8% of COSO Internal Control you already have
PCI PIN Security already covers about 8% of COSO Internal Control, leaving
44 of 48 controls as genuinely new work.
Already covered 1
Likely covered 3
New work 44
What is genuinely new work
Nothing in PCI PIN Security reaches these. This is the list to scope.
CA-11Selects and Develops General Controls over Technology
CE-1Demonstrates Commitment to Integrity and Ethical Values
CE-2Exercises Oversight Responsibility
CE-3Establishes Structure, Authority, and Responsibility
CE-4Demonstrates Commitment to Competence
CE-5Enforces Accountability
COSO-IC-CA-10The organization selects and develops control activities for asset safeguarding and mitigating risks to the achievement of objectives
COSO-IC-CA-11The organization selects and develops general controls over technology
COSO-IC-CA-12The organization deploys control activities through policies and procedures
COSO-IC-CE-01The organization demonstrates commitment to integrity and ethical values
COSO-IC-CE-02The board demonstrates independence from management and exercises oversight of internal control
COSO-IC-CE-03Management establishes structures, reporting lines, authorities, and responsibilities
COSO-IC-CE-04The organization demonstrates commitment to attract, develop, and retain competent individuals
COSO-IC-CE-05The organization holds individuals accountable for their internal control responsibilities
COSO-IC-IC-13The organization obtains or generates and uses relevant quality information
COSO-IC-IC-14The organization internally communicates information including internal control objectives
COSO-IC-IC-15The organization communicates with external parties regarding internal control matters
COSO-IC-MA-16The organization selects and performs ongoing and/or separate evaluations
COSO-IC-MA-17The organization evaluates and communicates internal control deficiencies in a timely manner
COSO-IC-OV-01COSO Internal Control Framework - integrated operation of all five components (Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring Act
IC-13Uses Relevant Information
IC-14Communicates Internally
IC-15Communicates Externally
MON-16Conducts Ongoing and/or Separate Evaluations
MON-17Evaluates and Communicates Deficiencies
P10Selects and Develops Control Activities
P11Selects and Develops General Controls over Technology
P12Deploys through Policies and Procedures
P13Uses Relevant Information
P14Communicates Internally
P15Communicates Externally
P16Conducts Ongoing and/or Separate Evaluations
P17Evaluates and Communicates Deficiencies
P2Exercises Oversight Responsibility
P3Establishes Structure, Authority, and Responsibility
P4Demonstrates Commitment to Competence
P5Enforces Accountability
P6Specifies Suitable Objectives
P9Identifies and Analyzes Significant Change
RA-6Specifies Suitable Objectives
RA-7Identifies and Analyzes Risk
RA-9Identifies and Analyzes Significant Change
Show the 4 you already have
CA-12Deploys Through Policies and Procedures
CA-10Selects and Develops Control Activities
P1Demonstrates Commitment to Integrity and Ethical Values
P7Identifies and Analyzes Risk
How this is calculated
Already covered means a mapping runs from a control in PCI PIN Security to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition