22% of ISO 20000-1 you already have
PCI SSF already covers about 22% of ISO 20000-1, leaving
21 of 27 controls as genuinely new work.
Already covered 4
Likely covered 2
New work 21
What is genuinely new work
Nothing in PCI SSF reaches these. This is the list to scope.
8.6.2Service Request Management
8.7.1Service Availability Management
8.7.2Service Continuity Management
8.7.3Information Security Management
ISO20000-01Service portfolio management
ISO20000-02Service level management
ISO20000-04IT service continuity management
ISO20000-05Information security for services
ISO20000-07Release and deployment management
ISO20000-08Service validation and testing
ISO20000-09Knowledge management
ISO20000-12Problem management
ISO20000-13Event management and monitoring
ISO20000-14Request fulfillment
ISO20000-16Service measurement and reporting
ISO20000-17Continual improvement process
ISO20000-18Benchmarking and maturity assessment
ISO20000-19Stakeholder feedback management
Show the 6 you already have
9.1Risk communication and consultation
ISO20000-03Capacity and availability management
ISO20000-10Configuration management
ISO20000-11Incident management
ISO20000-06Change management processes
ISO20000-15Access management for services
How this is calculated
Already covered means a mapping runs from a control in PCI SSF to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition