Framework overlap

Does PCI SSF cover ISO/IEC 27011:2024?

You hold PCI SSF and have been told to do ISO/IEC 27011:2024. Here is how much overlaps, control by control.

36% of ISO/IEC 27011:2024 you already have

PCI SSF already covers about 36% of ISO/IEC 27011:2024, leaving 25 of 39 controls as genuinely new work.

Already covered 4 Likely covered 10 New work 25

What is genuinely new work

Nothing in PCI SSF reaches these. This is the list to scope.

27011-4
Structure of this document
27011-5.1
Policies for Information Security in Telecoms
27011-5.10
Acceptable Use of Customer Data
27011-5.15
Access Control for Network Elements
27011-5.22
Monitoring of Supplier Services
27011-5.23
Cloud and Hosted Telecoms Services
27011-5.30
ICT Readiness for Continuity
27011-5.4
Threat intelligence for telecom
27011-5.5
Information security in project management
27011-5.7
Threat Intelligence for Telecoms
27011-6.1
Screening of Telecoms Personnel
27011-6.2
Terms and conditions of employment
27011-6.4
Remote working
27011-7.10
Storage Media Handling in Telecoms
27011-7.2
Physical entry and securing offices
27011-8.12
Data Leakage Prevention for Telecoms
27011-8.15
Logging of Network and Service Events
27011-8.16
Monitoring Activities
27011-8.20
Network Security for Telecoms Core
27011-8.21
Security of Network Services
27011-8.22
Segregation of Networks
27011-8.24
Use of Cryptography
27011-8.27
Secure System Architecture
27011-8.7
Protection Against Malware
27400-4
IoT overview and concepts
Show the 14 you already have
27011-6.3
Awareness and Training
27011-8.2
Network security and segregation
27011-8.3
Cryptography and key management
27011-8.6
Data protection and backup
27011-5.2
Information Security Roles in Telecoms
27011-5.3
Segregation of duties
27011-5.6
Supplier relationships and telecom supply chain
27011-7.1
Physical security perimeters
27011-7.3
Equipment protection
27011-7.4
Physical Security of Network Sites
27011-8.1
User Endpoint Devices
27011-8.32
Change Management for Network
27011-8.4
Logging and monitoring
27011-8.5
Vulnerability and malware management

How this is calculated

Already covered means a mapping runs from a control in PCI SSF to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition