11% of ISO/IEC 27004:2016 you already have
PCI SSF already covers about 11% of ISO/IEC 27004:2016, leaving
24 of 27 controls as genuinely new work.
Already covered 2
Likely covered 1
New work 24
What is genuinely new work
Nothing in PCI SSF reaches these. This is the list to scope.
27004-10.1Programme Review and Improvement
27004-4Structure and overview
27004-5.1Need for Measurement
27004-5.2Fulfilling 27001 Requirements
27004-5.3Validity of Results
27004-6.1What to Monitor and Measure
27004-6.2Who to Monitor and Measure
27004-6.3When to Monitor and Measure
27004-6.4How to Monitor and Measure
27004-7.1Performance Indicators
27004-7.2Effectiveness Indicators
27004-7.3Measurement Construct
27004-8.3Evaluation of measures
27004-8.4Review and improvement of processes
27004-9.1Evaluation of Results
27004-A.1Coverage Measures
27004-A.3Incident Measures
27004-A.4Awareness and Training Measures
27004-A.5Access Control Measures
27004-A.6Third-Party Measures
27004-B.2Control effectiveness examples
27004-B.3Process performance examples
Show the 3 you already have
27004-A.2Patching and Vulnerability Measures
27004-B.1Example measurement definitions
27004-9.2Communication and Reporting
How this is calculated
Already covered means a mapping runs from a control in PCI SSF to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition