26% of ISO/SAE 21434 you already have
US Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates already covers about 26% of ISO/SAE 21434, leaving
37 of 50 controls as genuinely new work.
Already covered 0
Likely covered 13
New work 37
No control in US Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates
maps directly to one in ISO/SAE 21434. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in US Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates reaches these. This is the list to scope.
21434-10Product Development at System Level
21434-10.4Hardware and Software Component Requirements
21434-11Cybersecurity Validation
21434-13Operations and Maintenance
21434-14End of Cybersecurity Support and Decommissioning
21434-15.3Asset Identification (TARA Step 1)
21434-15.5Threat Scenario Identification (TARA Step 2)
21434-15.6Impact Rating (TARA Step 3)
21434-15.7Attack Path Analysis (TARA Step 4)
21434-15.8Attack Feasibility and Risk Determination (TARA Step 5)
21434-15.9Cybersecurity Assurance Level (CAL) and Risk Treatment
21434-5Cybersecurity Governance
21434-6Cybersecurity Culture and Competence
21434-7Continuous Cybersecurity Activities
21434-8Risk Assessment Methods
21434-9.4Cybersecurity Goals and Claims
21434-Annex-EDistributed Cybersecurity Activities and Supplier Management
ISO21434-01Information security policy framework
ISO21434-02Management direction and commitment
ISO21434-03Policy review and update procedures
ISO21434-05Contact with authorities and special interest groups
ISO21434-06Asset inventory and ownership
ISO21434-07Acceptable use of assets
ISO21434-09Asset handling procedures
ISO21434-10Media management and disposal
ISO21434-11Access control policy and enforcement
ISO21434-20Key lifecycle management
ISO21434-21Operational procedures and responsibilities
ISO21434-22Protection from malware
ISO21434-26Audit considerations
ISO21434-27Network security management
ISO21434-28Network service security
ISO21434-29Segregation in networks
ISO21434-30Information transfer policies
ISO21434-31Secure messaging
Show the 13 you already have
ISO21434-04Roles and responsibilities definition
ISO21434-08Information classification and labeling
ISO21434-12User access management and provisioning
ISO21434-13Authentication and password management
ISO21434-14Privileged access management
ISO21434-15Access review and recertification
ISO21434-16Cryptographic policy and key management
ISO21434-17Encryption of data at rest
ISO21434-18Encryption of data in transit
ISO21434-19Certificate management
ISO21434-23Backup and recovery procedures
ISO21434-24Logging and monitoring
ISO21434-25Technical vulnerability management
How this is calculated
Already covered means a mapping runs from a control in US Children's Online Privacy Protection Act (COPPA) and COPPA 2.0 Proposed Updates to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition