Framework overlap

Does Personal Data Act (personopplysningsloven) cover BSI IT-Grundschutz?

You hold Personal Data Act (personopplysningsloven) and have been told to do BSI IT-Grundschutz. Here is how much overlaps, control by control.

35% of BSI IT-Grundschutz you already have

Personal Data Act (personopplysningsloven) already covers about 35% of BSI IT-Grundschutz, leaving 36 of 55 controls as genuinely new work.

Already covered 10 Likely covered 9 New work 36

What is genuinely new work

Nothing in Personal Data Act (personopplysningsloven) reaches these. This is the list to scope.

APP.1.1
Office Products
APP.3.1
Web Applications
BSI-06
Identity proofing and verification
BSI-07
Boundary protection and segmentation
BSI-09
Denial-of-service protection
BSI-10
Transmission confidentiality and integrity
BSI-11
Session management controls
BSI-12
Network monitoring and defense
BSI-16
Threat intelligence integration
BSI-19
Incident handling and containment
BSI-22
Lessons learned and improvement
BSI-25
Security impact analysis
BSI-27
Software usage restrictions
BSI-30
Time synchronization
BSI-32
Accountability and non-repudiation
CON.1
Crypto Concept
CON.2
Data Protection
CON.3
Data Backup Concept
CON.8
Software Development
DER.1
Detection of Security-Relevant Events
DER.2.1
Security Incident Handling
DER.4
Business Continuity Management
INF.1
General Building
ISMS.1
Security Management
NET.1.1
Network Architecture and Design
OPS.1.1.2
Proper IT Administration
OPS.1.1.3
Patch and Change Management
OPS.1.1.5
Logging
OPS.1.2.4
Teleworking
OPS.2.2
Cloud Usage
ORP.1
Organisation
ORP.2
Personnel
ORP.3
Awareness and Training
ORP.4
Identity and Access Management
SYS.1.1
General Server
SYS.2.1
General Client
Show the 19 you already have
BSI-03
Multi-factor authentication requirements
BSI-04
Remote access controls
BSI-05
Wireless access restrictions
BSI-08
Cryptographic protection of data
BSI-13
Risk assessment procedures
BSI-15
Security categorization
BSI-17
Continuous monitoring strategy
BSI-18
Incident response planning and testing
BSI-20
Incident reporting and notification
BSI-21
Forensic analysis capabilities
BSI-01
Account management and provisioning
BSI-02
Access enforcement and least privilege
BSI-14
Vulnerability scanning and management
BSI-23
Baseline configuration establishment
BSI-24
Configuration change control
BSI-26
System component inventory
BSI-28
Audit event logging and storage
BSI-29
Audit record review and analysis
BSI-31
Audit log protection and retention

How this is calculated

Already covered means a mapping runs from a control in Personal Data Act (personopplysningsloven) to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition