Framework overlap

Does PCI PIN Security cover MARS-E?

You hold PCI PIN Security and have been told to do MARS-E. Here is how much overlaps, control by control.

88% of MARS-E you already have

PCI PIN Security already covers about 88% of MARS-E, leaving 1 of 8 controls as genuinely new work.

Already covered 0 Likely covered 7 New work 1

No control in PCI PIN Security maps directly to one in MARS-E. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in PCI PIN Security reaches these. This is the list to scope.

MARS-E-Scope-CMS-CCIIO-ACA-Section-1311-Federal-Facilitated-State-Based-Marketplace-Exchange-45-CFR-155-260
MARS-E Scope + CMS + CCIIO + ACA Section 1311 + Marketplace + 45 CFR 155.260
Show the 7 you already have
MARS-E-Access-Control-Identity-Authentication-NIST-800-63-Identity-Assurance-Levels-MFA-AC-IA-Families
MARS-E Access Control + Identity + Authentication + NIST 800-63 + MFA + AC + IA Families
MARS-E-Audit-Accountability-Continuous-Monitoring-AU-Family-CM-Family-SIEM-Log-Retention-IRS-Pub-1075
MARS-E Audit + Accountability + Continuous Monitoring + AU + CM Families + SIEM + IRS Pub 1075
MARS-E-Contingency-Media-Protection-System-Integrity-CP-MP-SI-Families-DR-COOP-Encryption-Sanitization
MARS-E Contingency + Media Protection + System Integrity + CP + MP + SI Families + DR + COOP
MARS-E-Cross-Program-Coordination-IRS-Pub-1075-FedRAMP-CMS-ARS-HHS-OIG-Joint-Audit-3PAO
MARS-E Cross-Program + IRS Pub 1075 + FedRAMP + CMS ARS + HHS OIG + Joint Audit + 3PAO
MARS-E-Incident-Response-Breach-Notification-IR-Family-45-CFR-164-400-414-IRS-Pub-1075-Notification-CMS-IRT
MARS-E Incident Response + Breach Notification + IR Family + 45 CFR 164.400-414 + IRS Pub 1075 + CMS IRT
MARS-E-NIST-800-53-Moderate-Baseline-Catalog-v2-0-Volume-III-Tailoring-Risk-Assessment-Categorization
MARS-E NIST 800-53 Moderate Baseline + MARS-E Catalog Volume III + Tailoring + Risk Assessment + Categorization
MARS-E-Privacy-PII-PHI-Minimum-Necessary-HIPAA-Privacy-Rule-NIST-800-122-45-CFR-164-Subpart-E
MARS-E Privacy + PII + PHI + Minimum Necessary + HIPAA Privacy Rule + NIST 800-122 + 45 CFR 164 Subpart E

How this is calculated

Already covered means a mapping runs from a control in PCI PIN Security to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition