30% of PCI P2PE you already have
NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems already covers about 30% of PCI P2PE, leaving
31 of 44 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 31
No control in NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems
maps directly to one in PCI P2PE. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems reaches these. This is the list to scope.
Annex-ASymmetric Key Distribution Using Asymmetric Techniques
Annex-BKey Injection Facility Requirements
Domain-1.1POI Device Approval Status
Domain-1.2Account Data Encryption at POI
Domain-1.3POI Device Tampering Protection
Domain-2.1POI Application Security
Domain-2.2POI Device Authentication
Domain-3.1POI Device Management
Domain-3.2Merchant POI Device Deployment
Domain-4.1Decryption Environment Logical Security
Domain-4.2Decryption Environment Physical Security
Domain-5.2Key Distribution and Injection
Domain-5.4Key Usage and Cryptoperiods
Domain-5.5Key Destruction
Domain-6.1P2PE Solution Documentation
Domain-6.2Annual Reassessment and Change Management
Domain-6.3Merchant Self-Assessment Support
PCI-P2PE-01Information security program management
PCI-P2PE-02Board and management oversight
PCI-P2PE-03Risk appetite and tolerance for IT risk
PCI-P2PE-04Security policy framework
PCI-P2PE-06Network security and segmentation
PCI-P2PE-07Endpoint protection and detection
PCI-P2PE-13Third-party dependency management
PCI-P2PE-15Communication and escalation procedures
PCI-P2PE-17Contractual security requirements
PCI-P2PE-20Exit strategy and transition planning
PCI-P2PE-23Regulatory reporting requirements
PCI-P2PE-24Customer notification procedures
Show the 13 you already have
PCI-P2PE-05Roles and responsibilities definition
PCI-P2PE-08Application security controls
PCI-P2PE-09Encryption and key management
PCI-P2PE-10Secure configuration standards
PCI-P2PE-11Business continuity planning and testing
PCI-P2PE-12Disaster recovery procedures
PCI-P2PE-14Critical service identification
PCI-P2PE-16Due diligence and onboarding
PCI-P2PE-18Ongoing monitoring and assessment
PCI-P2PE-19Concentration risk management
PCI-P2PE-21Incident detection and classification
PCI-P2PE-22Incident response and containment
PCI-P2PE-25Post-incident review and improvement
How this is calculated
Already covered means a mapping runs from a control in NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition