AICPA Privacy Management Framework (PMF)
Security for Privacy

AICPA Privacy Management Framework (PMF) PMF-SP.3: Security Testing and Monitoring

Organisation regularly tests and monitors the effectiveness of security safeguards protecting personal information.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 32 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APPI · 1 control

  • APPI-A31 Provision of Personally Referable Information

Bahrain PDPL · 1 control

  • BH-PDPL-18 Regular security testing and assessment
  • FFIEC-08 Application security controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)

GDPR · 1 control

ISO/IEC 27400:2022 · 1 control

  • 27400-6.3 Secure Update Mechanism
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

PCI P2PE · 1 control

  • PCI-P2PE-08 Application security controls

PCI PIN Security · 1 control

  • PCI-PIN-08 Application security controls

PCI SSF · 1 control

  • PCI-SSF-08 Application security controls

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements

Qatar DPL · 1 control

  • QATAR-5 Security of Processing

Saudi Arabia PDPL · 1 control

  • SA-PDPL-18 Regular security testing and assessment
  • SBD-DEV-05 Secure Software Development Framework
  • IM8-DSS.3 Secure Development Practices

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-2 Consumer Rights

Uruguay DPL · 1 control

  • URUGUAY-4 Security and Cross-Border

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-3 Sensitive Data Consent and Children

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Security for Privacy

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.