD 100K + JOD 200K Repeat + Criminal 3 Years + Civil Compensation + Dire

How this is calculated

Already covered means a mapping runs from a control in NIST SP 800-171A to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition