AICPA Privacy Management Framework (PMF)
Monitoring and Enforcement

AICPA Privacy Management Framework (PMF) PMF-ME.3: Enforcement and Remediation

Organisation takes corrective action to address privacy program deficiencies identified through monitoring or complaints.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 271 controls across 117 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • IEC62304-4.1 Quality Management System
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures
  • IEC62304-9.6 Analyze Problems for Trends
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-15189-8.1 General requirements
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-17025-8.1 Options
  • ISO-17025-8.7 Corrective actions

ISO/IEC 29147:2018 · 4 controls

  • 29147-3 Terms and definitions
  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 4 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • 30111-8.1 Post-release monitoring
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • RMD-1 Reference Data Management
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-6.5 Monitoring and continuous improvement
  • ISO-20400-7.2 Integrating sustainability into specifications

ISO 22320:2018 · 3 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities
  • ISO-41001-10.1 Nonconformity and corrective action
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 3 controls

  • ISO-56002-10.2 Deviation, nonconformity and corrective action
  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27003:2017 · 3 controls

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27011:2024 · 3 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27014:2020 · 3 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions
  • 27014-5.6 Continuous improvement
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles
  • CISABD-2 Embrace Radical Transparency and Accountability
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-07 Dependency Management and SBOM
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights

UK Bribery Act 2010 · 3 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • UKBRIBE-3 Due Diligence on Third Parties
  • 58.1 Scope
  • 58.3 Definitions
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • CPG-5.A Vulnerability Disclosure Program
  • CPG-6.B Supply Chain Incident Reporting
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

GDPR · 2 controls

  • GDPR-Art.24 Responsibility of the controller
  • GDPR-Art.5 Principles relating to processing of personal data
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-14064-1-8 Quality management of the GHG inventory
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-04 Roles and responsibilities definition
  • ISO27043-25 Technical vulnerability management

ISO/IEC 29134:2023 · 2 controls

  • 29134-3 Terms and definitions
  • 29134-9.2 Report findings and recommendations

ISO/SAE 21434 · 2 controls

  • ISO21434-04 Roles and responsibilities definition
  • ISO21434-25 Technical vulnerability management
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NFPA1600-7.2 After-Action Reporting
  • NFPA1600-8.2 Corrective Action
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-190 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing

PTES · 2 controls

  • PTESPHASE-1 Pre-Engagement Interactions and Scoping
  • PTESPHASE-4 Vulnerability Analysis
  • SAEIGHT-1 Child Labour and Young Worker Protection
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation
  • SHAREASSESS-1 Information Governance and Risk
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

SOC 2 · 2 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • SCA-S2 Interpretation and Definitions
  • SCA-S26 Licensing Framework
  • IM8-RES.2 Disaster Recovery
  • IM8-SEC.4 Vulnerability Management

South Korea ISMS-P · 2 controls

  • ISMSP-MS-04 Management Review and Improvement
  • ISMSP-SYS-04 Vulnerability Management
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border
  • UKOPRES-4 Incident Management, Lessons Learned, Comms
  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • UKGAMBLE-1 Scope and Applicability to Licensees
  • UKGAMBLE-4 Resilience and Incident Response
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • CFR211-A-3 Section 211.3 - Definitions
  • AS9100D-10.2 Nonconformity and Corrective Action
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • ACQS-8-3 Continuous Improvement
  • AZ-DPA-2 Article 2 - Basic Concepts

BSI IT-Grundschutz · 1 control

  • BSI-14 Vulnerability scanning and management

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions
  • IS.AR.210 Findings and Corrective Actions
  • CAT-D3-3 Corrective controls
  • FFIEC-05 Roles and responsibilities definition

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • 62351-2 Glossary of terms
  • ISO-26262-3-5 Item definition
  • ISO28001-PI-01 Personnel Security Screening

ISO 30401 · 1 control

  • ISO30401-15 Nonconformity and corrective action
  • ISO-39001-10.1 Nonconformity and corrective action

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy
  • 27050-1.4 Terms and definitions

ISO/IEC 27400:2022 · 1 control

  • 27400-3 Terms and definitions
  • 29115-3 Terms and definitions
  • BIPA-SEC5-1 Biometric Identifier Definition

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • RIDTPPA-1 Scope, Applicability, Definitions
  • 2.5.2 Verification Activities
  • SOCI-S30CU Vulnerability assessments
  • SWE-2 Relationship to GDPR
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • OB-OPS.2 Performance Standards
  • UK-TSA-NET-01 Security Architecture
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Monitoring and Enforcement

Query this from an agent

The graph holds this control, the 271 it maps to, and the evidence behind each claim, over MCP and REST.