3% of COBIT 2019 you already have
PCI SSF already covers about 3% of COBIT 2019, leaving
66 of 68 controls as genuinely new work.
Already covered 2
Likely covered 0
New work 66
What is genuinely new work
Nothing in PCI SSF reaches these. This is the list to scope.
APO01Managed I&T Management Framework
APO07Managed Human Resources
APO08Managed Relationships
APO09Managed Service Agreements
BAI02Managed Requirements Definition
BAI03Managed Solutions Identification and Build
BAI07Managed IT Change Acceptance and Transitioning
BAI10Managed Configuration
COBIT-APO01Managed IT management framework
COBIT-APO02Managed strategy
COBIT-APO03Managed enterprise architecture
COBIT-APO04Managed innovation
COBIT-APO05Managed portfolio
COBIT-APO06Managed budget and costs
COBIT-APO07Managed human resources
COBIT-APO08Managed relationships
COBIT-APO09Managed service agreements
COBIT-APO10Managed vendors
COBIT-APO11Managed quality
COBIT-APO13Managed security
COBIT-BAI01Managed programs
COBIT-BAI03Managed solutions identification and build
COBIT-BAI05Managed organizational change
COBIT-BAI06Managed IT changes
COBIT-BAI07Managed IT change acceptance and transitioning
COBIT-BAI08Managed knowledge
COBIT-BAI09Managed assets
COBIT-BAI10Managed configuration
COBIT-BAI11Managed projects
COBIT-DSS01Managed operations
COBIT-DSS02Managed service requests and incidents
COBIT-DSS03Managed problems
COBIT-DSS04Managed continuity
COBIT-DSS05Managed security services
COBIT-DSS06Managed business process controls
COBIT-EDM01Ensured governance framework setting and maintenance
COBIT-EDM02Ensured benefits delivery
COBIT-EDM03Ensured risk optimization
COBIT-EDM04Ensured resource optimization
COBIT-EDM05Ensured stakeholder engagement
COBIT-MEA01Managed performance and conformance monitoring
COBIT-MEA02Managed system of internal control
COBIT-MEA03Managed compliance with external requirements
COBIT-MEA04Managed assurance
DSS02Managed Service Requests and Incidents
DSS05Managed Security Services
EDM01Ensured Governance Framework Setting and Maintenance
EDM02Ensured Benefits Delivery
EDM03Ensured Risk Optimization
EDM04Ensured Resource Optimization
EDM05Ensured Stakeholder Engagement
MEA01Managed Performance and Conformance Monitoring
MEA02Managed System of Internal Control
MEA03Managed Compliance with External Requirements
Show the 2 you already have
COBIT-BAI02Managed requirements definition
COBIT-BAI04Managed availability and capacity
How this is calculated
Already covered means a mapping runs from a control in PCI SSF to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition